We use this solution to centralize the monitoring on Forti Fabrics. We monitor all firewalls and use this solution for incident management.
Corporate IT Manager at PRopex Furnishing Solutions
Stable log management support system that offers a centralized view of incident reports
Pros and Cons
- "This solution offers one view of incident management which has been the most valuable feature."
- "When using this solution, you need a high-level expert to make it work as it should."
What is our primary use case?
What is most valuable?
This solution offers one view of incident management which has been the most valuable feature.
What needs improvement?
When using this solution, you need a high-level expert to make it work as it should. We hired IT support who had knowledge of the network and firewall. For the initial step, you need a Forti expert.
For how long have I used the solution?
We have used this solution for one year.
Buyer's Guide
Fortinet FortiAnalyzer
September 2026
Learn what your peers think about Fortinet FortiAnalyzer. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,262 professionals have used our research since 2012.
What do I think about the stability of the solution?
This is a stable solution.
What do I think about the scalability of the solution?
This is a scalable solution.
How are customer service and support?
We have a support expert who contacts Forti when we have a problem. If we come across a bug, we need to involve Forti and open a ticket for support.
How was the initial setup?
We hired a consultant to complete the setup as it is not straightforward and requires an expert. The setup took a few days. Four IT staff look after maintenance of this solution.
What's my experience with pricing, setup cost, and licensing?
The enterprise version of this solution is costly. We have considered FortiAuthenticator for network control, but the pricing was focused on the larger companies and didn't suit our needs as a smaller business.
The pricing for this solution is on an annual basis. Databases, a virus scanner, and intrusion detection is included.
Which other solutions did I evaluate?
We have previously looked into Sophos UTM and Palo Alto.
What other advice do I have?
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior IP Network Defense at MTN
Reporting features like graphs, threat intelligence, and vulnerabilities analysis are helpful
Pros and Cons
- "FortiAnalyzer's reporting features like graphs, threat intelligence, and vulnerabilities analysis are helpful. Fortinet knows how to do reporting. You can customize your reports to show exactly what you want to analyze. It's user-friendly and doesn't require a lot of effort."
- "If Fortinet could introduce some firewalling or maybe FortiAnalyzer on the cloud, that would be interesting because I've never seen it on a cloud."
- "We don't need to do much to install FortiAnalyzer because it always depends on FortiGate. You need to deploy FortiGate before you install it. That's why I say that I see it as a dummy box. I don't see anything interesting in it. It's only a support structure."
What is our primary use case?
We use FortiAnalyzer as our indicator of compromise solution, and I'm also running some SOC into it.
What is most valuable?
FortiAnalyzer's reporting features like graphs, threat intelligence, and vulnerabilities analysis are helpful. Fortinet knows how to do reporting. You can customize your reports to show exactly what you want to analyze. It's user-friendly and doesn't require a lot of effort.
The hub is another feature that's good to use. FortiAnalyzer can be connected to other Fortinet devices via the hub. It isn't restricted, and it's all controlled by FortiManager. It can also integrate all the opcodes to one box.
What needs improvement?
If Fortinet could introduce some firewalling or maybe FortiAnalyzer on the cloud, that would be interesting because I've never seen it on a cloud.
For how long have I used the solution?
We've been using FortiAnalyzer since 2015.
What do I think about the stability of the solution?
FortiAnalyzer is stable. It will do the work as long as your FortiGate is stable. It depends more on the FortiGate, so if your FortiGate is cool, there's no problem. If there is a problem, you can bypass it most of the time. I can't say that there are no issues. I don't want to lie.
What do I think about the scalability of the solution?
FortiAnalyzer is scalable. It can even take over traffic from other analyzers. You can connect as many analyzers as you want to it.
Which solution did I use previously and why did I switch?
I used a McAfee SIEM solution before at my previous employer, but it's not as powerful as FortiAnalyzer. I used a Rapid7 solution and Cisco FirePOWER, which are both weak.
How was the initial setup?
We don't need to do much to install FortiAnalyzer because it always depends on FortiGate. You need to deploy FortiGate before you install it. That's why I say that I see it as a dummy box. I don't see anything interesting in it. It's only a support structure.
What other advice do I have?
I rate FortiAnalyzer seven out of 10. It's a very user-friendly box. You don't even need to know the CLI. It has a CLI, but you don't need to know it because the GUI is excellent. It's always doing its duty to keep up with the reporting.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Fortinet FortiAnalyzer
September 2026
Learn what your peers think about Fortinet FortiAnalyzer. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,262 professionals have used our research since 2012.
