We use the solution for log analysis.
Senior Network Architect at NTT Global Networks Incorporated
Stable, but the initial setup is complex
Pros and Cons
- "The analyzer is the most valuable feature."
- "The deployment is complex and has room for improvement."
What is our primary use case?
What is most valuable?
The analyzer is the most valuable feature.
What needs improvement?
The deployment is complex and has room for improvement.
For how long have I used the solution?
I have been using the solution for five years.
Buyer's Guide
Fortinet FortiAnalyzer
November 2024
Learn what your peers think about Fortinet FortiAnalyzer. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
814,649 professionals have used our research since 2012.
What do I think about the stability of the solution?
The solution is stable.
How was the initial setup?
The initial setup is complex. The deployment took a few hours.
What about the implementation team?
The implementation was completed with an integrator.
What's my experience with pricing, setup cost, and licensing?
We pay for an annual license.
What other advice do I have?
I give the solution a six out of ten.
I do not recommend the solution.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Information Technology Administrator at Omnient SRL
Offers a great overview of the logs and integrates perfectly
Pros and Cons
- "It is easy to integrate Fortinet FortiAnalyzer with other products. You have a better overview of what's going on."
- "The only issue that I can see is with the cost. For example, if you buy support for one year, you are messed up next year. It's better to buy another gateway."
What is our primary use case?
We collect the logs from Fortinet in order to search and get a better view of everything that's coming from FortiGate because the overview on FortiGate isn't the same. FortiAnalyzer provides an overview of the logs and everything that's happening there. We integrate FortiGate and FortiAnalyzer with the SOC that we're working on, which is an open-source security solution.
The other use case is to have logs. Because otherwise, in FortiGate, you don't have logs for a long period of time. You only have seven days if you don't have an account in FortiGuard. So, FortiAnalyzer provides a better understanding of what's happening there. And for our clients, we always recommend FortiAnalyzer.
FortiGate by itself is a good choice, but without FortiAnalyzer, you lose a lot of features. Even the free version of FortiAnalyzer provides some useful features.
What is most valuable?
It is easy to integrate Fortinet FortiAnalyzer with other products. You have a better overview of what's going on. For example, you get a smaller alert for an infected workstation if it causes some suspicious traffic, you see it right away in Fortinet.
What needs improvement?
The only issue that I can see is with the cost. For example, if you buy support for one year, you are messed up next year. It's better to buy another gateway.
For how long have I used the solution?
I have been using Fortinet FortiAnalyzer for one year, and I am currently working with the latest version.
What do I think about the stability of the solution?
It is a very stable solution and integrates perfectly.
What do I think about the scalability of the solution?
It is a scalable solution. Our company is very proud of FortiGate solutions.
How are customer service and support?
The support team is good. We have some cases open with them, and they resolve them very quickly. Even when there is a breach of security, they patch it quickly.
How was the initial setup?
It is very easy to set up and deploy. Even someone with little networking knowledge or a manager can quickly understand what's happening in the network, such as an increase in traffic from specific endpoints or which websites are being browsed, including social media.
What's my experience with pricing, setup cost, and licensing?
You get a gateway, but without support, it's not worth much. We've also tried FortiGate virtual machines, but the price is so high that it's better to buy other appliances than to buy the license for the VM.
We also work with third-party solutions. However, this solution is not for everyone, and even though it's free, it's easy to implement when you have money.
Overall, I would rate it an eight out of ten.
What other advice do I have?
I would advise buying FortiGate and FortiAnalyzer together. They get it free of charge. When you buy FortiGate, you can put in a FortiAnalyzer VM for free. Although the free version has its limitations, you should get it because it doesn't cost you anything. When you try the free version of FortiAnalyzer, you'll see its potential, and you'll want more.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Buyer's Guide
Fortinet FortiAnalyzer
November 2024
Learn what your peers think about Fortinet FortiAnalyzer. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
814,649 professionals have used our research since 2012.
Senior Manager at Technometrics Limited
Stable and scalable solution, but the technical support could be better
Pros and Cons
- "We have the most data visibility."
- "The user interface could be a bit more user-friendly."
What is our primary use case?
We have the most data visibility with this solution.
What needs improvement?
The user interface could be a bit more user-friendly, and they could have more robust support. The support does not respond quickly. They should be able to solve the problems in one or two days, but sometimes it takes time. They constantly ask for logs, and it takes time.
For how long have I used the solution?
