Try our new research platform with insights from 80,000+ expert users
Othman Alamine - PeerSpot reviewer
Senior Network Engineer at Delta Line International
Real User
Top 20
Provides great visibility into user logs and traffic
Pros and Cons
  • "The traffic log information we receive from Fortinet FortiAnalyzer is valuable."
  • "Fortinet FortiAnalyzer needs to have more out-of-the-box connectors for integration with other solutions."

What is our primary use case?

We use Fortinet FortiAnalyzer for logs and reports. We have a SOC subscription to monitor the end users' login activity and traffic.

Fortinet FortiAnalyzer is deployed by us in both on-premises and cloud environments.

How has it helped my organization?

Fortinet FortiAnalyzer provides more visibility into the logs.

What is most valuable?

The traffic log information we receive from Fortinet FortiAnalyzer is valuable.

What needs improvement?

Fortinet FortiAnalyzer needs to have more out-of-the-box connectors for integration with other solutions.

Buyer's Guide
Fortinet FortiAnalyzer
September 2025
Learn what your peers think about Fortinet FortiAnalyzer. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
867,676 professionals have used our research since 2012.

For how long have I used the solution?

I have been using Fortinet FortiAnalyzer for three months.

What do I think about the stability of the solution?

Fortinet FortiAnalyzer is stable as long as we keep it up to date. 

What do I think about the scalability of the solution?

Fortinet FortiAnalyzer is scalable.

How are customer service and support?

The technical support is great. We receive support within 24 hours of opening a ticket.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial deployment of Fortinet FortiAnalyzer is straightforward. There are two network interfaces involved: the Internet interface and the LAN interface. The LAN interface must be configured on the same subnet as the other Fortinet products to enable visibility of the network connector from the Fortinet console. Upon successful configuration, an authorization message will be received, allowing us to proceed with adding the devices to the FortiAnalyzer device manager and initiating log data collection. The deployment process is well-documented, requiring minimal personnel, and can be completed within five hours.

What's my experience with pricing, setup cost, and licensing?

The number of licenses required directly corresponds with the number of devices connected.

What other advice do I have?

I would rate Fortinet FortiAnalyzer a nine out of ten.

FortiAnalyzer enhances network security visibility with its comprehensive logging and analysis capabilities, making it a valuable tool for organizations seeking to improve their security posture. I highly recommend it.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
PeerSpot user
Security Manager at Yarix S.r.l.
Real User
We can gather logs and generate reports, but the license cost is high
Pros and Cons
  • "The most valuable feature is the capability to gather logs and generate reports."
  • "The integration with other vendors for log collection could be enhanced."

What is our primary use case?

Fortinet FortiAnalyzer is utilized to gather logs from all Fortinet products and generate reports.

What is most valuable?

The most valuable feature is the capability to gather logs and generate reports. Without this solution, the firewalls exhibit limited proficiency in displaying logs.

What needs improvement?

The integration with other vendors for log collection could be enhanced.

The licensing cost has room for improvement.

For how long have I used the solution?

I have been using Fortinet FortiAnalyzer for over three years.

What do I think about the stability of the solution?

I rate FortiAnalyzer's stability a nine out of ten. We have had instances of data loss or source loss.

What do I think about the scalability of the solution?

For our needs, FortiAnalyzer is scalable because we are not dealing with thousands of firewalls.

How are customer service and support?

The technical support is good.

How was the initial setup?

The initial setup is straightforward. The deployment took a couple of days.

For the deployment, we needed to create the server for deploying the FortiAnalyzer image and create the policy rules. We also had to complete the basic configuration of FortiAnalyzer. Following that, we configured all the resources and logs within FortiAnalyzer to collect and correlate the logs, which are then used to generate reports.

What about the implementation team?

We used a consultant for the implementation.

What's my experience with pricing, setup cost, and licensing?

We pay for an annual license, but we have the ability to determine the payment schedule with our distributor.

The cost of the license is high.

What other advice do I have?

