FortiXDR
Cross-Fabric detection and response with the context to adjudicate it
- Licensing
- Per endpoint plus Fabric telemetry sources
- Sources
- Endpoint, network, email, cloud
- Automation
- Automated correlation, triage and response
FortiXDR extends FortiEDR's telemetry across network, email and cloud so a detection arrives with the surrounding context rather than as an isolated endpoint event. It correlates and triages automatically, which is what makes the alert volume survivable.
Worth it once you have the other Fabric telemetry to correlate. With only endpoints deployed, FortiEDR alone is the honest answer and XDR adds cost without adding signal.
Highlights
- Correlates endpoint, network, email and cloud signals
- Automated triage reduces analyst load
- Builds on an existing FortiEDR deployment
Typical deployments
- Reducing alert fatigue in a small SOC
- Investigating an incident that spans email and endpoint
- Getting cross-domain context without building it manually
What this includes
Fortinet publishes no throughput table for this product; it is licensed per user, endpoint, workload or account. What follows is capability and sizing, not benchmarks.
What you are buying
| Licensing | Per endpoint plus Fabric telemetry sources |
|---|---|
| Sources | Endpoint, network, email, cloud |
| Automation | Automated correlation, triage and response |
How this is sized
Fortinet licenses this product per user, endpoint, workload or account rather than by appliance throughput, so there is no comparable performance table to publish. We size it from your actual environment, tell us the numbers and we will work it through with you.
| Licensing | Per endpoint plus Fabric telemetry sources |
|---|
Sources
- Fortinet product line overview, retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order; we will.