The product is for reporting about the use or detecting some issues or activities.
Technological Infrastructure Coordinator at IEST
Easy to configure and integrate with a straightforward setup
Pros and Cons
- "Support is helpful."
- "We are concerned about the compliance of our policy and institutional philosophy."
What is our primary use case?
What is most valuable?
The ability to track the activities of our users and some topics about security risks are the most valuable aspects.
It's simple to use.
It is not hard to set up.
The configuration is easy.
It offers good integration capabilities.
Support is helpful.
There is a lot of great documentation to be found online.
What needs improvement?
We are concerned about the compliance of our policy and institutional philosophy. We are a university and provide the tool to the users and to the infrastructure for the right use.
For how long have I used the solution?
I've been using the solution for six years.
Buyer's Guide
Fortinet FortiAnalyzer
February 2025

Learn what your peers think about Fortinet FortiAnalyzer. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
What do I think about the scalability of the solution?
We have around 2,000 users.
How are customer service and support?
Support is good. We also use the documentation online and find help via some tutorials on the internet.
How was the initial setup?
The initial setup is very simple.
The deployment took about six months.
What about the implementation team?
We deployed it via our team, however, we used an external consultant from the reseller.
What's my experience with pricing, setup cost, and licensing?
We pay a standard licensing fee on a yearly basis.
The pricing is complex since we need to add some other products or tools to assure our infrastructure, then the amount of every one of the items of software otherwise the solution is expensive in the end.
What other advice do I have?
We are a customer and end-user.
I'd rate the solution nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Corporate IT Manager at PRopex Furnishing Solutions
Stable log management support system that offers a centralized view of incident reports
Pros and Cons
- "This solution offers one view of incident management which has been the most valuable feature."
- "When using this solution, you need a high-level expert to make it work as it should."
What is our primary use case?
We use this solution to centralize the monitoring on Forti Fabrics. We monitor all firewalls and use this solution for incident management.
What is most valuable?
This solution offers one view of incident management which has been the most valuable feature.
What needs improvement?
When using this solution, you need a high-level expert to make it work as it should. We hired IT support who had knowledge of the network and firewall. For the initial step, you need a Forti expert.
For how long have I used the solution?
We have used this solution for one year.
What do I think about the stability of the solution?
This is a stable solution.
What do I think about the scalability of the solution?
This is a scalable solution.
How are customer service and support?
We have a support expert who contacts Forti when we have a problem. If we come across a bug, we need to involve Forti and open a ticket for support.
How was the initial setup?
We hired a consultant to complete the setup as it is not straightforward and requires an expert. The setup took a few days. Four IT staff look after maintenance of this solution.
What's my experience with pricing, setup cost, and licensing?
The enterprise version of this solution is costly. We have considered FortiAuthenticator for network control, but the pricing was focused on the larger companies and didn't suit our needs as a smaller business.
The pricing for this solution is on an annual basis. Databases, a virus scanner, and intrusion detection is included.
Which other solutions did I evaluate?
We have previously looked into Sophos UTM and Palo Alto.
What other advice do I have?
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Fortinet FortiAnalyzer
February 2025

Learn what your peers think about Fortinet FortiAnalyzer. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
IT Manager at a manufacturing company with 201-500 employees
Notifications and alerts are helpful, and it is a natural choice for Fortinet security devices
Pros and Cons
- "Special notifications about compromised phones are valuable because we have some guest networks, and sometimes, people are connecting phones that are connected to compromised websites. We want to be informed about it. We sometimes have some cases where we want to analyze the connection from inside to outside ports. So, it helps with a lot of things. It depends on our needs."
- "The interface or GUI does not work properly on Microsoft Edge. The behavior or the view is different on Microsoft Edge versus on Chrome or Firefox. When some buttons do not work, I am forced to switch to Firefox."
What is our primary use case?
We take all the logs from FortiGate.
We have it deployed on-premises, and we are definitely using its latest version because we are creating a new virtual machine.
What is most valuable?
Special notifications about compromised phones are valuable because we have some guest networks, and sometimes, people are connecting phones that are connected to compromised websites. We want to be informed about it. We sometimes have some cases where we want to analyze the connection from inside to outside ports. So, it helps with a lot of things. It depends on our needs.
What needs improvement?
