We are using it only for integration and getting information from FortiAnalyzer to use and analyze important events.
Development and Innovation Manager at NSB
Good UI and customization with everything under one umbrella
Pros and Cons
- "The product can scale."
- "The pricing could be better."
What is our primary use case?
What is most valuable?
The stability is good.
They are able to integrate everything under one umbrella, which is nice.
The UI and customization are good right now.
The product can scale.
What needs improvement?
The pricing could be better.
We'd like integration with more providers.
The initial setup can be difficult.
For how long have I used the solution?
We've used the solution for about a year.
Buyer's Guide
Fortinet FortiAnalyzer
January 2025
Learn what your peers think about Fortinet FortiAnalyzer. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,158 professionals have used our research since 2012.
What do I think about the stability of the solution?
The stability of the product is good and it has been reliable. There are no bugs or glitches and it doesn't crash or freeze.
What do I think about the scalability of the solution?
The product can scale. It's simple to expand as necessary.
How are customer service and support?
I've never had to contact technical support. I cannot speak to how helpful or responsive they would be.
Which solution did I use previously and why did I switch?
We are using all the solutions from Fortinet, and FortiAnalyzer. We are planning to use FortiSIEM and FortiWeb.
How was the initial setup?
It's not too easy to set up. It can be a bit difficult. They could make it a little bit easier.
You only need two people (engineers) to handle deployment and maintenance.
What other advice do I have?
We are partners for Fortinet. So we are planning to use the FortiEDR, and then we're going to expand.
We only use FortiAnalyzer for internal purposes.
Our company is using the most up-to-date solution.
I'd advise potential users to look for a partner who knows how to handle the product and use their knowledge to give you quick training for your own people. The learning curve is not that easy.
I'd rate the solution eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Senior System Administrator at Citystars Properties
Helpful dashboards, reliable, and simple deployment
Pros and Cons
- "The most valuable features of Fortinet FortiAnalyzer are the dashboards and supporting services."
- "Fortinet FortiAnalyzer could improve by having better integration with other vendors."
What is our primary use case?
I am using Fortinet FortiAnalyzer for tracing anything that happens in the network.
What is most valuable?
The most valuable features of Fortinet FortiAnalyzer are the dashboards and supporting services.
What needs improvement?
Fortinet FortiAnalyzer could improve by having better integration with other vendors.
For how long have I used the solution?
I have been using Fortinet FortiAnalyzer for approximately five years.
What do I think about the stability of the solution?
Fortinet FortiAnalyzer is highly stable.
What do I think about the scalability of the solution?
Fortinet FortiAnalyzer is scalable.
We have five managers that are using the solutions.
How are customer service and support?
The support was great for Fortinet FortiAnalyzer.
I rate the support from Fortinet FortiAnalyzer a four out of five.
How was the initial setup?
The initial setup of Fortinet FortiAnalyzer was simple. The full deployment took approximately two or three hours.
What about the implementation team?
We used a local partner of Fortinet that was assisting us with the deployment. We had a two-person team for the deployment.
What other advice do I have?
I rate Fortinet FortiAnalyzer an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Fortinet FortiAnalyzer
January 2025
Learn what your peers think about Fortinet FortiAnalyzer. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,158 professionals have used our research since 2012.
Log management that is scalable, easy to use, and priced well
Pros and Cons
- "The interface is simple and easy to navigate."
- "One of the main disadvantages is not having a direct link to the security policy when you see something in the log."
What is our primary use case?
We are using Fortinet FortiAnalyzer to manage services for our customers. We use it for log management.
What is most valuable?
Fortinet FortiAnalyzer is easy. For customers with basic knowledge, and for those who do not have a technical background, Fortinet is quite good and it should be the first choice.
The interface is simple and easy to navigate.
What needs improvement?
One of the main disadvantages is not having a direct link to the security policy when you see something in the log. You should be able to right-click and go directly to the security policy. When you compare with Checkpoint, they are very good with reporting and logging, and when you right-click on the log you can go to the policy and edit it.
In the next release, I would like to have a feature added where you can right-click and it takes you directly to the policy to edit it.
For how long have I used the solution?
I have been working with Fortinet FortiAnalyzer for four years.
What do I think about the stability of the solution?
