What is our primary use case?
We use Splunk over SOC, the security operations center because it is more user-friendly for our team. Our team uses the solution extensively for traffic analysis and threat hunting.
What is most valuable?
The event handling solution in the platform is very good and useful. We can automate event-based handling solutions for example, if we have some events or issues on top of traffic, it triggers that function, and it can even get API for our firewall to ban that IP, or we can add a playbook for our attack, into the solution, and just manage the whole network based on that playbook.
What needs improvement?
The solution has very heavy features. Similar to when we get an app, usually, it's less than what we want. When we send all our logs over to the analyzer, it almost crashed on the first try. We must first get our logs tuned up and then set up the Fortinet FortiAnalyzer or it will crash. This is very complicated and heavy work for such a simple task, and it's a big issue for that app.
The setup of the solution can be improved because it is currently complex.
The cost of the solution is high and can be improved.
For how long have I used the solution?
I have been using the solution for seven years.
What do I think about the stability of the solution?
The solution is very stable.
What do I think about the scalability of the solution?
The solution is not really scalable. The solution is the largest. The solution is not in the security world and they don't have to have a threat on them to be secure. When we have a threat, we can't get distributed because our chain of logs is broken, and we don't get very regular events. We can't depend on this in the event of an accident or if they have to be reported because the chain is broken.
Which solution did I use previously and why did I switch?
Previously I used the ManageEngine Eventlog Analyzer. The solution is very lazy, it's heavy, and it has some bugs with reports. ManageEngine Eventlog Analyzer is a very bad solution.
How was the initial setup?
The initial setup is complex.
Setting up and launching a network, depending on the size can take anywhere from one or two days up to a week or more. However, in order for the network to run smoothly and be effective, it is important to continually tune and optimize that network. This is not a solution that can be set and forgotten; we need to be constantly adjusting Fortinet FortiAnalyzer to meet the needs of our network and the services we are providing.
What was our ROI?
The solution has a very high return on investment because when we encounter any problems, even functional problems, not technical problems, it is very easy and very fast to fix them and detect them using Fortinet FortiAnalyzer. With the heavy traffic, we have a lot of difficulty in the network, we can't get through. But when we have visibility on the network, and we force it, the solution is for us on the firewall. We know that the firewall is very complex because nothing is easy to configure, from the interface to the IP addresses and connectivity. We also have one filtering layer over that, even in new-generation firewalls with layer seven features we may not know what happened to our traffic if it's blocked at layer three or layer four. We need visibility, and the solution can give it to us.
What's my experience with pricing, setup cost, and licensing?
Fortinet FortiAnalyzer is very expensive. Solutions from companies like Fortinet, F5, and Juniper are very expensive, due in part to the high license fees and technical support they charge.
What other advice do I have?
I give the solution a nine out of ten.
Currently, we have five people using the solution, and we have plans to increase the solution's usage. As business owners, we need to grow our business structures and grow our staff to manage those structures.
I highly recommend the solution for a business with high and heavy traffic.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.