Senior Technical Sales Engineer at Logicalis
A solution for firewall, URL filtering, and SD-WAN
Pros and Cons
- "We use the solution for enterprise firewalls, URL filtering, and SD-WAN."
- "The solution could embed monitoring."
What is our primary use case?
We use the solution for enterprise firewalls, URL filtering, and SD-WAN.
What needs improvement?
The solution could embed monitoring.
For how long have I used the solution?
I have been using Fortinet FortiAnalyzer for a year. We are using V6.2 of the solution.
What do I think about the scalability of the solution?
The solution’s scalability is good. 500 users are using this solution. The solution is suitable for small and medium businesses.
I rate the solution’s scalability a seven out of ten.
How are customer service and support?
When the case is unresolved, the following person takes time to get involved in the tickets. The information may be complex.
How would you rate customer service and support?
Neutral
How was the initial setup?
The initial setup is easy. I rate the initial setup an eight out of ten, where one is difficult and ten is easy.
What's my experience with pricing, setup cost, and licensing?
The solution's pricing is good.
What other advice do I have?
I recommend it because it's a perfect solution.
Overall, I rate the solution a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
IT Manager at a manufacturing company with 201-500 employees
Notifications and alerts are helpful, and it is a natural choice for Fortinet security devices
Pros and Cons
- "Special notifications about compromised phones are valuable because we have some guest networks, and sometimes, people are connecting phones that are connected to compromised websites. We want to be informed about it. We sometimes have some cases where we want to analyze the connection from inside to outside ports. So, it helps with a lot of things. It depends on our needs."
- "The interface or GUI does not work properly on Microsoft Edge. The behavior or the view is different on Microsoft Edge versus on Chrome or Firefox. When some buttons do not work, I am forced to switch to Firefox."
What is our primary use case?
We take all the logs from FortiGate.
We have it deployed on-premises, and we are definitely using its latest version because we are creating a new virtual machine.
What is most valuable?
Special notifications about compromised phones are valuable because we have some guest networks, and sometimes, people are connecting phones that are connected to compromised websites. We want to be informed about it. We sometimes have some cases where we want to analyze the connection from inside to outside ports. So, it helps with a lot of things. It depends on our needs.
What needs improvement?
The interface or GUI does not work properly on Microsoft Edge. The behavior or the view is different on Microsoft Edge versus on Chrome or Firefox. When some buttons do not work, I am forced to switch to Firefox.
There could be better analysis from the client's perspective. If you have FortiClient EMS, you should be able to analyze users more than the connections.
For how long have I used the solution?
We started using Fortinet FortiAnalyzer this year. It was bought by our main company in the Netherlands.
What do I think about the stability of the solution?
It is now stable, but our previous instance was unstable. We had problems with connectivity. It was strange because it is a virtual machine, and it was on the same hypervisor or host, but only Fortinet FortiAnalyzer had connectivity problems. The connection was dropped, and it was not always possible to log in. We moved it to a different environment. We have now moved it to a Hyper-V cluster on a different site in Poland, and it is now stable.
What do I think about the scalability of the solution?
It is scalable. We could change the size. It was easy.
We have mainly two people working with Fortinet FortiAnalyzer. My colleague and I from the Netherlands work on it. All IT departments also can access it. In total, we have five or six users, but mainly, two of us work on it.
How are customer service and support?
I use their technical support when I have problems. They solve my problems, but sometimes, they take time because it is difficult to understand each other. I prefer a phone call over the email or ticket system because we can share more information in a short time. I would rate them a nine out of ten. They sometimes do not have a fast solution, but they always resolve an issue in the end.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I did not work on any similar product previously.
How was the initial setup?
It was easy to deploy. It took one hour.
What about the implementation team?
We deployed it ourselves. We know the product. We know how to register devices and how to join devices. It was easy. We used our knowledge.
What's my experience with pricing, setup cost, and licensing?
I do not know the price of Fortinet FortiAnalyzer. I did not pay for it, but I know the price of other Fortinet products. They are not cheap. I am from Poland. We have Zloty, not Euro, so for us, everything is expensive.
I had also tried to buy it in the past, but it was too expensive.
What other advice do I have?
If you have FortiGate and FortiClient EMS, FortiAnalyzer is a natural choice. You can have notifications and alerts. Some things are automatically done by FortiAnalyzer. From a security perspective, it is a very good product.
Overall, we are satisfied with it. I would rate Fortinet FortiAnalyzer an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Network Architect at INISI b.v.
