Skip to content
UptimeSkills
FortinetProfessionalOn requestUpdated: July 2026

SIEM-AN Training for Your Team — FortiSIEM Analyst

A SIEM is only as good as the person reading it at 3 a.m. Most FortiSIEM deployments are technically fine and operationally starved: alerts fire, dashboards rotate, and triage quality depends on whoever happens to be on shift. The FortiSIEM Analyst course fixes the human half — teaching analysts to search and correlate across sources under time pressure, understand why an incident fired before dismissing it, and tune noise down with a defensible reason instead of a suppression rule and a shrug.

It is deliberately a console-time course: investigation scenarios, incident workflow and reporting drills rather than deployment architecture. Teams typically book it when a SOC goes live on FortiSIEM, when MSSP analyst quality needs standardizing, or when analysts migrate from another SIEM and need the platform mapped onto skills they already have.

We organize delivery through authorized partners and instructors with real SOC mileage — live online across your shift patterns, on site, or as a private group built around your alert landscape.

Who this course is for

  • SOC analysts working shifts on a FortiSIEM console
  • Security engineers who inherited SIEM alert queues alongside their day job
  • MSSP analyst teams standardizing triage across customer tenants
  • Analysts moving to FortiSIEM from another SIEM platform

What your team will learn

Topic areas below are grouped in our own words. The full official agenda is available on request — it comes from the authorized partner as part of your quote.

Request full agenda

Key facts

DurationOn request
LevelProfessional
PrerequisitesGeneral security operations concepts and basic familiarity with log analysis; FortiSIEM exposure helps but is not assumed
FormatsLive online (VILT), On-site at your location, Private group, Seats in scheduled groups
LanguagesEnglish + local-language instructors on request

Formats and how we organize it

  • Live online (VILT)
  • On-site at your location
  • Private group
  • Seats in scheduled groups

One request → three options

Fill in the form below — it takes a couple of minutes. Within 5 business days you compare 2–3 concrete offers — provider, instructor, dates, price below the public list. We contract and administer the delivery end to end. Details:how we work and vendor training.

SIEM-AN vs alternatives: which to choose

Factual criteria only — level, duration, audience and certification. The right choice depends on your team's starting point and stack.

FortiAnalyzer 7.6 Analyst

The analyst course for Fortinet-fabric logging specifically. Choose FortiAnalyzer Analyst when your visibility scope is the Fortinet estate; FortiSIEM Analyst when you correlate across the whole environment — servers, cloud, identity and third-party sources included.

FortiSOAR Administrator

The automation layer above the SIEM: playbooks that act on what analysts confirm. A natural second step — SOAR automates triage decisions this course teaches analysts to make correctly in the first place.

A custom intensive

Standing up a SOC, or migrating one to FortiSIEM? A custom program can combine analyst training with your own use cases — the alerts, sources and escalation paths your team will actually face on shift one.

Need only part of SIEM-AN?

If your team needs a subset of this program — or a mix of topics from several courses — we build a custom 2–4 day intensive on our own materials, shaped by your infrastructure. One custom program typically replaces 2–3 catalog courses.

Explore custom courses

SIEM-AN: frequently asked questions

Is this an analyst course or an administrator course?

Analyst. The focus is using FortiSIEM to investigate — searching, correlation, incident handling, reporting — rather than deploying and maintaining the platform. Administrator-track training for FortiSIEM deployment and architecture is a separate course we can add to the same plan.

Our analysts come from another SIEM — how steep is the transition?

Gentle. Core analyst skills — query logic, correlation thinking, triage discipline — transfer directly; the course maps them onto FortiSIEM's console, rule model and incident workflow. Cross-trained analysts are typically productive on the new console within days of the course.

Does the course cover writing correlation rules?

It covers understanding and tuning them, which is the analyst's daily reality: reading why a rule fired, adjusting thresholds and reducing false positives. Deep rule authoring and content engineering can be added as a custom module for senior analysts.

Where does this sit in Fortinet's certification structure?

FortiSIEM training sat in the NSE 5 track under Fortinet's old numbering and now lives in the Security Operations family of the FCP/FCSS structure. If certification is the goal, tell us — we align the course version and exam plan accordingly.

How do we organize SIEM-AN training?

Fill in the request form on this page — team size, format, timing. Within 5 business days you receive 2–3 options from authorized partners with vetted instructors, dates and prices below public lists.

Request 2–3 SIEM-AN training options — quotes within 5 business days

No commitment — describe the task and we come back with concrete options, dates and prices.

Or email us directly:mail@uptimeskills.com

Fortinet, SIEM-AN and course names are trademarks of their respective owners. Uptime Skills is an independent training operator and is not affiliated with or endorsed byFortinet. Official courses are delivered by authorized training partners.