It's a lock storage correlation device. You can connect locks from different devices. Not just from Fortinet, but you can send locks from other devices to FortiAnalyzer. Basically, it is a centralized repository.
Network Security Specialist at GBM
Customer support is good, but the tool lacks a sophisticated and customizable dashboard
Pros and Cons
- "I would say that Fortinet's tech support is really good."
- "The deployment of Fortinet FortiAnalyzer is not complex, but integrating it with firewalls can take some time, depending on the number of firewalls."
What is our primary use case?
What is most valuable?
Fortinet FortiAnalyzer has a lock correlation feature. It simplifies the troubleshooting process for its customers. So now, instead of logging into every firewall, they can log into Fortinet FortiAnalyzer and check the locks. They can also check whether there are any issues with the network.
What needs improvement?
This is a difficult question for me to answer. I want the tool to have a sophisticated and customizable dashboard similar to the one in the SIEM solution. However, I'm not sure if that is in the pipeline. Basically, I would say that it's not a pure SIEM solution where your customer can have a layer on a view of dashboards or advanced dashboards.
For how long have I used the solution?
I work with Fortinet and Palo Alto. I am also a partner of Fortinet. Even though I have been working with Fortinet for more than five or six years now, Fortinet EDR is something very new for me and us in general. We have been working on firewalls, FortiAnalyzer, FortiManager, FortiMail, FortiADC, and FortiWeb. EDR, SDMA, and ZTNA are new to us. Speaking about Fortinet FortiAnalyzer, I have been working on it for more than six years now.
Buyer's Guide
Fortinet FortiAnalyzer
February 2025

Learn what your peers think about Fortinet FortiAnalyzer. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
What do I think about the stability of the solution?
The stability of Fortinet FortiAnalyzer is okay. Although some customers have encountered issues, others have had a pretty okay experience and are doing pretty well with the solution.
What do I think about the scalability of the solution?
I would say that more than ten of our clients are working on this solution. I would say that it is kind of scalable since it comes in different form factors. Owing to the different form factors and sizing of the solution, you can add and get increased capacity. This can help a person to add more firewalls and devices.
How are customer service and support?
I would say that Fortinet's tech support is really good.
How would you rate customer service and support?
Neutral
How was the initial setup?
I can say that the setup is a mixture of both options. I wouldn't say it is difficult. I would rather say that the setup process is okay or moderate. Also, the straightforwardness and complexity of the setup process will depend on your environment.
The deployment of Fortinet FortiAnalyzer is not complex, but integrating it with firewalls can take some time, depending on the number of firewalls. So, the deployment of the entire solution can take approximately one week to complete.
What's my experience with pricing, setup cost, and licensing?
I'm not familiar with the cost point, because I am more of a technical person and I do not do pre-sales or sales.
Which other solutions did I evaluate?
I downloaded reports for CrowdStrike Falcon and FortiEDR from peerspot.com to see how they are in terms of performance.
What other advice do I have?
Based on current trends, people are shifting towards FortiGate devices for their attractive value proposition and exceptional performance. FortiGate is the go-to choice for firewalls. And for us, along with FortiGate, I'll even go with FortiManager and FortiAnalyzer. I rate this solution a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner

IT Specialist at ELTEK Multimedia
Good documentation, a nice interface and a simple setup
Pros and Cons
- "It's a very stable product."
- "Their pricing model is not the best and needs work."
What is our primary use case?
Our customers are working with this product in their companies.
I haven't really played around with it so much. Basically, we're just doing log reviews, and that's it.
What is most valuable?
The initial setup is easy.
It's a very stable product.
We can scale the product as well.
Support has been good in general.
It offers pretty good documentation.
I like the interface they offer.
What needs improvement?
I'm a reseller and integrator.
I can't really tell if anything is missing. Maybe we'll find something in the future, however, I'm not sure at the moment.
Their pricing model is not the best and needs work.
It would be nice if there were more third-party integration capabilities.
For how long have I used the solution?
I've been using the solution for six months. It hasn't been that long.
