Try our new research platform with insights from 80,000+ expert users

Fortinet FortiAnalyzer vs Graylog comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 12, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiAnalyzer
Ranking in Log Management
8th
Average Rating
8.0
Reviews Sentiment
7.6
Number of Reviews
93
Ranking in other categories
No ranking in other categories
Graylog
Ranking in Log Management
18th
Average Rating
8.0
Reviews Sentiment
7.0
Number of Reviews
18
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of January 2025, in the Log Management category, the mindshare of Fortinet FortiAnalyzer is 2.4%, down from 3.5% compared to the previous year. The mindshare of Graylog is 6.6%, up from 5.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management
 

Featured Reviews

Boaz Katabazi - PeerSpot reviewer
Enables flexible and comprehensive reporting across all syslog-enabled devices
I mainly use it for reporting. It also integrates other security solutions around. It can report onto anything that has a syslog on the network. It doesn't have to be a Fortinet product. It integrates within FortiGate and you can find the reports there. It's a very flexible and rich tool, providing custom reports along with default reports.
Andrey Mostovykh - PeerSpot reviewer
Real-time analysis, easy setup, and open source
We stopped using it for analytics because of its price, and at the moment, we are using it mostly for log centralization. If you use it with high traffic for analytical purposes, as well as for the logs, the infrastructure costs are unbelievable. Graylog is a great product backed by Elasticsearch as the storage and query engine. It is just an interface on top of Elasticsearch and some Elasticsearch management. The indexes that are kept in Elasticsearch are managed by Graylog software. Elasticsearch is a decent product, but it's very infrastructure-heavy. It requires lots of resources, and if you make a mistake with provisioning, you are likely to not get a cluster back. We had a couple of outages like that, and we hated that. So, we ended up over-provisioning resources just to avoid such situations from happening. If you have a whole team trying to fix the Graylog instance for two days, that's a bit too much. That may be my Norwegian take on it, but the engineering resources are expensive. It's better to just provision the infrastructure. Overall, the product is great, and the features are just fine, but the infrastructure cost is what is killing it. The infrastructure cost is the main issue. I like the rest. If the infrastructure costs could be lower, it would be fantastic. I'm not sure if they can improve the infrastructure cost with the way Elasticsearch is. If they keep using Elasticsearch, maybe there are some opportunities there, or they can support other backends with cheaper storage. They could have a different backend to replace Elasticsearch or do some tweaks to Elasticsearch to reduce the costs. There could be partial parsing of logs or parsing on demand so that when you write data through Graylog to Elasticsearch, it doesn't need to crunch in every detail requiring that much CPU.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The reporting features, which offer customization, real-time insights, and compliance support, are particularly noteworthy aspects."
"The IBS (Intent Based Segmentation) and application web filtering are the most valuable aspects of the solution."
"The solution provides good standardized reports and is easy to troubleshoot."
"One of the greatest advantages of Fortinet FortiAnalyzer is its ability to integrate with a variety of software and solutions, providing comprehensive visibility into the network. The solution's strength lies in its capability to work with Fortinet's own products, such as the FortiAP access point, which allows for deep monitoring, automation, correlation, and incident management. However, this functionality is not present when utilizing other products, such as those from Cisco, limiting the visibility and benefits that can be gained."
"What I like the most is the monitoring system."
"The most important feature is to be able to get reports or information about the state of all firewalls."
"One of the most valuable features is the ability to analyze data in real-time using AR features to pull data from the industrial DB. You can know what is going on and see in milliseconds where the network is underperforming."
"The log analysis and reporting are both quite good."
"One of the most valuable features is that you are able to do a very detailed search through the log messages in the overview."
"I like the correlation and the alerting."
"Graylog's search functionality, alerting functionality, user management, and dashboards are useful."
"We're using the Community edition, but I know that it has really good dashboarding and alerts."
"Everything stands out as valuable, including the fact that I can quantify and qualify the logs, create pipelines and process the logs in any way I like, and create charts or data maps."
"The solution's most valuable feature is its new interface."
"UDP is a fast and lightweight protocol, perfect for sending large volumes of logs with minimal overhead."
"This had increased productivity for the dev and support teams, because we are directly notifying them."
 