The interface or GUI does not work properly on Microsoft Edge. The behavior or the view is different on Microsoft Edge versus on Chrome or Firefox. When some buttons do not work, I am forced to switch to Firefox.
There could be better analysis from the client's perspective. If you have FortiClient EMS, you should be able to analyze users more than the connections.
For how long have I used the solution?
We started using Fortinet FortiAnalyzer this year. It was bought by our main company in the Netherlands.
What do I think about the stability of the solution?
It is now stable, but our previous instance was unstable. We had problems with connectivity. It was strange because it is a virtual machine, and it was on the same hypervisor or host, but only Fortinet FortiAnalyzer had connectivity problems. The connection was dropped, and it was not always possible to log in. We moved it to a different environment. We have now moved it to a Hyper-V cluster on a different site in Poland, and it is now stable.
What do I think about the scalability of the solution?
It is scalable. We could change the size. It was easy.
We have mainly two people working with Fortinet FortiAnalyzer. My colleague and I from the Netherlands work on it. All IT departments also can access it. In total, we have five or six users, but mainly, two of us work on it.
How are customer service and support?
I use their technical support when I have problems. They solve my problems, but sometimes, they take time because it is difficult to understand each other. I prefer a phone call over the email or ticket system because we can share more information in a short time. I would rate them a nine out of ten. They sometimes do not have a fast solution, but they always resolve an issue in the end.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I did not work on any similar product previously.
How was the initial setup?
It was easy to deploy. It took one hour.
What about the implementation team?
We deployed it ourselves. We know the product. We know how to register devices and how to join devices. It was easy. We used our knowledge.
What's my experience with pricing, setup cost, and licensing?
I do not know the price of Fortinet FortiAnalyzer. I did not pay for it, but I know the price of other Fortinet products. They are not cheap. I am from Poland. We have Zloty, not Euro, so for us, everything is expensive.
I had also tried to buy it in the past, but it was too expensive.
What other advice do I have?
If you have FortiGate and FortiClient EMS, FortiAnalyzer is a natural choice. You can have notifications and alerts. Some things are automatically done by FortiAnalyzer. From a security perspective, it is a very good product.
Overall, we are satisfied with it. I would rate Fortinet FortiAnalyzer an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Network Architect at NTT Global Networks Incorporated
Stable, but the initial setup is complex
Pros and Cons
- "The analyzer is the most valuable feature."
- "The deployment is complex and has room for improvement."
What is our primary use case?
We use the solution for log analysis.
What is most valuable?
The analyzer is the most valuable feature.
What needs improvement?
The deployment is complex and has room for improvement.
For how long have I used the solution?
I have been using the solution for five years.
What do I think about the stability of the solution?
The solution is stable.
How was the initial setup?
The initial setup is complex. The deployment took a few hours.
What about the implementation team?
The implementation was completed with an integrator.
What's my experience with pricing, setup cost, and licensing?
We pay for an annual license.
What other advice do I have?
I give the solution a six out of ten.
I do not recommend the solution.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Manager (Engineering Department) at a comms service provider with 10,001+ employees
User-friendly, easy to deploy and simple to create reports
Pros and Cons
- "The solution is quite easy to deploy."
- "The solution should be more price competitive."
How has it helped my organization?
The clients using this solution have wifi for their guests and for their own users. They want to know which user has used their wifi to access the internet, and probably use this knowledge for a kind of security management purpose.
What is most valuable?
The solution is quite easy to deploy. For the user, they don't need to have a lot of technical know-how. It is easy to generate the report for review by the management.
The solution is stable and reliable.
We have not faced any scalability issues.
What needs improvement?
The solution should be more price competitive.
For how long have I used the solution?
I've used the solution for one or two years. I used it on a recent project.
However, the first time I used this product was in 2006 for our own infrastructure. We are not using it in our infrastructure anymore.
What do I think about the stability of the solution?
The solution is stable. There are no bugs or glitches. It doesn't crash or freeze. The performance is reliable.
What do I think about the scalability of the solution?
In terms of scalability, it really depends. For our customer, the SME customer, not that many people need it. If you talk about scalability around analysis, related to the hub and space, the hub disk size, and the capacity of the box, for the on-prem model, we need to choose it with some buffer. We can't foresee any scalability issue for that customer.
We only have one client on the solution.
How are customer service and support?