What do I think about the stability of the solution?
Like all Fortinet products, it is pretty stable. There are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
The solution is scalable and expandable. It's not an issue at all.
We have three people working on it in our organization.
How are customer service and support?
Technical support is fairly good. I haven't really needed to call support just yet.
Which solution did I use previously and why did I switch?
Our company is a Fortinet supplier. We don't deal with other solutions.
How was the initial setup?
It's an easy initial setup. The implementation is not overly complex. The deployment is pretty fast and only takes two or three hours.
What's my experience with pricing, setup cost, and licensing?
I'm not a fan of the licensing system in general. I don't like their pricing model.
What other advice do I have?
I'd rate the solution nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Buyer's Guide
Fortinet FortiAnalyzer
February 2025

Learn what your peers think about Fortinet FortiAnalyzer. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
Technical lead at Rogers Capital Technology Services Ltd
Offers customized reports but their support needs improvement
Pros and Cons
- "The program is stable and it gives me great visibility."
- "The technical support is not very good."
What is our primary use case?
Our primary use case of this solution is to deep-dive and get deep visibility analyzing of logs and proxy of the network. In other words, to get good customized reports.
How has it helped my organization?
The solution allows us to see what our users do on their computers. Some way they work all day long, but then we see that they have been surfing on net, using YouTube, streaming or looking at Facebook. It is therefore a very handy program.
What is most valuable?
I am very impressed by the new version's security - on-premise or on the cloud. We have integrated the program with FortiView to get a better-customized log and more scalability on the application. The newer version is also much faster than the previous one and we have more visibility on whatever is happening on our system.
What needs improvement?
Reporting wasn't very good in the previous version, but I believe it has greatly improved. The newer version has more features and the quality of reporting is better too.
I would also like to see an improvement in the rebooting.
For how long have I used the solution?
I've been using this solution for about 13 years now.
What do I think about the stability of the solution?
The stability of the solution is good - better than the previous version. Even the hardware had changed from DCVs to some STVs so now the hardware and software are more powerful compared to the previous version. We are now able to do 14-hour functionality. The program is disabled on the FortiManager by default, but we can enable it via the console in order to get the same visibility on the FortiAnalyzer.
What do I think about the scalability of the solution?
The scalability of the program is good and we are hoping to increase our usage. I would like to see new features and better functionality, though. For the scalability of the FortiAnalyzer, we need to take into consideration the time it will take to load 30 users instead of only 14. So maybe we would perhaps need an upgrade license for FortiAnalyzer deployment in that case.
How are customer service and technical support?
The technical support isn't very good, I rate it a 2 out of 5. I don't really rely on their support because in the past I had some issues and the support team could not help me.
How was the initial setup?
The initial setup was really straightforward. The duration of the deployment depends on the requirements of the customer and the kind of reports they want to get. It can be customized to the client's specifications. Some only use it for visibility while others want to get detailed reports. If the requirements are complex, it will take around two days. Otherwise, it will take a few hours. It is very easy to deploy the FortiAnalyzer.
What's my experience with pricing, setup cost, and licensing?
This program is quite expensive. We have to renew the hardware every year and the hardware is very expensive. And we need to renew the licensing for application control too.
What other advice do I have?
I rate this solution a 6 out of 10. It is a good security firmware for automation. From a single dashboard we can get all the logs and traffic information on our firewall. We can get more visibility, so there is no need for the engineer to go in each and every firewall to get information.
Even if we don't use the FortiAnalyzer, we can use a FortiCloud to send a log. But we are still using a cloud-based solution. We are using our internet bandwidth to send logs. That's in real-time or scheduling. If bandwidth is the key factor, I will not recommend the customer to use a FortiCloud. And even if you are using the FortiCloud, the basic free version, you have a retention log for only seven days. If you want to have a longer retention log, let's say for one year, then you need to create a subscription with FortiGate. In that case, it is better to have a FortiAnalyzer on-premise. Always try to listen to your customer.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.