The monitoring features are quite impressive, including maps, source IP, country codes, and geolocation
Pros and Cons
- "What I like the most is the monitoring system."
- "The UI can be more user-friendly for new users."
What is our primary use case?
We are an IT company. One of our clients utilizes FortiGate, FortiAnalyzer, and FortiManager. Thus, this is the sole customer in our portfolio using Fortinet FortiAnalyzer. Among our other clients, some exclusively employ FortiGate. Our responsibility encompasses network management for these clients.
What is most valuable?
What I like the most is the monitoring system. For example, it can track who is accessing through VPNs. The monitoring features are quite impressive, including maps, source IP, country codes, and geolocation – all of which are really cool. Additionally, the logging functionality is also excellent.
What needs improvement?
The UI can be more user-friendly for new users.
For how long have I used the solution?
I have been using Fortinet FortiAnalyzer for seven years.
What do I think about the stability of the solution?
Fortinet FortiAnalyzer is highly stable. In the seven years of usage, we have never needed to reinstall it or perform troubleshooting. We have not had to make any support calls to Fortinet either. We successfully performed upgrades from version five to six and from six to seven, all of which went smoothly.
What do I think about the scalability of the solution?
Fortinet FortiAnalyzer is scalable.
How are customer service and support?
The technical support is excellent. I have never encountered any problems with FortiAnalyzer, but the issues we faced with FortiGate, which I was unable to resolve on my own, were promptly resolved by their team.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is straightforward. We can choose to install either a single node or a cluster. We run it in a virtual environment on firmware, and the process of installing the RPA takes around 15 minutes. Afterward, some configuration is required, including the installation of certificates and similar tasks. Thus, the entire process usually takes approximately one to two hours.
Once the installation is complete, we need to connect all the FortiGate Firewalls to the FortiAnalyzer. This step also involves configuring them securely. When I deploy this solution for a customer, it typically takes me about four to eight hours to complete the installation and configuration.
What's my experience with pricing, setup cost, and licensing?
The price is not expensive when compared to other solutions like Palo Alto.
In addition to the licensing, we pay for a support contract.
What other advice do I have?
I would rate Fortinet FortiAnalyzer eight out of ten.
Fortinet FortiAnalyzer is only valuable for organizations that utilize ten or more FortiGates.
I recommend Fortinet FortiAnalyzer to others.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Team Leader IT at Tappoo Limited
Easy to use, easy to integrate, and configures multiple devices at the same time
Pros and Cons
- "The solution is easy to use and easy to integrate."
- "It would be good if the product could provide data about the websites users visit."
What is our primary use case?
I use the solution for the configuration process.
What is most valuable?
Logs are the most useful feature of the solution. The solution is easy to use and easy to integrate. It helps to configure multiple devices at once.
What needs improvement?
The solution provides details like category, IP address, and location. It would be good if the product could provide data about the websites users visit.
It will be better if the product can build its UI like Cisco Meraki’s.
For how long have I used the solution?
I have been using the solution for around seven years.
What do I think about the stability of the solution?
I rate the stability an eight out of ten.
What do I think about the scalability of the solution?
Compared to most other solutions, it is easier to scale Fortinet FortiAnalyzer. We also use FortiAnalyzer VM, so the scalability is pretty flexible. Around 1000 employees in our organization use the solution.
How are customer service and support?
It is a bit of a challenge to return devices. Once we return the device to Fortinet, they will send us a replacement. This process takes a bit of time. The cost of sending the device is very high. With that money, we can buy a smaller device.
How was the initial setup?
The initial setup was very simple.
What about the implementation team?
We need three employees to maintain the solution.
What's my experience with pricing, setup cost, and licensing?
The product’s price is much better than its competitors.
What other advice do I have?
We need to have a license for individual devices to use the solution. We end up in a loop when we try to access the websites and different routes. We also have to provide the options ourselves for all our queries. The process would be better if reports and records were more readily available.
Cisco Meraki is an online portal that provides organized and in-depth reports. Overall, I rate the solution an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cyber Security Specialist at EAST-NB
It aggregates and correlates all the events from multiple sources
Pros and Cons
- "Many of my clients are financial institutions that transmit files from around the country across a VPN. In a setup like this, it's helpful to have a centralized dashboard to manage firewalls and other security solutions across a distributed environment. You can do all sorts of analysis and configure it to trigger alarms."
- "FortiAnalyzer only integrates with Fortinet solutions. That is a limitation because many organizations use multiple vendors. It's often a mixture of Cisco network hardware and equipment from other vendors, such as switches, access points, etc."
What is our primary use case?