We have been using this solution for three years, and we are using the latest version. It is deployed on-premises and cloud. It gets all the logs in a single platform because we have multiple sites.
What do I think about the stability of the solution?
The stability is good. I rate it an eight out of ten.
What do I think about the scalability of the solution?
For cloud, the solution is always scalable. We have about ten customers using Fortinet FortiAnalyzer.
How are customer service and support?
I rate the technical support a five out of ten.
How was the initial setup?
The initial setup was not complex.
What other advice do I have?
I rate this solution a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Security Manager at Alternative Solutions
Scales well, helpful GUI, and useful automation
Pros and Cons
- "The most valuable features of Fortinet FortiAnalyzer are the GUI and there is automation that can be done with playbooks and mini-books."
- "Fortinet FortiAnalyzer can improve by introducing integration with other Fortinet solutions with automation with one interface would be helpful."
What is our primary use case?
My clients mainly use Fortinet FortiAnalyzer for the log and automation.
This solution can be deployed on-premise and on the cloud.
What is most valuable?
The most valuable features of Fortinet FortiAnalyzer are the GUI and there is automation that can be done with playbooks and mini-books.
What needs improvement?
Fortinet FortiAnalyzer can improve by introducing integration with other Fortinet solutions with automation with one interface would be helpful.
For how long have I used the solution?
I have been using Fortinet FortiAnalyzer for approximately four years.
What do I think about the stability of the solution?
The stability of Fortinet FortiAnalyzer is good.
I rate the stability of Fortinet FortiAnalyzer a ten out of ten.
What do I think about the scalability of the solution?
The solution is scalable.
This solution is suitable for all sized companies.
I rate the scalability of Fortinet FortiAnalyzer a nine out of ten.
How are customer service and support?
My clients had a mixed experience with the support from Fortinet FortiAnalyzer. Some had good experiences and others had poor experiences.
I rate the support of Fortinet FortiAnalyzer a ten out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
My customers have tried Palo Alto Panorama and we only had positive feedback from Fortinet FortiAnalyzer.
How was the initial setup?
The initial setup of Fortinet FortiAnalyzer is simple.
What's my experience with pricing, setup cost, and licensing?
The price of Fortinet FortiAnalyzer is expensive.
I rate the price of Fortinet FortiAnalyzer a ten out of ten.
What other advice do I have?
I rate Fortinet FortiAnalyzer a ten out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Solutions Consultant at a manufacturing company with 11-50 employees
Easy to deploy, stable, and scalable
Pros and Cons
- "The most valuable feature of the solution is reporting."
- "The solution can improve the incident response function to provide more detailed information on where the incident is originating."
What is our primary use case?
The customer purchased a Fortinet Firewall in order to run it as a decentralized block and collect amazing security logs from their internet usage or other data from the box. The benefit of having an on-premise firewall is that they don't have to worry about any subscription, and the storage space it consumes is minimal due to the internal hard drive of the FortiAnalyzer. Furthermore, the firewall does not consume a lot of traffic from the internet due to it being on-premise.
What is most valuable?
The most valuable feature of the solution is reporting. The report that accompanies the solution includes the top 10 usages, threats to be aware of, and any highlights. Additionally, the API can be connected to other systems to receive more notifications.
What needs improvement?
The solution can improve the incident response function to provide more detailed information on where the incident is originating.
For how long have I used the solution?
I have been using the solution for three months.
What do I think about the stability of the solution?
The solution is stable and we have never experienced downtime.
What do I think about the scalability of the solution?
I give the scalability of the solution an eight out of ten.
This solution is suitable for enterprise customers with a large number of devices and logs. Fortinet FortiAnalyzer enables the compilation of log files over a period of time, such as 90 days in Thailand. This is especially useful for gathering and analyzing data.
How was the initial setup?
The initial setup is simple. Fortinet FortiAnalyzer is an out-of-the-box solution, so we can start customizing as soon as we finish the installation.
What's my experience with pricing, setup cost, and licensing?
I give the cost a seven out of ten. I believe that Fortinet is a cost-effective brand, making it a competitive option in terms of pricing.
Which other solutions did I evaluate?
An alternative solution is SolarWinds, which analyzes server performance, and could be a competitor's CM solution or a managed service that sends data from sensors on the site to their facility. The primary distinguishing feature of SolarWinds is its form factor. SolarWinds must be installed on a server and requires server resources. In the past, a large amount of OS and other resources were necessary, but the form factor has remained the same.
What other advice do I have?
I give the solution an eight out of ten.