Security Manager at Alternative Solutions
Scales well, helpful GUI, and useful automation
Pros and Cons
- "The most valuable features of Fortinet FortiAnalyzer are the GUI and there is automation that can be done with playbooks and mini-books."
- "Fortinet FortiAnalyzer can improve by introducing integration with other Fortinet solutions with automation with one interface would be helpful."
What is our primary use case?
My clients mainly use Fortinet FortiAnalyzer for the log and automation.
This solution can be deployed on-premise and on the cloud.
What is most valuable?
The most valuable features of Fortinet FortiAnalyzer are the GUI and there is automation that can be done with playbooks and mini-books.
What needs improvement?
Fortinet FortiAnalyzer can improve by introducing integration with other Fortinet solutions with automation with one interface would be helpful.
For how long have I used the solution?
I have been using Fortinet FortiAnalyzer for approximately four years.
What do I think about the stability of the solution?
The stability of Fortinet FortiAnalyzer is good.
I rate the stability of Fortinet FortiAnalyzer a ten out of ten.
What do I think about the scalability of the solution?
The solution is scalable.
This solution is suitable for all sized companies.
I rate the scalability of Fortinet FortiAnalyzer a nine out of ten.
How are customer service and support?
My clients had a mixed experience with the support from Fortinet FortiAnalyzer. Some had good experiences and others had poor experiences.
I rate the support of Fortinet FortiAnalyzer a ten out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
My customers have tried Palo Alto Panorama and we only had positive feedback from Fortinet FortiAnalyzer.
How was the initial setup?
The initial setup of Fortinet FortiAnalyzer is simple.
What's my experience with pricing, setup cost, and licensing?
The price of Fortinet FortiAnalyzer is expensive.
I rate the price of Fortinet FortiAnalyzer a ten out of ten.
What other advice do I have?
I rate Fortinet FortiAnalyzer a ten out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Security Engineer at a recreational facilities/services company with 10,001+ employees
It runs very well on its own and doesn't really need much TLC
Pros and Cons
- "FortiAnalyzer has a robust ability to find a compromised host on your network, and when you identify a compromised host, you can address it."
- "Though FortiAnalyzer has improved over the last few versions, the user interface still has room for improvement. It's a bit dated-looking."
What is our primary use case?
The normal use case for FortiAnalyzer is log review, log analysis, etc.
How has it helped my organization?
FortiAnalyzer makes it much easier for us to find an apparently compromised host on the network.
What is most valuable?
FortiAnalyzer has a robust ability to find a compromised host on your network, and when you identify a compromised host, you can address it.
What needs improvement?
Though FortiAnalyzer has improved over the last few versions, the user interface still has room for improvement. It's a bit dated-looking. I guess that's the nicest way to describe it. In FortiAnalyzer, I would like the ability to turn off some of the services. So, for example, FortiAnalyzer can take data from FortiCamera products and turn off the FortiCamera stuff to lighten the load on the box or turn off the FortiSock product.
For how long have I used the solution?
I've been using FortiAnalyzer for about seven years.
What do I think about the stability of the solution?
FortiAnalyzer is really stable. It runs very well on its own and doesn't really need much TLC. It's a good product.
What do I think about the scalability of the solution?
It's pretty scalable. The units that we have are the right size for the amount of stuff that we're running, but they do have products that scale up to handle significantly more Fortigate firewalls in log stuff than we do. I would say about 20 people use FortiAnalyzer. There's me, the security engineer, and the network engineering team, which uses it to look at stuff on the firewalls or check the firewall logs. And our information security group uses it to look at stuff that's going on with the firewalls as well as compromised hosts. It is being used pretty well as we get further down the path of deploying our FortiGate-managed endpoint product. There'll be more users and probably more use cases for it in the future.
Which solution did I use previously and why did I switch?
I haven't really used a different solution previously. We've always used FortiAnalyzer in concert with Splunk.
How was the initial setup?
