It's a lock storage correlation device. You can connect locks from different devices. Not just from Fortinet, but you can send locks from other devices to FortiAnalyzer. Basically, it is a centralized repository.
Network Security Specialist at GBM
Customer support is good, but the tool lacks a sophisticated and customizable dashboard
Pros and Cons
- "I would say that Fortinet's tech support is really good."
- "The deployment of Fortinet FortiAnalyzer is not complex, but integrating it with firewalls can take some time, depending on the number of firewalls."
What is our primary use case?
What is most valuable?
Fortinet FortiAnalyzer has a lock correlation feature. It simplifies the troubleshooting process for its customers. So now, instead of logging into every firewall, they can log into Fortinet FortiAnalyzer and check the locks. They can also check whether there are any issues with the network.
What needs improvement?
This is a difficult question for me to answer. I want the tool to have a sophisticated and customizable dashboard similar to the one in the SIEM solution. However, I'm not sure if that is in the pipeline. Basically, I would say that it's not a pure SIEM solution where your customer can have a layer on a view of dashboards or advanced dashboards.
For how long have I used the solution?
I work with Fortinet and Palo Alto. I am also a partner of Fortinet. Even though I have been working with Fortinet for more than five or six years now, Fortinet EDR is something very new for me and us in general. We have been working on firewalls, FortiAnalyzer, FortiManager, FortiMail, FortiADC, and FortiWeb. EDR, SDMA, and ZTNA are new to us. Speaking about Fortinet FortiAnalyzer, I have been working on it for more than six years now.
Buyer's Guide
Fortinet FortiAnalyzer
June 2025

Learn what your peers think about Fortinet FortiAnalyzer. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,592 professionals have used our research since 2012.
What do I think about the stability of the solution?
The stability of Fortinet FortiAnalyzer is okay. Although some customers have encountered issues, others have had a pretty okay experience and are doing pretty well with the solution.
What do I think about the scalability of the solution?
I would say that more than ten of our clients are working on this solution. I would say that it is kind of scalable since it comes in different form factors. Owing to the different form factors and sizing of the solution, you can add and get increased capacity. This can help a person to add more firewalls and devices.
How are customer service and support?
I would say that Fortinet's tech support is really good.
How would you rate customer service and support?
Neutral
How was the initial setup?
I can say that the setup is a mixture of both options. I wouldn't say it is difficult. I would rather say that the setup process is okay or moderate. Also, the straightforwardness and complexity of the setup process will depend on your environment.
The deployment of Fortinet FortiAnalyzer is not complex, but integrating it with firewalls can take some time, depending on the number of firewalls. So, the deployment of the entire solution can take approximately one week to complete.
What's my experience with pricing, setup cost, and licensing?
I'm not familiar with the cost point, because I am more of a technical person and I do not do pre-sales or sales.
Which other solutions did I evaluate?
I downloaded reports for CrowdStrike Falcon and FortiEDR from peerspot.com to see how they are in terms of performance.
What other advice do I have?
Based on current trends, people are shifting towards FortiGate devices for their attractive value proposition and exceptional performance. FortiGate is the go-to choice for firewalls. And for us, along with FortiGate, I'll even go with FortiManager and FortiAnalyzer. I rate this solution a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner

Technological Infrastructure Coordinator at IEST
Easy to configure and integrate with a straightforward setup
Pros and Cons
- "Support is helpful."
- "We are concerned about the compliance of our policy and institutional philosophy."
What is our primary use case?
The product is for reporting about the use or detecting some issues or activities.
What is most valuable?
The ability to track the activities of our users and some topics about security risks are the most valuable aspects.
It's simple to use.
It is not hard to set up.
The configuration is easy.
It offers good integration capabilities.
Support is helpful.
There is a lot of great documentation to be found online.
What needs improvement?
We are concerned about the compliance of our policy and institutional philosophy. We are a university and provide the tool to the users and to the infrastructure for the right use.
For how long have I used the solution?
I've been using the solution for six years.
What do I think about the scalability of the solution?
We have around 2,000 users.
How are customer service and support?
Support is good. We also use the documentation online and find help via some tutorials on the internet.
How was the initial setup?
The initial setup is very simple.
The deployment took about six months.
What about the implementation team?
We deployed it via our team, however, we used an external consultant from the reseller.
What's my experience with pricing, setup cost, and licensing?