Due to the high cost, Fortinet FortiAnalyzer is not feasible to use for certain office or branch office environments. A possible compromise could be to use a combination of two solutions: for banks, the file-based solution may be beneficial, but for on-premises locations, it could be worthwhile to make use of the existing value and use it to centrally control and manage the data.
I recommend utilizing the FortiAnalyzer if our log volume is sufficient and we have a FortiGate.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Security Solutions Architect at a manufacturing company with 1,001-5,000 employees
User-friendly and easy to set up with good logging
Pros and Cons
- "Logging is the best feature."
- "We would like to do the reporting, logging, and administration of all the public devices and all the IoT devices. We wish to add the switches, and routers from different vendors, so it's not a vendor-specific diagnostic solution."
What is our primary use case?
Most importantly, it is for the administration of Forti fabric devices and reporting of Forti fabric, and being able to generate reports. It's for logging. All 40 fabric devices are able to send logs to FortiAnalyzer. Basically, the use cases are for administration, reporting, and logging.
What is most valuable?
Logging is the best feature.
I like how everything is integrated with the FortiGate devices, FortiAuthenticator, and other fabric devices. You're able to see all the login details for the administration of FortiGate. It offers great user connectivity using that Fortinet embodiment of the user. It gives you all those login information details.
It's easy to set up.
The solution is stable.
It can scale well.
It's very user-friendly.
What needs improvement?
The fact that it only works with FortiGate devices is quite unfair. We would like to do the reporting, logging, and administration of all the public devices and all the IoT devices. We wish to add the switches, and routers from different vendors, so it's not a vendor-specific diagnostic solution.
For how long have I used the solution?
I've been using the solution for four years now.
What do I think about the stability of the solution?
The product is 100% stable. I haven't found any issues with FortiAnalyzer. It's reliable.
What do I think about the scalability of the solution?
Depending on the licenses you procure, the number of devices, and the storage space that you have, to be able to attain those logs and reports, the solution can scale.
How are customer service and support?
Support is great. Usually, when you call on them, they are right on time, and they'll be able to assign an engineer for remote session support.
How would you rate customer service and support?
Positive
How was the initial setup?
Setting the solution up is pretty easy. It's just a matter of integrating with the Fortinet public devices. FortiGate will start sending logs and then reports to FortiAnalyzer.
Once it is set up, the solution is easy to maintain.
What's my experience with pricing, setup cost, and licensing?
I'm not sure about the exact licensing costs.
What other advice do I have?
I'm working with the latest version of the solution.
We've done on-premises and cloud deployments.
Usually, clients who don't have SIEM or Nag solutions find FortiAnalyzer quite effective as it's going to give them identification of the user activity reports on different IO devices and the usage of devices. It gives you visibility of your entire infrastructure.
I'd recommend the solution. It's very user-friendly.
I'd rate the solution eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Implementer
Chief Technology Officer at Litmus
Can be used by institutions whose data needs to be on-premises and not in the cloud
Pros and Cons
- "I have found incident management and also identifying new threats, analyzing the network traffic, and finding out the issues with the network traffic such as any security issues to be valuable. I also like the compliance reports."
- "One thing we struggled with FortiAnalyzer was integration with SIEM. We also had issues with the new threats and APTs. There were false positives, so we needed to have some ratings related to false positives."
What is our primary use case?
Most of our clients are banking and financial institutions, so their data doesn't go to the cloud as such. Their data is on-premises only. Some of our clients can go to the cloud to save the price and do management, administration, and so on, but then most of our clients, use on-premises FortiAnalyzer.
How has it helped my organization?
Fortianalyzer helped us to manage fortigate devices and update them from central location.
What is most valuable?
I have found incident management and also identifying new threats, analyzing the network traffic, and finding out the issues with the network traffic such as any security issues to be valuable. I also like the compliance reports.
It is a very stable and scalable solution.
What needs improvement?
One thing we struggled with FortiAnalyzer was integration with SIEM. We also had issues with the new threats and APTs. There were false positives, so we needed to have some ratings related to false positives.
It is easy to set up is you have FortiGate firewalls. We tried setting up with other devices, and I don't think it supports other firewalls or other devices. If it did, then it would have been great because we would have been able to use FortiAnalyzer for hybrid environments with different OEM firewalls.
If we can have an intelligent analysis system which will detect false positives and detect the exact problem, it would be great. If FortiAnalyzer can integrate with FortiSIEM and give us threat reports, that will also help because then I won't need to have another tool or another dashboard which I need to look out for.
