Try our new research platform with insights from 80,000+ expert users

Fortinet FortiAnalyzer vs NetWitness Platform comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiAnalyzer
Ranking in Log Management
10th
Average Rating
8.0
Reviews Sentiment
7.3
Number of Reviews
106
Ranking in other categories
No ranking in other categories
NetWitness Platform
Ranking in Log Management
33rd
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
37
Ranking in other categories
Security Information and Event Management (SIEM) (30th)
 

Mindshare comparison

As of October 2025, in the Log Management category, the mindshare of Fortinet FortiAnalyzer is 1.8%, down from 2.3% compared to the previous year. The mindshare of NetWitness Platform is 0.4%, up from 0.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management Market Share Distribution
ProductMarket Share (%)
Fortinet FortiAnalyzer1.8%
NetWitness Platform0.4%
Other97.8%
Log Management
 

Featured Reviews

Manikandan Kannan - PeerSpot reviewer
Simplifying log management by displaying detailed access information
The most valuable feature of Fortinet FortiAnalyzer is its ability to simplify and display logs clearly, providing details like which IPs are accessing the system, the destination, and the policies applied. This visualization and detail make managing logs more straightforward. In conjunction with our VMware setup, Fortinet FortiAnalyzer enhances organizational efficiency, meeting the standard log retention period for up to a year.
MOTASHIM Al Razi - PeerSpot reviewer
It is a stable solution, but they should make the user interface easier to understand
The solution's initial setup takes work. We have to organize multiple paths and many features. The deployment process takes less than a week. But it takes a month to complete if we want to make the solution smarter by integrating it with various devices. I rate the process as a six out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Report generation is very easy"
"The most valuable features are customizing reports, and the ability to drill down to display critical information in real-time."
"The IBS (Intent Based Segmentation) and application web filtering are the most valuable aspects of the solution."
"One of the greatest advantages of Fortinet FortiAnalyzer is its ability to integrate with a variety of software and solutions, providing comprehensive visibility into the network. The solution's strength lies in its capability to work with Fortinet's own products, such as the FortiAP access point, which allows for deep monitoring, automation, correlation, and incident management. However, this functionality is not present when utilizing other products, such as those from Cisco, limiting the visibility and benefits that can be gained."
"The most valuable feature of Fortinet FortiAnalyzer is the capturing of traffic for reports."
"The most valuable features of Fortinet FortiAnalyzer are the GUI and there is automation that can be done with playbooks and mini-books."
"Fortinet FortiAnalyzer is a complete package for managing our equipment."
"The most valuable feature of Fortinet FortiAnalyzer is its ability to report for several management tasks in a very short time."
"It gives the ability to investigate into network traffic in the Net and the organization what we couldn't do before."
"The most valuable feature is the hunting ability to work in a CERT."
"The software is scalable to whatever is required, and you can also put a lot of resources in the cloud."
"Setting up NetWitness is straightforward. There are multiple connectors, including standard and specialized connectors. One purpose of the connectors is the enhanced capability integrate the custom applications. NetWitness comes with E6 appliances and application images that we use for the initial configurations and for the OS stack information. From there, you can consider the correlation rules, integrate the different log sources, and easily create correlation rules and backlog reports."
"The product has a user-friendly interface and a valuable feature for threat intelligence integration."
"NetWitness can be highly beneficial for incident detection and response."
"Alerting Module: It provides real-time event processing language on all the logs/packets stream for advanced alerting, i.e., using SQL LIKE statements."
"The development of use cases on the SSA console is quite user friendly. This means that the security analyst or the researcher does not have to learn another language."
 