While I haven't directly dealt with technical support, I have not heard any complaints from my colleagues that may have. I would say that the support has been satisfactory for the moment.
How was the initial setup?
The initial setup is pretty straightforward. That said, I didn't handle it directly. We had an internal team that did the implementation.
Most of the time, one engineer is sufficient for a small deployment, just two AP, one firewall, and one analyzer.
What about the implementation team?
The implementation work was done by my engineers. We did not need any outside assistance from any integrators or consultants.
What's my experience with pricing, setup cost, and licensing?
I can't remember if they have a new license for software maintenance. They have maintenance that is charged annually. Unlike a firewall, they have a UTM license you need to pay annually and then only an annual maintenance cost for the hardware, for FortiAnalyzer.
I'm not sure what the exact price is at the moment. However, my understanding is the pricing could be better.
What other advice do I have?
I would recommend the solution to others. We have been happy with its overall capabilities. I'd rate the solution at an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Senior Network Architect at INISI b.v.
The monitoring features are quite impressive, including maps, source IP, country codes, and geolocation
Pros and Cons
- "What I like the most is the monitoring system."
- "The UI can be more user-friendly for new users."
What is our primary use case?
We are an IT company. One of our clients utilizes FortiGate, FortiAnalyzer, and FortiManager. Thus, this is the sole customer in our portfolio using Fortinet FortiAnalyzer. Among our other clients, some exclusively employ FortiGate. Our responsibility encompasses network management for these clients.
What is most valuable?
What I like the most is the monitoring system. For example, it can track who is accessing through VPNs. The monitoring features are quite impressive, including maps, source IP, country codes, and geolocation – all of which are really cool. Additionally, the logging functionality is also excellent.
What needs improvement?
The UI can be more user-friendly for new users.
For how long have I used the solution?
I have been using Fortinet FortiAnalyzer for seven years.
What do I think about the stability of the solution?
Fortinet FortiAnalyzer is highly stable. In the seven years of usage, we have never needed to reinstall it or perform troubleshooting. We have not had to make any support calls to Fortinet either. We successfully performed upgrades from version five to six and from six to seven, all of which went smoothly.
What do I think about the scalability of the solution?
Fortinet FortiAnalyzer is scalable.
How are customer service and support?
The technical support is excellent. I have never encountered any problems with FortiAnalyzer, but the issues we faced with FortiGate, which I was unable to resolve on my own, were promptly resolved by their team.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is straightforward. We can choose to install either a single node or a cluster. We run it in a virtual environment on firmware, and the process of installing the RPA takes around 15 minutes. Afterward, some configuration is required, including the installation of certificates and similar tasks. Thus, the entire process usually takes approximately one to two hours.
Once the installation is complete, we need to connect all the FortiGate Firewalls to the FortiAnalyzer. This step also involves configuring them securely. When I deploy this solution for a customer, it typically takes me about four to eight hours to complete the installation and configuration.
What's my experience with pricing, setup cost, and licensing?
The price is not expensive when compared to other solutions like Palo Alto.
In addition to the licensing, we pay for a support contract.
What other advice do I have?
I would rate Fortinet FortiAnalyzer eight out of ten.
Fortinet FortiAnalyzer is only valuable for organizations that utilize ten or more FortiGates.
I recommend Fortinet FortiAnalyzer to others.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Information Technology Administrator at Omnient SRL
Offers a great overview of the logs and integrates perfectly
Pros and Cons
- "It is easy to integrate Fortinet FortiAnalyzer with other products. You have a better overview of what's going on."
- "The only issue that I can see is with the cost. For example, if you buy support for one year, you are messed up next year. It's better to buy another gateway."
What is our primary use case?
We collect the logs from Fortinet in order to search and get a better view of everything that's coming from FortiGate because the overview on FortiGate isn't the same. FortiAnalyzer provides an overview of the logs and everything that's happening there. We integrate FortiGate and FortiAnalyzer with the SOC that we're working on, which is an open-source security solution.
The other use case is to have logs. Because otherwise, in FortiGate, you don't have logs for a long period of time. You only have seven days if you don't have an account in FortiGuard. So, FortiAnalyzer provides a better understanding of what's happening there. And for our clients, we always recommend FortiAnalyzer.