I would give Fortinet FortiAnalyzer a rating of six out of ten. I am not satisfied with the solution as it falls short of a proper SIEM. Therefore, we would prefer to allocate more funds towards a SIEM in order to effectively collect logs.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Fortinet FortiAnalyzer
September 2025
Learn what your peers think about Fortinet FortiAnalyzer. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
867,676 professionals have used our research since 2012.
Sunail Nair - PeerSpot reviewer
Team Leader IT at Tappoo Limited
Real User
Easy to use, easy to integrate, and configures multiple devices at the same time
Pros and Cons
  • "The solution is easy to use and easy to integrate."
  • "It would be good if the product could provide data about the websites users visit."

What is our primary use case?

I use the solution for the configuration process.

What is most valuable?

Logs are the most useful feature of the solution. The solution is easy to use and easy to integrate. It helps to configure multiple devices at once.

What needs improvement?

The solution provides details like category, IP address, and location. It would be good if the product could provide data about the websites users visit.

It will be better if the product can build its UI like Cisco Meraki’s.

For how long have I used the solution?

I have been using the solution for around seven years.

What do I think about the stability of the solution?

I rate the stability an eight out of ten.

What do I think about the scalability of the solution?

Compared to most other solutions, it is easier to scale Fortinet FortiAnalyzer. We also use FortiAnalyzer VM, so the scalability is pretty flexible. Around 1000 employees in our organization use the solution.

How are customer service and support?

It is a bit of a challenge to return devices. Once we return the device to Fortinet, they will send us a replacement. This process takes a bit of time. The cost of sending the device is very high. With that money, we can buy a smaller device.

How was the initial setup?

The initial setup was very simple.

What about the implementation team?

We need three employees to maintain the solution.

What's my experience with pricing, setup cost, and licensing?

The product’s price is much better than its competitors.

What other advice do I have?

We need to have a license for individual devices to use the solution. We end up in a loop when we try to access the websites and different routes. We also have to provide the options ourselves for all our queries. The process would be better if reports and records were more readily available.

Cisco Meraki is an online portal that provides organized and in-depth reports. Overall, I rate the solution an eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Works at renesas
Real User
Easy to set up and enables separation of sections with clarity
Pros and Cons
  • "Separating sections or conditions on Fortinet FortiAnalyzer is quite clear."
  • "The product should be integrated with other third-party solutions for context exchange."

What is our primary use case?

We use the product to review firewall logs.

What is most valuable?

The solution works fine. Separating sections or conditions on Fortinet FortiAnalyzer is quite clear.

What needs improvement?

The product should be integrated with other third-party solutions for context exchange.

For how long have I used the solution?

I have been using the solution for the past two years.

What do I think about the stability of the solution?

The solution is stable. I would rate the stability a nine out of ten.

What do I think about the scalability of the solution?

The solution is scalable. Around 20 to 30 IT employees in our organization use the solution. I would rate the scalability a nine out of ten.

How was the initial setup?

The product is easy to set up.

What other advice do I have?

Around 120 employees work in the technical and maintenance department. I would recommend the solution to other users. I don’t know whether FortiNAC can be integrated with the Fortinet FortiAnalyzer. I rate the solution a nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Alain ClovisBapfunya - PeerSpot reviewer
Cyber Security Specialist at EAST-NB
Real User
It aggregates and correlates all the events from multiple sources
Pros and Cons
  • "Many of my clients are financial institutions that transmit files from around the country across a VPN. In a setup like this, it's helpful to have a centralized dashboard to manage firewalls and other security solutions across a distributed environment. You can do all sorts of analysis and configure it to trigger alarms."
  • "FortiAnalyzer only integrates with Fortinet solutions. That is a limitation because many organizations use multiple vendors. It's often a mixture of Cisco network hardware and equipment from other vendors, such as switches, access points, etc."

What is our primary use case?

FortiAnalyzer provides a centralized dashboard for analyzing the output of all our Fortinet solutions, like FortiGate, FortiManager, FortiSandbox, etc. It aggregates and correlates all the events.

What is most valuable?

Many of my clients are financial institutions that transmit files from around the country across a VPN. In a setup like this, it's helpful to have a centralized dashboard to manage firewalls and other security solutions across a distributed environment. You can do all sorts of analysis and configure it to trigger alarms. 

What needs improvement?

FortiAnalyzer only integrates with Fortinet solutions. That is a limitation because many organizations use multiple vendors. It's often a mixture of Cisco network hardware and equipment from other vendors, such as switches, access points, etc. 

