Try our new research platform with insights from 80,000+ expert users

Fortinet FortiAnalyzer vs Graylog vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

As of May 2025, in the Log Management category, the mindshare of Fortinet FortiAnalyzer is 2.0%, down from 2.9% compared to the previous year. The mindshare of Graylog is 6.7%, up from 5.8% compared to the previous year. The mindshare of Splunk Enterprise Security is 7.3%, down from 10.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management
 

Featured Reviews

Manikandan Kannan - PeerSpot reviewer
Simplifying log management by displaying detailed access information
The most valuable feature of Fortinet FortiAnalyzer is its ability to simplify and display logs clearly, providing details like which IPs are accessing the system, the destination, and the policies applied. This visualization and detail make managing logs more straightforward. In conjunction with our VMware setup, Fortinet FortiAnalyzer enhances organizational efficiency, meeting the standard log retention period for up to a year.
Ivan Kokalovic - PeerSpot reviewer
Facilitates backend service monitoring with efficient log retrieval and API flexibility
Graylog is valuable because it bridges technical knowledge to non-technical teams, presenting complex backend processes in a simple timeline. It boosts the knowledge of sales and customer support teams by allowing them to see the backend operations without needing to read the code. Its API is flexible for visualization, and its powerful search engine efficiently handles large volumes of log data. Moreover, its stability, fast search capabilities, and compatibility with languages like ANSI SQL enhance its utility in IT infrastructure.
ROBERT-CHRISTIAN - PeerSpot reviewer
Has many predefined correlation rules and is brilliant for investigation and log analysis
It is very complicated to write your own correlation rules without the help of Splunk support. What Splunk could do better is to create an API to the standard SIEM tools, such as Microsoft Sentinel. The idea would be to make it less painful. In ELK Stack, Kibana is the query language with which you can search log files. I believe Splunk has also a query language in which they search their log files, but once you have identified the log file that you want to use for further security correlation, you want to very quickly transport that into your SIEM tool, such as Microsoft Sentinel. That is something that Splunk could make a little bit less painful because it is a lot of effort to find that log file and forward it. An API with Microsoft Sentinel or a similar SIEM tool would be a good idea.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The feature I find most useful is the handy dashboard."
"FortiAnalyzer's reporting features like graphs, threat intelligence, and vulnerabilities analysis are helpful. Fortinet knows how to do reporting. You can customize your reports to show exactly what you want to analyze. It's user-friendly and doesn't require a lot of effort."
"The most valuable feature of Fortinet FortiAnalyzer is its performance."
"The most valuable is its robust and comprehensive reporting functionality, providing a thorough overview of various metrics."
"It is easy to integrate Fortinet FortiAnalyzer with other products. You have a better overview of what's going on."
"FortiAnalyzer's best feature is centralized log analysis. It's based on SQL database, so I can fully customize my report, chart-wise and log-wise, and can create as many reports as I want without any limit."
"The features that our customers have found most valuable are their different type of reports including the drill down report, as well as the flexibility to connect to any number of appliances which can be connected to it centrally."
"Fortinet FortiAnalyzer comes with a lot of prebuilt reports out of the box, making it easy for our team to generate necessary reports without much struggle."
"The best feature of Graylog is the Elasticsearch integration. We can integrate and we can run filters, such as an event of interest, and those logs we can send to any SIEM tool or as an analytic. Additionally, there are clear and well-documented implementation instructions on their website to follow if needed."
"Graylog is very handy."
"The product is scalable. The solution is stable."
"What I like about Graylog is that it's real-time and you have access to the raw data. So, you ingest it, and you have access to every message and every data item you ingest. You can then build analytics on top of that. You can look at the raw data, and you can do some volumetric estimations, such as how big traffic you have, how many messages of data of a type you have, etc."
"The ability to write custom alerts is key to information security and compliance."
"It has data adapters and lookup tables that utilize HTTP calls to APIs."
"I like the correlation and the alerting."
"One of the most valuable features is that you are able to do a very detailed search through the log messages in the overview."
"Without Splunk Enterprise Security, it would be difficult for us to manage and prioritize alerts. There's a potential to lose track of important notifications, and it's essential to our security that we do not miss anything. Splunk has improved our investigations because the reporting and dashboarding make things so much easier. We can provide weekly or monthly reports. I also like Splunk's ability to integrate."
"What is nice about the solution is that it makes it easy to build the queries, search for the events and then do analysis."
"The Splunk queries are valuable."
"Correlating data across different systems via one interface will allow you to know your environment or identify incident data in ways you never imagined."
"Overall, I would rate it a nine out of ten."
"In the past we used the different application to collect logs. We used SurfWatch and VMware to do so. But, we found that the Splunk has more capacity to do more in less time. They provide a aster speed to index all the events , and this is a huge asset."
"Splunk has significantly reduced the time in performing the task of aggregating logs, reviewing as well as time spent during investigations."
"Its integration is most valuable. Its UI is also pretty much easy."
 

