FortiSIEM 3600G Supervisor
Supervisor node, 50,000 EPS with collectors
- Performance
- 50
- Max UEBA users
- 10,000
- Role
- Supervisor
The FortiSIEM 3600G Supervisor correlates events across the estate at 50,000 EPS with collectors, with a recommended maximum of 10,000 UEBA users. It maintains a CMDB so an alert arrives attached to the asset it concerns rather than to an IP address someone has to look up.
50,000 EPS with collectors, at the same 10,000 recommended UEBA users as the 2200G, so the choice between them is purely event volume, not analytical capability. If your peak is comfortably under 20,000 EPS, the extra spend is better placed on the collectors that will actually get events to the supervisor reliably.
How to work out whether it fits
The arithmetic a datasheet leaves out. If any of it does not match your situation, that is worth a call rather than a guess.
The only difference from the 2200G is event volume, UEBA capacity is identical, so this is a pure throughput decision. If your measured peak sits comfortably under 20,000 EPS, spend the difference on collectors instead: getting events reliably to the supervisor is a more common failure than the supervisor running out of capacity. If you genuinely exceed it, size on peak with headroom, because retrofitting a supervisor is disruptive.
What to order alongside the FortiSIEM 3600G Supervisor
The published threat protection figure for this model is measured with IPS, application control and malware protection all running. Those arrive as a FortiGuard subscription, so the bundle you choose decides whether the hardware can reach the number you sized it on. Every bundle already includes FortiCare Premium 24x7 support.
| Bundle | What it adds | 1 yearlist price | 3 yearslist price | 5 yearslist price |
|---|---|---|---|---|
| Enterprise ProtectionENT | The broadest bundle. Everything in UTP, plus the services that cover data, SaaS posture and attack-surface visibility, plus inline zero-day malware prevention. | on quote | on quote | on quote |
| Unified Threat ProtectionUTP | The traditional mid-tier: perimeter defence covering network, file, web and email threats. Everything most sites actually switch on. | on quote | on quote | on quote |
| Advanced Threat ProtectionATP | The narrow bundle: IPS and the full malware stack including cloud sandboxing, without the web and email filtering layers. | on quote | on quote | on quote |
These are Fortinet list prices. You will not pay them.
Every quote we write is discounted from list, and how far below depends on quantity, term and whether we register the deal with Fortinet. Longer terms also price better per year, which is why three and five year bundles are usually the better buy on a device you intend to keep through a refresh cycle. Part numbers follow Fortinet’s standard bundled convention; not every model carries every combination, so we confirm the exact orderable SKU before anything is placed.
Highlights
- 50,000 EPS with collectors
- Up to 10,000 UEBA users
- CMDB attaches every alert to a known asset
- Correlates Fortinet and third-party sources together
Typical deployments
- Large estates with very high event volume
- Service providers correlating across multiple customers
- Environments retaining broad third-party log sources
What this includes
Fortinet publishes no throughput table for this product; it is licensed per user, endpoint, workload or account. What follows is capability and sizing, not benchmarks.
Performance
| Performance benchmark | 50,000 EPS with collectors |
|---|---|
| Recommended max. UEBA users | 10,000 |
| Role | Supervisor |
Sources
- Fortinet Product Matrix (July 2026), retrieved 2026-09-01
- Fortinet Partner Portal price list, retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order; we will.