Fortinet FortiAnalyzer is stable.
What do I think about the scalability of the solution?
This is solution is very scalable.
How are customer service and technical support?
I don't have any issues with technical support.
How was the initial setup?
The initial setup is straightforward. Everything with Fortinet is straightforward.
What's my experience with pricing, setup cost, and licensing?
When comparing with other solutions such as Checkpoint and Cisco, Fortinet is priced well.
What other advice do I have?
I am an expert in Juniper and Fortinet at a professional level.
Previously in another company, we were service providers, and I did the implementation for service delivery cargo, and for an enterprise company, I did the firewall migration.
I would recommend Fortinet FortiAnalyzer.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
Network Security Engineer at ZOL Zimbabwe
Offers visibility of critical data in real-time for our clients, but the reports are over-summarized
Pros and Cons
- "The most valuable features are customizing reports, and the ability to drill down to display critical information in real-time."
- "The reports are good, but they are over-summarized."
What is our primary use case?
We use this solution for reporting. We also use it to keep logs for our clients that require logs with a history of more than seven days.
In addition to our own firewalls, we have several clients with firewalls that report into the same FortiAnalyzer.
We have a private cloud deployment, set up on-premises.
What is most valuable?
The most valuable features are customizing reports, and the ability to drill down to display critical information in real-time. FortiGate itself, for example, doesn't offer all of this information on the entry-level firewalls. You can get more detailed information from FortiAnalyzer based on the log that is retrieved from FortiGate while it is operating.
What needs improvement?
I would like to be able to do more customization. For example, I would like to be able to develop my own set of reports that I can upload to the analyzer, and then it can report in a fashionable way as to what I really expect, rather than the ones that are preconfigured. Then we can play around with them in terms of where you can position your top bandwidth users, and such.
The reports are good, but they are over-summarized.
For how long have I used the solution?
We have been using this solution for four years.
What do I think about the stability of the solution?
The device has been pretty much stable. We haven't really had issues with it in the time that we've been using it.
What do I think about the scalability of the solution?
The licensing limits the storage in terms of how much information it can store. For example, you can collect seven gigs of log files in a day.
We have twenty firewalls connecting to FortiAnalyzer. We are moving some of them to the FortiCloud platform because we get thirty days of reporting on a non-subscription basis with FortiCloud. With FortiAnalyzer, we would have to pay for more licenses.
At this stage, we do not plan to increase usage. The majority of our clients who have entry-level firewalls are now depending on FortiCloud. It is more robust than us having more of the FortiAnalyzer devices. Because FortiCloud is accessible from anywhere, a client can easily manage it, rather than us giving them access to the Fortianalyzer. So, we're finding FortiCloud being a better option than us having an on-site FortiAnalyzer.
How are customer service and technical support?
When I speak with Fortinet technical support it is usually in regards to FortiGate. I would rate their support team an eight out of ten. Sometimes, what happens is that we open a webchat with them where you don't have to open a ticket. The problem is that you may end up dealing with the level-one support who doesn't really give you the answer, so they then refer you to open a ticket. This delay can be a problem when you have a client that needs an issue resolved right then and there.
Which solution did I use previously and why did I switch?
We have not used any other solutions for log analysis.
How was the initial setup?
The initial setup of this solution is pretty straightforward. We have a few FortiGate firewalls, and they communicate with FortiAnalyzer over the public networks by sending their logs.
The deployment was not difficult and did not take much time. It is just the initial configuration on FortiAnalyzer, which takes no more than ten minutes. Then, the analyzer will be synchronized with FortiGate. It is just a matter of entering the FortiAnalyzer IP address, then allowing it to register. In total, it takes about twenty minutes.
There are three administrators for this solution, and I handle the maintenance myself.
What about the implementation team?
We handled the deployment ourselves. The documentation from Fortinet is pretty straightforward.
What's my experience with pricing, setup cost, and licensing?
The pricing of this solution is fair, and it is based on what you can manage. There are no costs in addition to the licensing fees.
Which other solutions did I evaluate?
We tried NetFlow Analyzer, and the product was good but it was highly expensive.
What other advice do I have?
This solution, at every stage, does what I expect it to.