For how long have I used the solution?

We have used FortiAnalyzer for one year.

What do I think about the stability of the solution?

FortiAnalyzer is stable as long as you don't push it. It can cause trouble if you are overreliant on virtual machines and you don't have hardware acceleration. You might see some performance problems. 

What do I think about the scalability of the solution?

FortiAnalyzer is scalable. It covers FortiGate firewalls, switches, etc. You can always buy more licenses or hardware if you need to upgrade. 

How are customer service and support?

The response times could be faster.

How was the initial setup?

Setting up FortiAnalyzer is straightforward. It doesn't take long because everything is already built for you unless you need to do some virtualization. The specific steps depend on your environment and what kind of device fabrics you use. 

What's my experience with pricing, setup cost, and licensing?

They have three-year licenses, but I usually recommend starting with a one-year license to try FortiAnalyzer out. After that, you can switch to a three-year license. 

What other advice do I have?

I rate FortiAnalyzer nine out of 10. I recommend FortiAnalyzer to anyone who is using Fortinet products. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Implementer
PeerSpot user
Saneesh Pv - PeerSpot reviewer
Network Security Specialist at GBM
Real User
Customer support is good, but the tool lacks a sophisticated and customizable dashboard
Pros and Cons
  • "I would say that Fortinet's tech support is really good."
  • "The deployment of Fortinet FortiAnalyzer is not complex, but integrating it with firewalls can take some time, depending on the number of firewalls."

What is our primary use case?

It's a lock storage correlation device. You can connect locks from different devices. Not just from Fortinet, but you can send locks from other devices to FortiAnalyzer. Basically, it is a centralized repository.

What is most valuable?

Fortinet FortiAnalyzer has a lock correlation feature. It simplifies the troubleshooting process for its customers. So now, instead of logging into every firewall, they can log into Fortinet FortiAnalyzer and check the locks. They can also check whether there are any issues with the network.

What needs improvement?

This is a difficult question for me to answer. I want the tool to have a sophisticated and customizable dashboard similar to the one in the SIEM solution. However, I'm not sure if that is in the pipeline. Basically, I would say that it's not a pure SIEM solution where your customer can have a layer on a view of dashboards or advanced dashboards.

For how long have I used the solution?

I work with Fortinet and Palo Alto. I am also a partner of Fortinet. Even though I have been working with Fortinet for more than five or six years now, Fortinet EDR is something very new for me and us in general. We have been working on firewalls, FortiAnalyzer, FortiManager, FortiMail, FortiADC, and FortiWeb. EDR, SDMA, and ZTNA are new to us. Speaking about Fortinet FortiAnalyzer, I have been working on it for more than six years now.

What do I think about the stability of the solution?

The stability of Fortinet FortiAnalyzer is okay. Although some customers have encountered issues, others have had a pretty okay experience and are doing pretty well with the solution.

What do I think about the scalability of the solution?

I would say that more than ten of our clients are working on this solution. I would say that it is kind of scalable since it comes in different form factors. Owing to the different form factors and sizing of the solution, you can add and get increased capacity. This can help a person to add more firewalls and devices.

How are customer service and support?

I would say that Fortinet's tech support is really good.

How would you rate customer service and support?

Neutral

How was the initial setup?

I can say that the setup is a mixture of both options. I wouldn't say it is difficult. I would rather say that the setup process is okay or moderate. Also, the straightforwardness and complexity of the setup process will depend on your environment.

The deployment of Fortinet FortiAnalyzer is not complex, but integrating it with firewalls can take some time, depending on the number of firewalls. So, the deployment of the entire solution can take approximately one week to complete.

What's my experience with pricing, setup cost, and licensing?

I'm not familiar with the cost point, because I am more of a technical person and I do not do pre-sales or sales.

Which other solutions did I evaluate?

I downloaded reports for CrowdStrike Falcon and FortiEDR from peerspot.com to see how they are in terms of performance.

What other advice do I have?

Based on current trends, people are shifting towards FortiGate devices for their attractive value proposition and exceptional performance. FortiGate is the go-to choice for firewalls. And for us, along with FortiGate, I'll even go with FortiManager and FortiAnalyzer. I rate this solution a seven out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Moises Castillo - PeerSpot reviewer
Technological Infrastructure Coordinator at IEST
Real User
Easy to configure and integrate with a straightforward setup
Pros and Cons
  • "Support is helpful."
  • "We are concerned about the compliance of our policy and institutional philosophy."