FortiAnalyzer is a pretty straightforward product to deploy. It took half a day to deploy a pair of FortiAnalyzers and set them up in high availability mode. I deployed it by myself. These are hardware appliances, so there were a couple of devices that needed to be racked, powered, and configured.
What's my experience with pricing, setup cost, and licensing?
I believe that these devices were procured with a five-year maintenance and support license up front. I work at a university, so the vendor provides a considerable higher ed discount.
Which other solutions did I evaluate?
It's all part of our Fortinet ecosystem, so we didn't really consider alternatives. I have a significant investment in FortiGate firewalls, so it just made sense to add FortiAnalyzer.
What other advice do I have?
I rate FortiAnalyzer eight out of 10. It does an outstanding job of what it does. But the vendor doesn't necessarily live up to the hype, which is why it only got an eight out of 10. There's a lot of hype about the Fortinet security fabric. But for the large customers that buy their large firewalls and deploy them in infrastructure components, the Fortinet fabric does not work. If you are considering FortiAnalyzer, I suggest having a complete understanding of how your firewall infrastructure works in terms of what data you're going to and from it for analysis and what you're looking for in that analysis.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Head Cyberdefense at a tech vendor with 5,001-10,000 employees
Offers fast report generation and logging with easy deployment
Pros and Cons
- "Report generation is very easy"
- "The upgradation process is slow"
What is our primary use case?
As part of a company, we manage customers of Fortinet FortiAnalyzer. The solution is used to analyze and locate traffic in a particular network.
How has it helped my organization?
Fortinet FortiAnalyzer has helped my organization improve operational efficiency. The company has been using it for ten years.
What is most valuable?
Report generation is very easy when using Fortinet FortiAnalyzer. Checking and reading the logs becomes seamless with the solution. Fortinet FortiAnalyzer also allows fast logging on a license when requesting information. For example, when you are trying to locate a logged destination or using the tool to find an error or fault, the basic networking is very fast.
What needs improvement?
The upgrade process for Fortinet FortiAnalyzer is slow.
For how long have I used the solution?
I have been using Fortinet FortiAnalyzer for four years.
What do I think about the stability of the solution?
Fortinet FortiAnalyzer is a stable product.
What do I think about the scalability of the solution?
The solution is highly scalable.
How was the initial setup?
It's easy to deploy Fortinet FortiAnalyzer. The solution needs to be upgraded every two or three years. The product is very easy to maintain.
What's my experience with pricing, setup cost, and licensing?
Due to the multiple features and the large environment compatibility, the solution is quite expensive. I would rate the pricing an eight out of ten.
Which other solutions did I evaluate?
At our company, Kibana is sometimes used to pull logs and develop graphical representations from it.
What other advice do I have?
I would rate the solution an eight out of ten. I would advise others never to jump into upgrading to the latest firmware; wait until the present environment products are being used. There have been bad releases in the past, so everyone needs to carefully analyze options.
Disclosure: My company has a business relationship with this vendor other than being a customer:
You can also download premade reports on the portal, but the user experience could be better
Pros and Cons
- "FortiAnalyzer helps us discover what's happening on the network."
- "They could always improve the interface and the user experience."
What is our primary use case?
FortiAnalyzer is a log analytics tool. Our company has around 600 to 700 people.
What is most valuable?
FortiAnalyzer helps us discover what's happening on the network.
What needs improvement?
They could always improve the interface and the user experience.
For how long have I used the solution?
I have used FortiAnalyzer for four or five years.
What do I think about the stability of the solution?
I rate FortiAnalyzer eight out of 10 for stability.
What do I think about the scalability of the solution?
Scalability is irrelevant to me because we have a small setup. One analyzer is enough for me.
How was the initial setup?
Setting up FortiAnalyzer isn't complex and takes two or three hours. They have a prebuilt OVA we can deploy using Ansible. Next, we configure FortiGate to send the logs to the FortiAnalyzer. You can also download premade reports on the portal.
What's my experience with pricing, setup cost, and licensing?
You pay an annual license based on the volume of logs per day.
What other advice do I have?