FortiGate by itself is a good choice, but without FortiAnalyzer, you lose a lot of features. Even the free version of FortiAnalyzer provides some useful features.
What is most valuable?
It is easy to integrate Fortinet FortiAnalyzer with other products. You have a better overview of what's going on. For example, you get a smaller alert for an infected workstation if it causes some suspicious traffic, you see it right away in Fortinet.
What needs improvement?
The only issue that I can see is with the cost. For example, if you buy support for one year, you are messed up next year. It's better to buy another gateway.
For how long have I used the solution?
I have been using Fortinet FortiAnalyzer for one year, and I am currently working with the latest version.
What do I think about the stability of the solution?
It is a very stable solution and integrates perfectly.
What do I think about the scalability of the solution?
It is a scalable solution. Our company is very proud of FortiGate solutions.
How are customer service and support?
The support team is good. We have some cases open with them, and they resolve them very quickly. Even when there is a breach of security, they patch it quickly.
How was the initial setup?
It is very easy to set up and deploy. Even someone with little networking knowledge or a manager can quickly understand what's happening in the network, such as an increase in traffic from specific endpoints or which websites are being browsed, including social media.
What's my experience with pricing, setup cost, and licensing?
You get a gateway, but without support, it's not worth much. We've also tried FortiGate virtual machines, but the price is so high that it's better to buy other appliances than to buy the license for the VM.
We also work with third-party solutions. However, this solution is not for everyone, and even though it's free, it's easy to implement when you have money.
Overall, I would rate it an eight out of ten.
What other advice do I have?
I would advise buying FortiGate and FortiAnalyzer together. They get it free of charge. When you buy FortiGate, you can put in a FortiAnalyzer VM for free. Although the free version has its limitations, you should get it because it doesn't cost you anything. When you try the free version of FortiAnalyzer, you'll see its potential, and you'll want more.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Network Security Engineer at Social Security Commission
A good firewall activity reporting tool with next to real-time reporting capabilities, but lacking auto-detection when upgrades take place
Pros and Cons
- "We like the fact that we can run minute-by-minute reporting form this solution."
- "We would like to see some improvement on the upgrade process around this solution. There are sometimes communication issues when a new version of the firewall is implemented, and it fails to report back to this product."
What is our primary use case?
We use this solution to actively pick up and report on all activities and connectivity going through the FortiGate firewall.
What is most valuable?
We like the fact that we can run minute-by-minute reporting form this solution.
We also appreciate that the interface of this solution is very good, and doesn't require a lot of configuration, updating, or maintenance.
What needs improvement?
We would like to see some improvement on the upgrade process around this solution. There are sometimes communication issues when a new version of the firewall is implemented, and it fails to report back to this product.
We would also like to be able to pull off incident reports and display them graphically using this solution.
For how long have I used the solution?
We have been using this solution for about three years now.
What do I think about the stability of the solution?
The stability of this solution is okay. There is some room for improvement, and so we would rate the stability as an eight out of ten.
What do I think about the scalability of the solution?
We have found this to be a fairly scalable solution.
How was the initial setup?
The initial setup of this solution is very easy, and takes around three hours to complete the implementation.
What about the implementation team?
We carried out the implementation using in-house resources.
What's my experience with pricing, setup cost, and licensing?
The renewals for this solution are carried out yearly.
What other advice do I have?
We would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free Fortinet FortiAnalyzer Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2025
Product Categories
Log ManagementPopular Comparisons
Dynatrace
Splunk Enterprise Security
IBM Security QRadar
Elastic Security
Elastic Observability
Grafana Loki
LogRhythm SIEM
Security Onion
Sumo Logic Security
syslog-ng
Amazon CloudWatch
SolarWinds Kiwi Syslog Server
Buyer's Guide
Download our free Fortinet FortiAnalyzer Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- When evaluating Log Management tools and software, what aspect do you think is the most important to look for?
- Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
- Which Windows event log monitoring tool do you recommend?
- What is the difference between log management and SIEM?
- Splunk vs. Elastic Stack
- How can Cloudtrail logs be used effectively to improve log monitoring?
- Why hot data and cold data differences in SIEM solutions are not discussed sufficiently?
- When evaluating Log Management solutions, what aspect do you think is the most important to look for?
- When evaluating Log Management solutions, what aspects do you think are the most important to look for?
- Why are Log Management tools important for companies?