FortiAnalyzer provides a centralized dashboard for analyzing the output of all our Fortinet solutions, like FortiGate, FortiManager, FortiSandbox, etc. It aggregates and correlates all the events.
What is most valuable?
Many of my clients are financial institutions that transmit files from around the country across a VPN. In a setup like this, it's helpful to have a centralized dashboard to manage firewalls and other security solutions across a distributed environment. You can do all sorts of analysis and configure it to trigger alarms.
What needs improvement?
FortiAnalyzer only integrates with Fortinet solutions. That is a limitation because many organizations use multiple vendors. It's often a mixture of Cisco network hardware and equipment from other vendors, such as switches, access points, etc.
For how long have I used the solution?
We have used FortiAnalyzer for one year.
What do I think about the stability of the solution?
FortiAnalyzer is stable as long as you don't push it. It can cause trouble if you are overreliant on virtual machines and you don't have hardware acceleration. You might see some performance problems.
What do I think about the scalability of the solution?
FortiAnalyzer is scalable. It covers FortiGate firewalls, switches, etc. You can always buy more licenses or hardware if you need to upgrade.
How are customer service and support?
The response times could be faster.
How was the initial setup?
Setting up FortiAnalyzer is straightforward. It doesn't take long because everything is already built for you unless you need to do some virtualization. The specific steps depend on your environment and what kind of device fabrics you use.
What's my experience with pricing, setup cost, and licensing?
They have three-year licenses, but I usually recommend starting with a one-year license to try FortiAnalyzer out. After that, you can switch to a three-year license.
What other advice do I have?
I rate FortiAnalyzer nine out of 10. I recommend FortiAnalyzer to anyone who is using Fortinet products.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Implementer
Solutions Architect at a comms service provider with 501-1,000 employees
Easy to configure and understand with helpful support
Pros and Cons
- "The initial setup is easy, and the deployment is fast."
- "They could improve the user interface a bit."
What is our primary use case?
We primarily use the solution as a firewall and security gateway.
What is most valuable?
It is easy to configure.
The end-user finds it very easy to understand.
It's stable and reliable.
The solution is scalable.
The initial setup is easy, and the deployment is fast.
Technical support is generally helpful.
What needs improvement?
I'm not sure if any features need improvement.
They could improve the user interface a bit. The GUI could be easier to understand.
For how long have I used the solution?
I've used the solution for four years.
What do I think about the stability of the solution?
The solution is very stable. I'd rate the solution ten out of ten in terms of reliability. There are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
It's a very scalable solution. I'd rate the ability to extend ten out of ten. It's excellent.
We work with mostly small and medium companies.
How are customer service and support?
I haven't been directly involved with support. However, I have an understanding that they are very good. I haven't heard of any complaints.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I'm also familiar with Check Point. I prefer Fortinet products.
How was the initial setup?
The initial setup is straightforward. I'd rate the ease of setup eight out of ten. It is quite simple.
Deployment only takes about one week. We can handle the customer's various policies and configurations.
It only takes one person to deploy and maintain the solution. It's easy to manage the product. The customer can self-learn the solution and manage it once it is launched.
What's my experience with pricing, setup cost, and licensing?
It is a fairly affordable solution. I'd rate the solution three or four out of ten with ten being the most expensive. It's cheap It's not costly.
What other advice do I have?
We mostly resell the solution to big and small customers.
We're using the latest version of the solution.
I'd recommend the solution to others. I'd recommend Fortigate products to users in general.
I would rate the solution ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
solution architect at a non-profit with 51-200 employees
Low cost and easy to set up, but needs to be easier to use
Pros and Cons
- "There are a lot of monitoring features available."
- "They need to make the monitor better."
What is our primary use case?
We primarily use the solution as an analysis tool.
What is most valuable?
We can look at all of the logs in one place. It helps with analysis. It's useful for centralization. We're able to collect all of the logs via the analyzer.
Overall, it's a useful tool.
The cost is very low. It's one of the reasons I am using it.
There are a lot of monitoring features available.
It is easy to set up.
What needs improvement?
You have to play a lot with it in order to find what you need and how to use it.
It is not easy to use.
We were trying to monitor more problems via FortiAnalyzer, however, it was not very good.
We haven't received much help from the team. They haven't tried to make it better or more user-friendly.
They need to make the monitor better.
They really need to focus on security issues. Every manager is most concerned with this and that must be at the forefront of future designs.
For how long have I used the solution?
I've been using the solution for three or four years.
What do I think about the stability of the solution?