What is our primary use case?

The product is for reporting about the use or detecting some issues or activities.

What is most valuable?

The ability to track the activities of our users and some topics about security risks are the most valuable aspects.

It's simple to use.

It is not hard to set up.

The configuration is easy.

It offers good integration capabilities.

Support is helpful.

There is a lot of great documentation to be found online. 

What needs improvement?

We are concerned about the compliance of our policy and institutional philosophy. We are a university and provide the tool to the users and to the infrastructure for the right use.

For how long have I used the solution?

I've been using the solution for six years. 

What do I think about the scalability of the solution?

We have around 2,000 users.

How are customer service and support?

Support is good. We also use the documentation online and find help via some tutorials on the internet.

How was the initial setup?

The initial setup is very simple. 

The deployment took about six months. 

What about the implementation team?

We deployed it via our team, however, we used an external consultant from the reseller.

What's my experience with pricing, setup cost, and licensing?

We pay a standard licensing fee on a yearly basis. 

The pricing is complex since we need to add some other products or tools to assure our infrastructure, then the amount of every one of the items of software otherwise the solution is expensive in the end.

What other advice do I have?

We are a customer and end-user.

I'd rate the solution nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
IgnitiusMolepo - PeerSpot reviewer
Senior IP Network Defense at MTN
Real User
Top 5Leaderboard
Reporting features like graphs, threat intelligence, and vulnerabilities analysis are helpful
Pros and Cons
  • "FortiAnalyzer's reporting features like graphs, threat intelligence, and vulnerabilities analysis are helpful. Fortinet knows how to do reporting. You can customize your reports to show exactly what you want to analyze. It's user-friendly and doesn't require a lot of effort."
  • "If Fortinet could introduce some firewalling or maybe FortiAnalyzer on the cloud, that would be interesting because I've never seen it on a cloud."

What is our primary use case?

We use FortiAnalyzer as our indicator of compromise solution, and I'm also running some SOC into it. 

What is most valuable?

FortiAnalyzer's reporting features like graphs, threat intelligence, and vulnerabilities analysis are helpful. Fortinet knows how to do reporting. You can customize your reports to show exactly what you want to analyze. It's user-friendly and doesn't require a lot of effort. 

The hub is another feature that's good to use. FortiAnalyzer can be connected to other Fortinet devices via the hub. It isn't restricted, and it's all controlled by FortiManager. It can also integrate all the opcodes to one box. 

What needs improvement?

If Fortinet could introduce some firewalling or maybe FortiAnalyzer on the cloud, that would be interesting because I've never seen it on a cloud. 

For how long have I used the solution?

We've been using FortiAnalyzer since 2015. 

What do I think about the stability of the solution?

FortiAnalyzer is stable. It will do the work as long as your FortiGate is stable. It depends more on the FortiGate, so if your FortiGate is cool, there's no problem. If there is a problem, you can bypass it most of the time. I can't say that there are no issues. I don't want to lie.

What do I think about the scalability of the solution?

FortiAnalyzer is scalable. It can even take over traffic from other analyzers. You can connect as many analyzers as you want to it. 

Which solution did I use previously and why did I switch?

I used a McAfee SIEM solution before at my previous employer, but it's not as powerful as FortiAnalyzer. I used a Rapid7 solution and Cisco FirePOWER, which are both weak.

How was the initial setup?

We don't need to do much to install FortiAnalyzer because it always depends on FortiGate. You need to deploy FortiGate before you install it. That's why I say that I see it as a dummy box. I don't see anything interesting in it. It's only a support structure.

What other advice do I have?

I rate FortiAnalyzer seven out of 10. It's a very user-friendly box. You don't even need to know the CLI. It has a CLI, but you don't need to know it because the GUI is excellent. It's always doing its duty to keep up with the reporting. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Fortinet FortiAnalyzer Report and get advice and tips from experienced pros sharing their opinions.
Updated: September 2025
Product Categories
Log Management
Buyer's Guide
Download our free Fortinet FortiAnalyzer Report and get advice and tips from experienced pros sharing their opinions.