Cons

"When it comes to pushing logs to a SIEM, most of the time we have some issues when it comes to filtering."
"They could improve the user interface a bit."
"Though FortiAnalyzer has improved over the last few versions, the user interface still has room for improvement. It's a bit dated-looking."
"One thing we struggled with FortiAnalyzer was integration with SIEM. We also had issues with the new threats and APTs. There were false positives, so we needed to have some ratings related to false positives."
"The solution should include the ability to customize reports so that customers receive greater value and high level reporting."
"I would like to see an improvement in the technical support. Stronger authentication will also be a plus."
"Fortinet FortiAnalyzer could improve by having better integration with other vendors."
"The FortiAnalyzer is not good at managing multi-version environments. If all your FortiGate are at different versions in the field, that's difficult. The one thing we didn't like is the fact you have to have 100% of your environment at the same release, which is not pleasant, to have it fully functional. You can have a different release, but to have it fully functional 100% of your environment has to be the same release."
"Nowadays, their support is a little subpar compared to other solutions. I rate RSA support six out of 10."
"The implementation needs assistance."
"The initial setup is very complex and should be simplified."
"The product's licensing models are complex to understand. This particular area needs improvement."
"I'd like to see improvement in its ease of use. It's basically unusable. It's overly complex."
"Lots of competing products have vulnerability protection built into their products, and this solution would be improved by including that support."
"Health monitoring of the event sources and devices."
"We have encountered issues with unresolved crashes."
 

Pricing and Cost Advice

"I believe that these devices were procured with a five-year maintenance and support license up front. I work at a university, so the vendor provides a considerable higher ed discount."
"When comparing with other solutions such as Checkpoint and Cisco, Fortinet is priced well."
"When you compare with other firewall vendors, FortiAnalyzer is quite competitive in pricing."
"The cost and pricing should be in accordance with the calculation of log storage capacity for a time period required for historical analysis."
"The enterprise version of this solution is costly. We have considered FortiAuthenticator for network control, but the pricing was focused on the larger companies and didn't suit our needs as a smaller business."
"Fortinet FortiAnalyzer is very expensive."
"The product's prices are a bit higher than the other solutions available in the market, but I would say that the tool's quality and support are areas that are good."
"The pricing model is subscription-based."
"It’s cheaper to run virtual machines in a VMware environment."
"The product price was reasonable for my region and the market."
"We have yearly licensing costs. The license fee can be based on the volume of EPS. Some organizations may have, as a gentlemanly gesture, 10,000 EPS and get a 3,000 EPS license but actually use 5,000 EPS."
"The tool is very expensive, so I rate the pricing a ten out of ten. The solution has an annual subscription."
"We are on an annual license for the use of the solution."
"RSA NetWitness Logs and Packets do not have a subscription model, it's a one-time purchase. There is only a perpetual license."
"We have a perpetual license, so the total cost of ownership is not very expensive. It's a good investment."
"It provides tools to assist in selecting the appropriate license and usage scenarios."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
869,566 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
14%
Manufacturing Company
8%
Government
7%
Comms Service Provider
6%
Financial Services Firm
13%
Computer Software Company
12%
Comms Service Provider
7%
Performing Arts
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business57
Midsize Enterprise20
Large Enterprise31
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise7
Large Enterprise20
 

Questions from the Community

What do you like most about Fortinet FortiAnalyzer?
The reporting features, which offer customization, real-time insights, and compliance support, are particularly noteworthy aspects.
What is your experience regarding pricing and costs for Fortinet FortiAnalyzer?
I have experience with pricing, licensing, and setup costs as I prepare quotes for clients. While Fortinet FortiAnalyzer might be more expensive than some other solutions, it remains very competiti...
What needs improvement with Fortinet FortiAnalyzer?
When I had contact with FortiManager and Fortinet FortiAnalyzer, it was not so easy, but with some reading or training on the platform, it becomes easy to use.
What do you like most about NetWitness Platform?
The product's initial setup phase was not at all difficult.
What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem ), though there could be potential enhancements by integrating with AI.
 

Also Known As

No data available
RSA Security Analytics
 

Overview

 

Sample Customers

General Directorate of Information Technology
Los Angeles World Airports, Reply
Find out what your peers are saying about Fortinet FortiAnalyzer vs. NetWitness Platform and other solutions. Updated: September 2025.
869,566 professionals have used our research since 2012.