My advice for anybody researching this solution is to consider the size of their organization. If it is very big and they need to retain a log for a specific number of days or a period of time, for example, going back to thirty days and they also need to analyze the traffic in real-time, then FortiAnalyzer would be ideal. However, the same service is now available on FortiCloud, which is something else that I highly recommend.
With other solutions, such as NetFlow Analyzer, you can really customize your report to what you expect. Together you can insert logs, you can customize your reports with the logs that you're receiving, unlike with FortiAnalyzer. This is a major drawback.
I would rate this solution a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
Head of Service at MPM
Has a useful dashboard and good scalability
Pros and Cons
- "The feature I find most useful is the handy dashboard."
- "I would like to see an improvement in the technical support. Stronger authentication will also be a plus."
What is our primary use case?
Our primary use case of this solution is for bandwidth. We are very satisfied with this program.
What is most valuable?
The feature I find most useful is the handy dashboard.
What needs improvement?
I would like to see an improvement in the technical support. Stronger authentication will also be a plus.
In the next version, I would like to have authentication for 40 tokens.
For how long have I used the solution?
I have been using Fortinet FortiAnalyzer for a month now on private cloud.
What do I think about the scalability of the solution?
We have between 20 and 25 users and we plan to increase this number, so I believe the program is scalable.
How are customer service and technical support?
We are very satisfied with the customer service.
How was the initial setup?
The initial setup was straightforward and deployment took us about eight months. The reason for this is that we installed other programs during this time too, like Fireworks Data Center, Switch Data Center, Cisco Nexus Data Center, and Forcepoint. We use Stitch as our local manager.
What's my experience with pricing, setup cost, and licensing?
All Fortinet programs come at a good price.
What other advice do I have?
I will definitely recommend this solution to others. My rating is a ten out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Network and Security Engineer at RaytonCOrp
Provides detailed reporting, customizable dashboards, and an easy deployment
Pros and Cons
- "The most valuable feature is the capability to create a customized dashboard."
- "The integration between specific tenants and FortiAnalyzer can be simplified when utilizing a multi-tenant EMS for our FortiClient."
What is our primary use case?
Fortinet FortiAnalyzer is primarily utilized to generate quarterly reports showcasing blocked attacks and vulnerabilities. It employs features like WAV porting triggers and DNS triggers to effectively demonstrate to the client the security of their environment.
How has it helped my organization?
Fortinet FortiAnalyzer assists in showcasing the value of Fortinet and facilitates the upselling of additional Fortinet products to our customers.
What is most valuable?
The most valuable feature is the capability to create a customized dashboard. We can subsequently input our EMS, FortiClient, and FortiGate data into it and generate reports.
What needs improvement?
The integration between specific tenants and FortiAnalyzer can be simplified when utilizing a multi-tenant EMS for our FortiClient.
For how long have I used the solution?
I have been using Fortinet FortiAnalyzer for three months.
What do I think about the stability of the solution?
Fortinet FortiAnalyzer is stable.
What do I think about the scalability of the solution?
Fortinet FortiAnalyzer is scalable.
How are customer service and support?
I utilized the technical support services once, and I received a prompt response.
How was the initial setup?
The initial setup is straightforward. The deployment was an easy and smooth process. The deployment took one day and I did it myself.
What other advice do I have?
I would rate Fortinet FortiAnalyzer a nine out of ten.
Fortinet FortiAnalyzer does not require maintenance after the initial report setup. We simply have to remove and add FortiGate as needed for each report.
Before utilizing Fortinet FortiAnalyzer, individuals should determine the type of reporting they require. Additionally, they ought to be acquainted with FortiGate before endeavoring to use FortiAnalyzer.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
Project Manager at a tech services company with 51-200 employees
Enriches visibility for security solutions
Pros and Cons
- "FortiAnalyzer's best feature is centralized log analysis. It's based on SQL database, so I can fully customize my report, chart-wise and log-wise, and can create as many reports as I want without any limit."
- "FortiAnalyzer's price could be lower."
What is our primary use case?
I mainly use FortiAnalyzer to centralize logs from multiple devices and generate local reports. It can work in two operation modes: as a collector only or an analyzer.
How has it helped my organization?
FortiAnalyzer has enriched the visibility for all our security solutions.
What is most valuable?