We pay a standard licensing fee on a yearly basis.
The pricing is complex since we need to add some other products or tools to assure our infrastructure, then the amount of every one of the items of software otherwise the solution is expensive in the end.
What other advice do I have?
We are a customer and end-user.
I'd rate the solution nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Fortinet FortiAnalyzer
June 2025

Learn what your peers think about Fortinet FortiAnalyzer. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,592 professionals have used our research since 2012.
Corporate IT Manager at PRopex Furnishing Solutions
Stable log management support system that offers a centralized view of incident reports
Pros and Cons
- "This solution offers one view of incident management which has been the most valuable feature."
- "When using this solution, you need a high-level expert to make it work as it should."
What is our primary use case?
We use this solution to centralize the monitoring on Forti Fabrics. We monitor all firewalls and use this solution for incident management.
What is most valuable?
This solution offers one view of incident management which has been the most valuable feature.
What needs improvement?
When using this solution, you need a high-level expert to make it work as it should. We hired IT support who had knowledge of the network and firewall. For the initial step, you need a Forti expert.
For how long have I used the solution?
We have used this solution for one year.
What do I think about the stability of the solution?
This is a stable solution.
What do I think about the scalability of the solution?
This is a scalable solution.
How are customer service and support?
We have a support expert who contacts Forti when we have a problem. If we come across a bug, we need to involve Forti and open a ticket for support.
How was the initial setup?
We hired a consultant to complete the setup as it is not straightforward and requires an expert. The setup took a few days. Four IT staff look after maintenance of this solution.
What's my experience with pricing, setup cost, and licensing?
The enterprise version of this solution is costly. We have considered FortiAuthenticator for network control, but the pricing was focused on the larger companies and didn't suit our needs as a smaller business.
The pricing for this solution is on an annual basis. Databases, a virus scanner, and intrusion detection is included.
Which other solutions did I evaluate?
We have previously looked into Sophos UTM and Palo Alto.
What other advice do I have?
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior IP Network Defense at MTN
Reporting features like graphs, threat intelligence, and vulnerabilities analysis are helpful
Pros and Cons
- "FortiAnalyzer's reporting features like graphs, threat intelligence, and vulnerabilities analysis are helpful. Fortinet knows how to do reporting. You can customize your reports to show exactly what you want to analyze. It's user-friendly and doesn't require a lot of effort."
- "If Fortinet could introduce some firewalling or maybe FortiAnalyzer on the cloud, that would be interesting because I've never seen it on a cloud."
What is our primary use case?
We use FortiAnalyzer as our indicator of compromise solution, and I'm also running some SOC into it.
What is most valuable?
FortiAnalyzer's reporting features like graphs, threat intelligence, and vulnerabilities analysis are helpful. Fortinet knows how to do reporting. You can customize your reports to show exactly what you want to analyze. It's user-friendly and doesn't require a lot of effort.
The hub is another feature that's good to use. FortiAnalyzer can be connected to other Fortinet devices via the hub. It isn't restricted, and it's all controlled by FortiManager. It can also integrate all the opcodes to one box.
What needs improvement?
If Fortinet could introduce some firewalling or maybe FortiAnalyzer on the cloud, that would be interesting because I've never seen it on a cloud.
For how long have I used the solution?
We've been using FortiAnalyzer since 2015.
What do I think about the stability of the solution?
FortiAnalyzer is stable. It will do the work as long as your FortiGate is stable. It depends more on the FortiGate, so if your FortiGate is cool, there's no problem. If there is a problem, you can bypass it most of the time. I can't say that there are no issues. I don't want to lie.
What do I think about the scalability of the solution?
FortiAnalyzer is scalable. It can even take over traffic from other analyzers. You can connect as many analyzers as you want to it.
Which solution did I use previously and why did I switch?
I used a McAfee SIEM solution before at my previous employer, but it's not as powerful as FortiAnalyzer. I used a Rapid7 solution and Cisco FirePOWER, which are both weak.
How was the initial setup?
We don't need to do much to install FortiAnalyzer because it always depends on FortiGate. You need to deploy FortiGate before you install it. That's why I say that I see it as a dummy box. I don't see anything interesting in it. It's only a support structure.
What other advice do I have?
