FortiSIEM 500G Collector
Collector node, 8,000 events per second
- Performance
- 8
- Max UEBA users
- N/A
- Role
- Collector
The FSM-500G is a collector: it gathers events at the edge of a site or network segment and forwards them to a supervisor for correlation. Benchmarked at 8,000 EPS with 500 SNMP and 200 WMI for performance monitoring.
A collector, not a supervisor; it gathers events at the edge of a site or segment and forwards them for correlation, benchmarked at 8,000 EPS with 500 SNMP and 200 WMI for performance monitoring. Count your sites and network segments when sizing, not just total event volume: a single central supervisor with no collectors will struggle to reach devices across a distributed estate.
How to work out whether it fits
The arithmetic a datasheet leaves out. If any of it does not match your situation, that is worth a call rather than a guess.
Collectors are sized by site and segment, not by total event volume. The right question is how many places you have that a central supervisor cannot reach reliably, remote sites, isolated OT segments, cloud VPCs, because each of those needs local collection regardless of how few events it produces. Eight thousand EPS is ample for almost any single site; you will need several of these long before you need a bigger one.
What to order alongside the FortiSIEM 500G Collector
The published threat protection figure for this model is measured with IPS, application control and malware protection all running. Those arrive as a FortiGuard subscription, so the bundle you choose decides whether the hardware can reach the number you sized it on. Every bundle already includes FortiCare Premium 24x7 support.
| Bundle | What it adds | 1 yearlist price | 3 yearslist price | 5 yearslist price |
|---|---|---|---|---|
| Enterprise ProtectionENT | The broadest bundle. Everything in UTP, plus the services that cover data, SaaS posture and attack-surface visibility, plus inline zero-day malware prevention. | on quote | on quote | on quote |
| Unified Threat ProtectionUTP | The traditional mid-tier: perimeter defence covering network, file, web and email threats. Everything most sites actually switch on. | on quote | on quote | on quote |
| Advanced Threat ProtectionATP | The narrow bundle: IPS and the full malware stack including cloud sandboxing, without the web and email filtering layers. | on quote | on quote | on quote |
These are Fortinet list prices. You will not pay them.
Every quote we write is discounted from list, and how far below depends on quantity, term and whether we register the deal with Fortinet. Longer terms also price better per year, which is why three and five year bundles are usually the better buy on a device you intend to keep through a refresh cycle. Part numbers follow Fortinet’s standard bundled convention; not every model carries every combination, so we confirm the exact orderable SKU before anything is placed.
Highlights
- 8,000 EPS, 500 SNMP, 200 WMI for performance / 100 WMI for logs
- Edge collection for distributed estates
- CMDB attaches every alert to a known asset
- Correlates Fortinet and third-party sources together
Typical deployments
- Edge collection at branch or regional sites
- Scaling an existing FortiSIEM deployment horizontally
- Segments where direct supervisor reach is not practical
What this includes
Fortinet publishes no throughput table for this product; it is licensed per user, endpoint, workload or account. What follows is capability and sizing, not benchmarks.
Performance
| Performance benchmark | 8,000 EPS, 500 SNMP, 200 WMI for performance / 100 WMI for logs |
|---|---|
| Recommended max. UEBA users | N/A |
| Role | Collector |
Sources
- Fortinet Product Matrix (July 2026), retrieved 2026-09-01
- Fortinet Partner Portal price list, retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order; we will.