FortiAnalyzer's best feature is centralized log analysis. It's based on SQL database, so I can fully customize my report, chart-wise and log-wise, and can create as many reports as I want without any limit. It also has an important feature called Indicators of Compromise, an artificial intelligence feature that detects and alerts you when there is a breach in your entity.
For how long have I used the solution?
I've been using FortiAnalyzer for ten years.
What do I think about the stability of the solution?
FortiAnalyzer is a very mature and stable product.
What do I think about the scalability of the solution?
FortiAnalyzer is scalable. When my organization expands in any way, I can implement a FortiAnalyzer as a collector only, it will collect the log, and I can send this to the main analyzer. If I use the virtual alert mode, this is a stackable license, so I can expand the log size or the internal hard-disc log size by purchasing a license. There is also a workaround solution, to automatically upload the old log file to shared storage and delete the old one, which gives more space in the hard drive.
How are customer service and support?
FortiAnalyzer's technical support is helpful.
How would you rate customer service and support?
Positive
How was the initial setup?
FortiAnalyzer is straightforward to implement and integrate, but a little experience is needed to generate a technical level.
What was our ROI?
We get good ROI from FortiAnalyzer.
What's my experience with pricing, setup cost, and licensing?
FortiAnalyzer's price could be lower, but it is cheaper than competitors like Palo Alto, Forcepoint, or Sophos. The basic license is available on a yearly basis, but some other licenses can be for three, six, or nine months as required. There are no hidden costs associated with this product.
What other advice do I have?
Don't just depend on the basic reports, you can get much more out of FortiAnalyzer if you know how to create customized reports from the SQL queries. I would give FortiAnalyzer a rating of eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
Information Security Specialist at Ministry of Heritage and Culture
Good network protection and web filtering capabilities with responsive technical support
Pros and Cons
- "The IBS (Intent Based Segmentation) and application web filtering are the most valuable aspects of the solution."
- "The solution could use more graphics and be more specific in the dashboard. This way, I'm able to understand everything and effectively understand what's going on, including what's incoming and outgoing. Right now, I have to look up everything. I need a dashboard so that I can see specific items right there in one place."
What is our primary use case?
We primarily use the solution to protect the network and to control how the users access and use the internet.
What is most valuable?
The IBS (Intent Based Segmentation) and application web filtering are the most valuable aspects of the solution.
What needs improvement?
The solution is quite expensive.
The solution could use more graphics and be more specific in the dashboard. This way, I'm able to understand everything and effectively understand what's going on, including what's incoming and outgoing. Right now, I have to look up everything. I need a dashboard so that I can see specific items right there in one place.
For how long have I used the solution?
I've been using the solution for three years.
What do I think about the scalability of the solution?
We have 600 users and do plan to increase usage in the future.
How are customer service and technical support?
Technical support is good. We've talked with them a few times. We have third-party support here in Oman.
Which solution did I use previously and why did I switch?
I didn't previously use another solution.
What about the implementation team?
A third party vendor assisted us with the implementation.
What's my experience with pricing, setup cost, and licensing?
We have around 12 devices and yearly we spend approximately $14,000.
What other advice do I have?
We are using the private cloud deployment model.
I would rate the solution nine out of ten. I don't have much to compare it to, but it's been fairly good.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Fortinet FortiAnalyzer Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Product Categories
Log ManagementPopular Comparisons
Dynatrace
Splunk Enterprise Security
IBM Security QRadar
Elastic Security
Elastic Observability
LogRhythm SIEM
Grafana Loki
Sumo Logic Security
Security Onion
syslog-ng
Amazon CloudWatch
SolarWinds Kiwi Syslog Server
Buyer's Guide
Download our free Fortinet FortiAnalyzer Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- When evaluating Log Management tools and software, what aspect do you think is the most important to look for?
- Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
- Which Windows event log monitoring tool do you recommend?
- What is the difference between log management and SIEM?
- Splunk vs. Elastic Stack
- How can Cloudtrail logs be used effectively to improve log monitoring?
- Why hot data and cold data differences in SIEM solutions are not discussed sufficiently?
- When evaluating Log Management solutions, what aspect do you think is the most important to look for?
- When evaluating Log Management solutions, what aspects do you think are the most important to look for?
- Why are Log Management tools important for companies?