I rate FortiAnalyzer seven out of 10. It's a very user-friendly box. You don't even need to know the CLI. It has a CLI, but you don't need to know it because the GUI is excellent. It's always doing its duty to keep up with the reporting.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
System Specialist at Databros
Easy to get reports and read specific logs
Pros and Cons
- "With Fortinet FortiAnalyzer, it is easy to get reports and read specific logs."
- "Fortinet has a new bug every month, which needs to be improved."
What is our primary use case?
Our clients use Fortinet FortiAnalyzer to analyze and locate the traffic in their network. Since it's a big customer, they have both Fortinet FortiAnalyzer and Fortinet FortiManager.
What is most valuable?
With Fortinet FortiAnalyzer, it is easy to get reports and read specific logs. It provides fast log analysis for getting information. The solution helps locate if a destination is blocked or a machine communicates with the right port or server. Basic debugging can be done quickly using Fortinet FortiAnalyzer.
What needs improvement?
Fortinet has a new bug every month, which needs to be improved.
For how long have I used the solution?
I have been using Fortinet FortiAnalyzer for four years.
What do I think about the stability of the solution?
Fortinet FortiAnalyzer is a really stable solution and does not have any bugs.
What do I think about the scalability of the solution?
Fortinet FortiAnalyzer is a scalable solution.
Which solution did I use previously and why did I switch?
I have previously used the Kibana tool.
How was the initial setup?
The solution's initial setup is easy because it's a virtual machine. You have to upgrade it once every two to three years, which is a slow process. However, there aren't many features that need to be updated because the product is good.
What was our ROI?
The solution has been in our organization before I joined. Based on that, I have to say it's a good investment.
What's my experience with pricing, setup cost, and licensing?
Fortinet FortiAnalyzer is quite an expensive tool.
On a scale from one to ten, where one is cheap and ten is expensive, I rate the solution's pricing an eight out of ten.
What other advice do I have?
Users should never upgrade to the newest firmware. In the last decade, we have learned to always wait and see. Fortinet has had some bad releases. You must have good quality assurance that the product is bug-free. It is easy to maintain the solution.
Overall, I rate the solution an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Chief Technology Officer at Future Point Technologies
Comprehensive reporting and efficient log management
Pros and Cons
- "The most valuable is its robust and comprehensive reporting functionality, providing a thorough overview of various metrics."
- "I believe that its technical support is the only aspect that requires significant improvement."
What is our primary use case?
The primary use case for our clients revolves around robust reporting capabilities, addressing key aspects such as understanding diverse utilizations and the performance of network links. They specifically sought insights into bandwidth usage and detailed reporting at the application level. Additionally, an essential requirement was efficient log management. This is crucial because FortiGate has limitations on retaining logs for an extended duration, and our clients needed a solution, such as FortiAnalyzer, to effectively manage and analyze logs over an extended period.
What is most valuable?
The most valuable is its robust and comprehensive reporting functionality, providing a thorough overview of various metrics. Additionally, its ability to centrally capture logs from multiple devices proves indispensable for our SOC. This centralized log management facilitates automation processes, and we also greatly appreciate the effectiveness of its analytics features.
What needs improvement?
I believe that its technical support is the only aspect that requires significant improvement. With the current trend toward AI advancements, there's an opportunity for improved AI analytics. This could empower us to better leverage technology to detect attacks in a more effective manner.
For how long have I used the solution?
I have been working with it for more than five years.
What do I think about the stability of the solution?
It offers excellent stability capabilities. I would rate it nine out of ten.
What do I think about the scalability of the solution?
It offers a capacity of up to two thousand gigabytes of logs daily, showcasing considerable scalability. I believe it is a scalable solution that can easily accommodate increasing needs without compromising performance. Our clients fall into the enterprise category. I would rate it eight out of ten.
How are customer service and support?
The support services are often outsourced to specific regions, resulting in varying levels of technical expertise. While regions like America, the USA, Europe, and certain countries in Australia benefit from reasonable and proficient engineers, other locations may experience subpar tech support. Consequently, issue resolution can be time-consuming, leading customers to sometimes address problems independently. Particularly in terms of time efficiency, there is a need for improvement to expedite the support process. I would rate it six out of ten.
How would you rate customer service and support?
Neutral
How was the initial setup?
The initial setup was straightforward. I would rate it eight out of ten.
What about the implementation team?
The deployment process is straightforward and efficient, requiring minimal time and effort. It takes approximately thirty minutes and it's quite user-friendly.