I rate FortiAnalyzer seven out of 10.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Chief Technology Officer at Litmus
Can be used by institutions whose data needs to be on-premises and not in the cloud
Pros and Cons
- "I have found incident management and also identifying new threats, analyzing the network traffic, and finding out the issues with the network traffic such as any security issues to be valuable. I also like the compliance reports."
- "One thing we struggled with FortiAnalyzer was integration with SIEM. We also had issues with the new threats and APTs. There were false positives, so we needed to have some ratings related to false positives."
What is our primary use case?
Most of our clients are banking and financial institutions, so their data doesn't go to the cloud as such. Their data is on-premises only. Some of our clients can go to the cloud to save the price and do management, administration, and so on, but then most of our clients, use on-premises FortiAnalyzer.
How has it helped my organization?
Fortianalyzer helped us to manage fortigate devices and update them from central location.
What is most valuable?
I have found incident management and also identifying new threats, analyzing the network traffic, and finding out the issues with the network traffic such as any security issues to be valuable. I also like the compliance reports.
It is a very stable and scalable solution.
What needs improvement?
One thing we struggled with FortiAnalyzer was integration with SIEM. We also had issues with the new threats and APTs. There were false positives, so we needed to have some ratings related to false positives.
It is easy to set up is you have FortiGate firewalls. We tried setting up with other devices, and I don't think it supports other firewalls or other devices. If it did, then it would have been great because we would have been able to use FortiAnalyzer for hybrid environments with different OEM firewalls.
If we can have an intelligent analysis system which will detect false positives and detect the exact problem, it would be great. If FortiAnalyzer can integrate with FortiSIEM and give us threat reports, that will also help because then I won't need to have another tool or another dashboard which I need to look out for.
For how long have I used the solution?
I've been using it for four years.
What do I think about the stability of the solution?
It is a very stable product, and we have had no issues at all.
What do I think about the scalability of the solution?
It is easy to scale; there are no challenges.
How are customer service and support?
The technical support is good. Most of the time, when we escalate the tickets the second line of support, FortiGate support, has been very good. The first line might take up time, but the second line of support resolves the case quite quickly.
Which solution did I use previously and why did I switch?
Yes we used checkpoint for our organisation , but it was a complex system to manage, we expect a firewall to be a simple device to avoid complexity.
How was the initial setup?
The initial setup is quite simple with FortiGate devices. So, if you have FortiGate firewalls, it is quite easy to set up. Once Fortinet FortiAnalyzer is configured, then the only thing we need to do is to monitor it.
What's my experience with pricing, setup cost, and licensing?
When you compare with other firewall vendors, FortiAnalyzer is quite competitive in pricing. They are very aggressive as well.
Which other solutions did I evaluate?
Yes we did evaluate paloa alto , but it went into backburner due cost factor.
What other advice do I have?
If you have critical objects to protect or critical data to protect, then you should go for FortiAnalyzer.
On a scale from one to ten, I would rate Fortinet FortiAnalyzer at eight.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner

Buyer's Guide
Download our free Fortinet FortiAnalyzer Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2025
Product Categories
Log ManagementPopular Comparisons
Dynatrace
Splunk Enterprise Security
IBM Security QRadar
Elastic Security
Elastic Observability
Grafana Loki
LogRhythm SIEM
Security Onion
Sumo Logic Security
syslog-ng
Amazon CloudWatch
SolarWinds Kiwi Syslog Server
Buyer's Guide
Download our free Fortinet FortiAnalyzer Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- When evaluating Log Management tools and software, what aspect do you think is the most important to look for?
- Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
- Which Windows event log monitoring tool do you recommend?
- What is the difference between log management and SIEM?
- Splunk vs. Elastic Stack
- How can Cloudtrail logs be used effectively to improve log monitoring?
- Why hot data and cold data differences in SIEM solutions are not discussed sufficiently?
- When evaluating Log Management solutions, what aspect do you think is the most important to look for?
- When evaluating Log Management solutions, what aspects do you think are the most important to look for?
- Why are Log Management tools important for companies?