Try our new research platform with insights from 80,000+ expert users

Fortinet FortiAnalyzer vs Graylog comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Apr 20, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiAnalyzer
Ranking in Log Management
8th
Average Rating
8.2
Reviews Sentiment
7.6
Number of Reviews
101
Ranking in other categories
No ranking in other categories
Graylog
Ranking in Log Management
16th
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
20
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of May 2025, in the Log Management category, the mindshare of Fortinet FortiAnalyzer is 2.0%, down from 2.9% compared to the previous year. The mindshare of Graylog is 6.7%, up from 5.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management
 

Featured Reviews

Manikandan Kannan - PeerSpot reviewer
Simplifying log management by displaying detailed access information
The most valuable feature of Fortinet FortiAnalyzer is its ability to simplify and display logs clearly, providing details like which IPs are accessing the system, the destination, and the policies applied. This visualization and detail make managing logs more straightforward. In conjunction with our VMware setup, Fortinet FortiAnalyzer enhances organizational efficiency, meeting the standard log retention period for up to a year.
Ivan Kokalovic - PeerSpot reviewer
Facilitates backend service monitoring with efficient log retrieval and API flexibility
Graylog is valuable because it bridges technical knowledge to non-technical teams, presenting complex backend processes in a simple timeline. It boosts the knowledge of sales and customer support teams by allowing them to see the backend operations without needing to read the code. Its API is flexible for visualization, and its powerful search engine efficiently handles large volumes of log data. Moreover, its stability, fast search capabilities, and compatibility with languages like ANSI SQL enhance its utility in IT infrastructure.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I have found incident management and also identifying new threats, analyzing the network traffic, and finding out the issues with the network traffic such as any security issues to be valuable. I also like the compliance reports."
"The most valuable feature of the solution is reporting."
"The initial setup is straightforward."
"The IBS (Intent Based Segmentation) and application web filtering are the most valuable aspects of the solution."
"Report generation is very easy"
"The solution allows for a lot of customization."
"The traffic log information we receive from Fortinet FortiAnalyzer is valuable."
"I like its simplicity. It is straightforward. We get reports and emails about the logs, and that's it."
"UDP is a fast and lightweight protocol, perfect for sending large volumes of logs with minimal overhead."
"Message forwarding through the in-built module."
"Graylog's search functionality, alerting functionality, user management, and dashboards are useful."
"Graylog is very handy."
"I am very proud of how very stable the solution is."
"Real-time UDP/GELF logging and full text-based searching."
"Everything stands out as valuable, including the fact that I can quantify and qualify the logs, create pipelines and process the logs in any way I like, and create charts or data maps."
"Open source and user friendly."
 

Cons

"It will be better if behavior or indicators of compromise were on the same licensing schema. Currently, it is an advanced feature that you have to purchase as an add-on. This is the reason we're trying to do the ELK so that we can integrate them and create those rules by using open-source software. It will also be better if it has some more integration with IT service management tools so that we can do endpoint protection and response based on those indicators of compromise or those behavior analysis rules that create events that can automatically flow. We can inject that data into a service incident ticket on our IT service management tool, and that way we can assign the ticket to the proper teams and respond right away. Currently, we only have integration with ServiceNow."
"The setup of the solution can be improved because it is currently complex."
"Fortinet FortiAnalyzer needs to improve its pricing flexibility."
"Fortinet FortiAnalyzer cannot receive any queries. They should add this feature in the future to help manage solutions."
"Their pricing model is not the best and needs work."
"I would like to see an improvement in the technical support. Stronger authentication will also be a plus."
"Sometimes, there is a problem with CPU consumption, where one process consumes 100%, and I need to restart FortiAnalyzer to fix this."
"The solution costs too much."
"When it comes to configuring the processing pipeline, writing the rules can be very tedious, especially since the documentation isn't extensive on how the functions provided for these rules work."
"Graylog needs to improve their authentication. Also, the fact that Graylog displays logs from the top down is just ridiculous."
"When it comes to configuring the processing pipeline, writing the rules can be very tedious, especially since the documentation isn't extensive on how the functions provided for these rules work."
"More customization is always useful."
"We ran into problems with Elasticsearch throwing a circuit-breaking exception due to field data size being too large. It turned out that the heap size directly impacted this size in a high-throughput environment, causing unexplained instability in Graylog. We were able to troubleshoot on the Elasticsearch size, but we should have been able to reference some minimum requirements for Graylog to know that our settings weren't sufficient."
"I hope to see improvements in Graylog for more interactivity, user-friendliness, and creating alerts. The initial setup is complex."
"Graylog could improve the process of creating rules. We have to create them manually by doing parses and applying them. Other SIEM solutions have basic rules and you can create and get more events of interest."
"Dashboards, stream alerts and parsing could be improved."
 

Pricing and Cost Advice

"The cost and pricing should be in accordance with the calculation of log storage capacity for a time period required for historical analysis."
"I won't say the solution is too costly since it is available at a fair price."
"The number of licenses required directly corresponds with the number of devices connected."
"When comparing with other solutions such as Checkpoint and Cisco, Fortinet is priced well."
"The hardware has a one-time cost and maintenance is paid by annual subscription."
"The enterprise version of this solution is costly. We have considered FortiAuthenticator for network control, but the pricing was focused on the larger companies and didn't suit our needs as a smaller business."
"We have around 12 devices and yearly we spend approximately $14,000."
"The pricing of this solution is fair, and it is based on what you can manage."
"We are using the free version of the product. However, the paid version is expensive."
"I use the free version of Graylog."
"I am using a community edition. I have not looked at the enterprise offering from Graylog."
"It's an open-source solution that can be used free of charge."
"It's open source and free. They have a paid version, but we never looked into that because we never needed the features of the paid version."
"Having paid official support is wise for projects."
"If you want something that works and do not have the money for Splunk or QRadar, take Graylog.​​"
"There is an open source version and an enterprise version. I wouldn't recommend the enterprise version, but as an open source solution, it is solid and works really well."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
849,686 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
17%
Government
8%
Manufacturing Company
8%
Financial Services Firm
7%
Computer Software Company
18%
Comms Service Provider
10%
Educational Organization
7%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Fortinet FortiAnalyzer?
The reporting features, which offer customization, real-time insights, and compliance support, are particularly noteworthy aspects.
What is your experience regarding pricing and costs for Fortinet FortiAnalyzer?
In the Indian market, Fortinet's pricing is very competitive, allowing us to win most of our deals. It is supportive in terms of pricing, offering a good balance for mid-sized enterprises.
What needs improvement with Fortinet FortiAnalyzer?
Currently, Fortinet FortiAnalyzer provides a very basic level of correlation facilities. I would like to see improvements in the integration of better correlation capabilities. This would help in a...
What do you like most about Graylog?
The product is scalable. The solution is stable.
What is your experience regarding pricing and costs for Graylog?
We are using the free version of the product. However, the paid version is expensive.
What needs improvement with Graylog?
When it comes to configuring the processing pipeline, writing the rules can be very tedious, especially since the documentation isn't extensive on how the functions provided for these rules work. P...
 

Also Known As

No data available
Graylog2
 

Overview

 

Sample Customers

General Directorate of Information Technology
Blue Cross Blue Shield, eBay, Cisco, LinkedIn, SAP, King.com, Twilio, Deutsche Presse-Agentur
Find out what your peers are saying about Fortinet FortiAnalyzer vs. Graylog and other solutions. Updated: April 2025.
849,686 professionals have used our research since 2012.