Cons

"I need some improvements in the support team since it is an area where there are certain shortcomings."
"The upgradation process is slow"
"We should be able to do the patch upgrades in a centralized manner. This functionality is currently not there. It would be good to be able to do the firmware updates from one place and at the same time. Currently, if we want to update all appliances, we require FortiManager, which is another solution from Fortinet. Its documentation can be improved. It will be helpful for implementing the product and gaining knowledge for management purposes."
"The interface or GUI does not work properly on Microsoft Edge. The behavior or the view is different on Microsoft Edge versus on Chrome or Firefox. When some buttons do not work, I am forced to switch to Firefox."
"A possible improvement for FortiAnalyzer could be in threat intelligence."
"We would like to do the reporting, logging, and administration of all the public devices and all the IoT devices. We wish to add the switches, and routers from different vendors, so it's not a vendor-specific diagnostic solution."
"Fortinet FortiAnalyzer cannot receive any queries. They should add this feature in the future to help manage solutions."
"The following could be better: operation and maintenance, high-availability architecture, and management link embedded in the transmission link."
"The biggest problem is the collector application, as we wanted to avoid using Graylog Collector Sidecar due to its architecture."
"Graylog needs to improve their authentication. Also, the fact that Graylog displays logs from the top down is just ridiculous."
"More customization is always useful."
"I would like to see a default dashboard widget that shows the topology of the clusters defined for the graylog install."
"Elasticsearch recommendations for tuning could be better. Graylog doesn't have direct support for running the system inside of Kubernetes, so it can be challenging to fill in the gaps and set up containers in a way that is both performant and stable."
"More complex visualizations and the ability to execute custom Elasticsearch queries would be great."
"Over six months, I had two similar issues where searches were performed on field "messages". It exhausted all the memory of the ES node causing an ES crash and a Graylog halt."
"Lacks sufficient documentation."
 

Pricing and Cost Advice

"All Fortinet programs come at a good price."
"I believe that Fortinet is a cost-effective brand, making it a competitive option in terms of pricing."
"Compared to other products, the price is a little bit high."
"The cost of the license is high."
"I rate FortiAnalyzer six out of 10 for affordability. FortiAnalyzer pricing isn't steady. It changes each quarter or year. That's one of the main problems in West Abaco because most businesses here are small or medium-sized enterprises. It makes budgeting complicated. You always want to pay the same price on the subscription."
"The price is not expensive when compared to other solutions like Palo Alto."
"The product’s price is much better than its competitors."
"It is acceptable for on-premises, but it is expensive for the cloud."
"I use the free version of Graylog."
"If you want something that works and do not have the money for Splunk or QRadar, take Graylog.​​"
"It's an open-source solution that can be used free of charge."
"We are using the free version of the product. However, the paid version is expensive."
"I am using a community edition. I have not looked at the enterprise offering from Graylog."
"Having paid official support is wise for projects."
"Consider Enterprise support if you have atypical needs or setup requirements.​"
"​You get a lot out-of-the-box with the non-enterprise version, so give it a try first."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
831,158 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
18%
Government
8%
Financial Services Firm
7%
Manufacturing Company
7%
Computer Software Company
17%
Comms Service Provider
9%
Government
8%
Educational Organization
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Fortinet FortiAnalyzer?
The reporting features, which offer customization, real-time insights, and compliance support, are particularly noteworthy aspects.
What is your experience regarding pricing and costs for Fortinet FortiAnalyzer?
I am a technical engineer, so I am not privy to pricing details.
What needs improvement with Fortinet FortiAnalyzer?
Sometimes, there is a problem with CPU consumption, where one process consumes 100%, and I need to restart FortiAnalyzer to fix this. I am not familiar with the processes of scalability.
What do you like most about Graylog?
The product is scalable. The solution is stable.
What is your experience regarding pricing and costs for Graylog?
We are using the free version of the product. However, the paid version is expensive.
What needs improvement with Graylog?
Since it's a free tool, I don't have much to say. Troubleshooting is important to me. The initial setup is complex. I hope to see improvements in Graylog for more interactivity, user-friendliness, ...
 

Also Known As

No data available
Graylog2
 

Learn More

 

Overview

 

Sample Customers

General Directorate of Information Technology
Blue Cross Blue Shield, eBay, Cisco, LinkedIn, SAP, King.com, Twilio, Deutsche Presse-Agentur
Find out what your peers are saying about Fortinet FortiAnalyzer vs. Graylog and other solutions. Updated: January 2025.
831,158 professionals have used our research since 2012.