For how long have I used the solution?
I've been using it for four years.
What do I think about the stability of the solution?
It is a very stable product, and we have had no issues at all.
What do I think about the scalability of the solution?
It is easy to scale; there are no challenges.
How are customer service and support?
The technical support is good. Most of the time, when we escalate the tickets the second line of support, FortiGate support, has been very good. The first line might take up time, but the second line of support resolves the case quite quickly.
Which solution did I use previously and why did I switch?
Yes we used checkpoint for our organisation , but it was a complex system to manage, we expect a firewall to be a simple device to avoid complexity.
How was the initial setup?
The initial setup is quite simple with FortiGate devices. So, if you have FortiGate firewalls, it is quite easy to set up. Once Fortinet FortiAnalyzer is configured, then the only thing we need to do is to monitor it.
What's my experience with pricing, setup cost, and licensing?
When you compare with other firewall vendors, FortiAnalyzer is quite competitive in pricing. They are very aggressive as well.
Which other solutions did I evaluate?
Yes we did evaluate paloa alto , but it went into backburner due cost factor.
What other advice do I have?
If you have critical objects to protect or critical data to protect, then you should go for FortiAnalyzer.
On a scale from one to ten, I would rate Fortinet FortiAnalyzer at eight.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Co-founder at Korunet
User-friendly interface with a quick response and good analytics
Pros and Cons
- "FortiAnalyzer has a user-friendly interface with a quick response and good analytics. It's very secure because it's taking the log from the devices on a secure channel, so there is no problem with that in your network."
- "The cost of FortiAnalyzer could be cheaper, especially when you are installing to a VM. For 90 percent of customers, the VM solution is enough."
What is our primary use case?
For most of our customers, we are installing FortiAnalyzer as a VM-based solution. We installed a big analyzer for just one customer because they needed too much storage capacity. We have about 10 clients using it currently.
How has it helped my organization?
We prepare reports for our customers, and when the manager sees them, he's pleased. They show how many users connected, how many attacks happened, and the number of attacks stopped. The management of the IP depends on your report, so the customers need it. We are customizing these reports every day or every week, depending on what the customers need. We send emails with these reports, and the managers are also pleased about it. Also, technical guys are thrilled because they can solve problems very quickly. It's working on the SQL Server, so techs can do a quick search in real-time and see everything in the port analyzer's interface query.
What is most valuable?
FortiAnalyzer has a user-friendly interface with a quick response and good analytics. It's very secure because it's taking the log from the devices on a secure channel, so there is no problem with that in your network. Because you're getting the information from a secure channel, it's also possible to back it up in a storage solution.
For how long have I used the solution?
We have been installing FortiAnalyzer bundled with other products for about six or seven years.
How was the initial setup?
Setting up FortiAnalyzer is very straightforward. It takes just 30 minutes or less. With our installation, we sent our FortiGates log, email logs, and other logs for the three devices we're currently running to the analyzers we are using within the public architecture.
What's my experience with pricing, setup cost, and licensing?
The license depends on the storage capacity. If you want to take a log of up to 1 gigabyte daily, it's free, if I remember correctly. But if you want 5 gigabytes daily, it's licensed at different prices. The cost of FortiAnalyzer could be cheaper, especially when you are installing to a VM. For 90 percent of customers, the VM solution is enough.
What other advice do I have?
I would rate FortiAnalyzer 10 out of 10
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
Download our free Fortinet FortiAnalyzer Report and get advice and tips from experienced pros
sharing their opinions.
Updated: November 2024
Product Categories
Log ManagementPopular Comparisons
Splunk Enterprise Security
Dynatrace
IBM Security QRadar
Elastic Security
Elastic Observability
LogRhythm SIEM
Sumo Logic Security
Grafana Loki
Security Onion
Securonix Next-Gen SIEM
syslog-ng
Buyer's Guide
Download our free Fortinet FortiAnalyzer Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- When evaluating Log Management tools and software, what aspect do you think is the most important to look for?
- Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
- Which Windows event log monitoring tool do you recommend?
- What is the difference between log management and SIEM?
- Splunk vs. Elastic Stack
- How can Cloudtrail logs be used effectively to improve log monitoring?
- Why hot data and cold data differences in SIEM solutions are not discussed sufficiently?
- When evaluating Log Management solutions, what aspect do you think is the most important to look for?
- When evaluating Log Management solutions, what aspects do you think are the most important to look for?
- Why are Log Management tools important for companies?