FortiSIEM 2200G Supervisor
Supervisor node, 20,000 EPS with collectors
- Performance
- 20
- Max UEBA users
- 10,000
- Role
- Supervisor
The FortiSIEM 2200G Supervisor correlates events across the estate at 20,000 EPS with collectors, with a recommended maximum of 10,000 UEBA users. It maintains a CMDB so an alert arrives attached to the asset it concerns rather than to an IP address someone has to look up.
A supervisor at 20,000 EPS with collectors and a recommended maximum of 10,000 UEBA users. Size on PEAK events per second measured during an incident, when every device is logging hard; that is exactly when a SIEM must not drop events, and it is when under-sized deployments fail. Averages will mislead you here.
How to work out whether it fits
The arithmetic a datasheet leaves out. If any of it does not match your situation, that is worth a call rather than a guess.
Measure peak EPS during a real incident, not a quiet Tuesday. The difference is routinely an order of magnitude, and a SIEM that drops events under load fails precisely when it was supposed to earn its keep. A practical method: enable verbose logging across the estate for one busy day, measure, then add 50%. The UEBA ceiling of 10,000 users is separate and rarely binds first, but check it if you are monitoring a large workforce.
What to order alongside the FortiSIEM 2200G Supervisor
The published threat protection figure for this model is measured with IPS, application control and malware protection all running. Those arrive as a FortiGuard subscription, so the bundle you choose decides whether the hardware can reach the number you sized it on. Every bundle already includes FortiCare Premium 24x7 support.
| Bundle | What it adds | 1 yearlist price | 3 yearslist price | 5 yearslist price |
|---|---|---|---|---|
| Enterprise ProtectionENT | The broadest bundle. Everything in UTP, plus the services that cover data, SaaS posture and attack-surface visibility, plus inline zero-day malware prevention. | on quote | on quote | on quote |
| Unified Threat ProtectionUTP | The traditional mid-tier: perimeter defence covering network, file, web and email threats. Everything most sites actually switch on. | on quote | on quote | on quote |
| Advanced Threat ProtectionATP | The narrow bundle: IPS and the full malware stack including cloud sandboxing, without the web and email filtering layers. | on quote | on quote | on quote |
These are Fortinet list prices. You will not pay them.
Every quote we write is discounted from list, and how far below depends on quantity, term and whether we register the deal with Fortinet. Longer terms also price better per year, which is why three and five year bundles are usually the better buy on a device you intend to keep through a refresh cycle. Part numbers follow Fortinet’s standard bundled convention; not every model carries every combination, so we confirm the exact orderable SKU before anything is placed.
Highlights
- 20,000 EPS with collectors
- Up to 10,000 UEBA users
- CMDB attaches every alert to a known asset
- Correlates Fortinet and third-party sources together
Typical deployments
- Mid-size enterprises building a SOC capability
- Cross-vendor correlation beyond what FortiAnalyzer reports on
- Deployments needing UEBA on privileged accounts
What this includes
Fortinet publishes no throughput table for this product; it is licensed per user, endpoint, workload or account. What follows is capability and sizing, not benchmarks.
Performance
| Performance benchmark | 20,000 EPS with collectors |
|---|---|
| Recommended max. UEBA users | 10,000 |
| Role | Supervisor |
Sources
- Fortinet Product Matrix (July 2026), retrieved 2026-09-01
- Fortinet Partner Portal price list, retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order; we will.