Cons

"Sometimes, there is a problem with CPU consumption, where one process consumes 100%, and I need to restart FortiAnalyzer to fix this."
"Fortinet FortiAnalyzer needs to improve its pricing flexibility."
"One area for improvement could be better support for third-party products, as it doesn't have as much visibility with these compared to Fortinet's own products."
"I need some improvements in the support team since it is an area where there are certain shortcomings."
"I believe that its technical support is the only aspect that requires significant improvement."
"A possible improvement for FortiAnalyzer could be in threat intelligence. This feature might be enhanced to provide better insights and more efficient operations."
"We are concerned about the compliance of our policy and institutional philosophy."
"They need to make the monitor better."
"Graylog could improve the process of creating rules. We have to create them manually by doing parses and applying them. Other SIEM solutions have basic rules and you can create and get more events of interest."
"I would like to see a date and time in the Graylog Grok patterns so that I can save time when searching for a log. I like how the streams and the search query work, but adding a date and time will allow me to pull out a log in a milli-second."
"The area in Graylog that needs to be improved or enhanced would be the integrations."
"With technical support, you are on your own without an enterprise license."
"I would like to see a default dashboard widget that shows the topology of the clusters defined for the graylog install."
"I hope to see improvements in Graylog for more interactivity, user-friendliness, and creating alerts. The initial setup is complex."
"Graylog needs to improve their authentication. Also, the fact that Graylog displays logs from the top down is just ridiculous."
"Its scalability gets complicated when we have to update or edit multiple nodes."
"The Web Application Firewall will send you too much information because it's more dedicated to security than a normal firewall."
"Having analysts put their notes directly within the investigation feature in the incident review would be beneficial."
"Customizing our commands should be simpler. Creating custom commands in Splunk requires a long, complex process. For example, we have a command to add all the column data, but we don't have a command to get the average of the column data at the end. It would be useful to have a blank at the end to create our commands and leave the rest to others."
"The analytics of Splunk could be improved."
"I feel as though a major focus of upcoming releases should be set on Machine Learning, Predictive Analytics, and I would enjoy to see more security focused add-ons and apps developed by the vendor."
"The monitoring aspect of Splunk could be improved. We have to do some queries to get as much information as CrowdStrike or other solutions provide. If you run a big query, you will see a delay. That is the only concern we have because it will take some time if you query large data sets."
"I do not like the pricing model. It is expensive."
"Previously, they developed custom connectors or add-ons for a lot of applications. But that number can be upgraded still. There are a lot of applications in the world that are not supported."
 

Pricing and Cost Advice

"Its price is okay for us. Fortinet products are cheaper than other solutions."
"The program is expensive."
"Compared to other products, the price is a little bit high."
"t varies depending on your needs. However, after-sales support is expensive."
"All Fortinet programs come at a good price."
"The cost and pricing should be in accordance with the calculation of log storage capacity for a time period required for historical analysis."
"Fortinet FortiAnalyzer is quite an expensive tool."
"I do not know the price of Fortinet FortiAnalyzer. I did not pay for it, but I know the price of other Fortinet products. They are not cheap. I am from Poland. We have Zloty, not Euro, so for us, everything is expensive."
"It's open source and free. They have a paid version, but we never looked into that because we never needed the features of the paid version."
"We're using the Community edition."
"Consider Enterprise support if you have atypical needs or setup requirements.​"
"I am using a community edition. I have not looked at the enterprise offering from Graylog."
"If you want something that works and do not have the money for Splunk or QRadar, take Graylog.​​"
"There is an open source version and an enterprise version. I wouldn't recommend the enterprise version, but as an open source solution, it is solid and works really well."
"It's an open-source solution that can be used free of charge."
"I use the free version of Graylog."
"It can be expensive, especially the licensing costs. However, there is added value in what it can do, not just log aggregation."
"I've heard Splunk is often preferred over other options, but the cost can be prohibitive for smaller organizations."
"The price of Splunk is reasonable."
"It would be nice if the pricing were cheaper. However, we did purchase it."
"The pricing and licensing of the product are quite high."
"It's a yearly subscription."
"Splunk should be able to integrate with other product using the free version."
"Splunk Enterprise Security incurs a significant cost because of the amount of data we send, but we are fine with the value we're getting for that price."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
851,823 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Government
8%
Manufacturing Company
8%
Financial Services Firm
7%
Computer Software Company
18%
Comms Service Provider
10%
Educational Organization
7%
Government
7%
Financial Services Firm
15%
Computer Software Company
15%
Manufacturing Company
8%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Fortinet FortiAnalyzer?
The reporting features, which offer customization, real-time insights, and compliance support, are particularly notew...
What is your experience regarding pricing and costs for Fortinet FortiAnalyzer?
We pay roughly $5,000 for a solution that we needed specifically, but I do not remember the exact price. Overall, I f...
What needs improvement with Fortinet FortiAnalyzer?
The only area where it could improve is in providing better training for the tool. Some training would be beneficial,...
What do you like most about Graylog?
The product is scalable. The solution is stable.
What is your experience regarding pricing and costs for Graylog?
I am not familiar with the pricing details of Graylog, as I was not responsible for that aspect. It was determined th...
What needs improvement with Graylog?
An improvement I would suggest is in Graylog's user interface, such as allowing for font size adjustments. A potentia...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is a...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingest...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitor...
 

Also Known As

No data available
Graylog2
No data available
 

Overview

 

Sample Customers

General Directorate of Information Technology
Blue Cross Blue Shield, eBay, Cisco, LinkedIn, SAP, King.com, Twilio, Deutsche Presse-Agentur
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Wazuh, Splunk, Datadog and others in Log Management. Updated: April 2025.
851,823 professionals have used our research since 2012.