It is very stable and reliable. There are no bugs or glitches. I'd rate the stability nine out of ten. It doesn't crash or freeze.
What do I think about the scalability of the solution?
The scalability is okay. I'd rate it between five and seven out of ten.
We have 2,000 users on the solution right now.
How are customer service and support?
The technical support is good overall.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I did not use a similar product previously.
How was the initial setup?
The solution is very simple to set up. It is very easy to connect all other Fortinet products to this solution.
What's my experience with pricing, setup cost, and licensing?
The pricing is reasonable. I'd rate the affordability four out of ten, where ten is the most expensive.
What other advice do I have?
I'd rate the solution five out of ten overall. It's an okay product that needs to be easier to use.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Technology Administrator at Omnient SRL
Offers a great overview of the logs and integrates perfectly
Pros and Cons
- "It is easy to integrate Fortinet FortiAnalyzer with other products. You have a better overview of what's going on."
- "The only issue that I can see is with the cost. For example, if you buy support for one year, you are messed up next year. It's better to buy another gateway."
What is our primary use case?
We collect the logs from Fortinet in order to search and get a better view of everything that's coming from FortiGate because the overview on FortiGate isn't the same. FortiAnalyzer provides an overview of the logs and everything that's happening there. We integrate FortiGate and FortiAnalyzer with the SOC that we're working on, which is an open-source security solution.
The other use case is to have logs. Because otherwise, in FortiGate, you don't have logs for a long period of time. You only have seven days if you don't have an account in FortiGuard. So, FortiAnalyzer provides a better understanding of what's happening there. And for our clients, we always recommend FortiAnalyzer.
FortiGate by itself is a good choice, but without FortiAnalyzer, you lose a lot of features. Even the free version of FortiAnalyzer provides some useful features.
What is most valuable?
It is easy to integrate Fortinet FortiAnalyzer with other products. You have a better overview of what's going on. For example, you get a smaller alert for an infected workstation if it causes some suspicious traffic, you see it right away in Fortinet.
What needs improvement?
The only issue that I can see is with the cost. For example, if you buy support for one year, you are messed up next year. It's better to buy another gateway.
For how long have I used the solution?
I have been using Fortinet FortiAnalyzer for one year, and I am currently working with the latest version.
What do I think about the stability of the solution?
It is a very stable solution and integrates perfectly.
What do I think about the scalability of the solution?
It is a scalable solution. Our company is very proud of FortiGate solutions.
How are customer service and support?
The support team is good. We have some cases open with them, and they resolve them very quickly. Even when there is a breach of security, they patch it quickly.
How was the initial setup?
It is very easy to set up and deploy. Even someone with little networking knowledge or a manager can quickly understand what's happening in the network, such as an increase in traffic from specific endpoints or which websites are being browsed, including social media.
What's my experience with pricing, setup cost, and licensing?
You get a gateway, but without support, it's not worth much. We've also tried FortiGate virtual machines, but the price is so high that it's better to buy other appliances than to buy the license for the VM.
We also work with third-party solutions. However, this solution is not for everyone, and even though it's free, it's easy to implement when you have money.
Overall, I would rate it an eight out of ten.
What other advice do I have?
I would advise buying FortiGate and FortiAnalyzer together. They get it free of charge. When you buy FortiGate, you can put in a FortiAnalyzer VM for free. Although the free version has its limitations, you should get it because it doesn't cost you anything. When you try the free version of FortiAnalyzer, you'll see its potential, and you'll want more.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Buyer's Guide
Download our free Fortinet FortiAnalyzer Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Product Categories
Log ManagementPopular Comparisons
Splunk Enterprise Security
Dynatrace
IBM Security QRadar
Elastic Security
LogRhythm SIEM
Elastic Observability
Coralogix
Grafana Loki
IBM SevOne Network Performance Management (NPM)
LevelBlue USM Anywhere
Graylog Enterprise
Amazon OpenSearch Service
Buyer's Guide
Download our free Fortinet FortiAnalyzer Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- When evaluating Log Management tools and software, what aspect do you think is the most important to look for?
- Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
- Which Windows event log monitoring tool do you recommend?
- What is the difference between log management and SIEM?
- Splunk vs. Elastic Stack
- How can Cloudtrail logs be used effectively to improve log monitoring?
- Why hot data and cold data differences in SIEM solutions are not discussed sufficiently?
- When evaluating Log Management solutions, what aspect do you think is the most important to look for?
- When evaluating Log Management solutions, what aspects do you think are the most important to look for?
- Why are Log Management tools important for companies?






