What's my experience with pricing, setup cost, and licensing?
The pricing is reasonable. The cost structure is primarily based on factors such as the number of logs, log sizes, and the daily log storage capacity, with a minimum requirement of two gigabytes per day. The maximum storage capacity can extend up to eight thousand gigabytes of logs per day.
What other advice do I have?
I would strongly recommend utilizing it. It's an excellent product with abundant features, offered at a very reasonable price point. Overall, I would rate it eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Solutions Architect at a comms service provider with 501-1,000 employees
Easy to configure and understand with helpful support
Pros and Cons
- "The initial setup is easy, and the deployment is fast."
- "They could improve the user interface a bit."
What is our primary use case?
We primarily use the solution as a firewall and security gateway.
What is most valuable?
It is easy to configure.
The end-user finds it very easy to understand.
It's stable and reliable.
The solution is scalable.
The initial setup is easy, and the deployment is fast.
Technical support is generally helpful.
What needs improvement?
I'm not sure if any features need improvement.
They could improve the user interface a bit. The GUI could be easier to understand.
For how long have I used the solution?
I've used the solution for four years.
What do I think about the stability of the solution?
The solution is very stable. I'd rate the solution ten out of ten in terms of reliability. There are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
It's a very scalable solution. I'd rate the ability to extend ten out of ten. It's excellent.
We work with mostly small and medium companies.
How are customer service and support?
I haven't been directly involved with support. However, I have an understanding that they are very good. I haven't heard of any complaints.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I'm also familiar with Check Point. I prefer Fortinet products.
How was the initial setup?
The initial setup is straightforward. I'd rate the ease of setup eight out of ten. It is quite simple.
Deployment only takes about one week. We can handle the customer's various policies and configurations.
It only takes one person to deploy and maintain the solution. It's easy to manage the product. The customer can self-learn the solution and manage it once it is launched.
What's my experience with pricing, setup cost, and licensing?
It is a fairly affordable solution. I'd rate the solution three or four out of ten with ten being the most expensive. It's cheap It's not costly.
What other advice do I have?
We mostly resell the solution to big and small customers.
We're using the latest version of the solution.
I'd recommend the solution to others. I'd recommend Fortigate products to users in general.
I would rate the solution ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
solution architect at a non-profit with 51-200 employees
Low cost and easy to set up, but needs to be easier to use
Pros and Cons
- "There are a lot of monitoring features available."
- "They need to make the monitor better."
What is our primary use case?
We primarily use the solution as an analysis tool.
What is most valuable?
We can look at all of the logs in one place. It helps with analysis. It's useful for centralization. We're able to collect all of the logs via the analyzer.
Overall, it's a useful tool.
The cost is very low. It's one of the reasons I am using it.
There are a lot of monitoring features available.
It is easy to set up.
What needs improvement?
You have to play a lot with it in order to find what you need and how to use it.
It is not easy to use.
We were trying to monitor more problems via FortiAnalyzer, however, it was not very good.
We haven't received much help from the team. They haven't tried to make it better or more user-friendly.
They need to make the monitor better.
They really need to focus on security issues. Every manager is most concerned with this and that must be at the forefront of future designs.
For how long have I used the solution?
I've been using the solution for three or four years.
What do I think about the stability of the solution?
It is very stable and reliable. There are no bugs or glitches. I'd rate the stability nine out of ten. It doesn't crash or freeze.
What do I think about the scalability of the solution?
The scalability is okay. I'd rate it between five and seven out of ten.
We have 2,000 users on the solution right now.
How are customer service and support?
The technical support is good overall.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I did not use a similar product previously.
How was the initial setup?
The solution is very simple to set up. It is very easy to connect all other Fortinet products to this solution.
What's my experience with pricing, setup cost, and licensing?
The pricing is reasonable. I'd rate the affordability four out of ten, where ten is the most expensive.
What other advice do I have?
I'd rate the solution five out of ten overall. It's an okay product that needs to be easier to use.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Fortinet FortiAnalyzer Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Log ManagementPopular Comparisons
Dynatrace
Splunk Enterprise Security
IBM Security QRadar
Elastic Security
Elastic Observability
Grafana Loki
Security Onion
LogRhythm SIEM
Elastic Stack
syslog-ng
Amazon CloudWatch
Buyer's Guide
Download our free Fortinet FortiAnalyzer Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- When evaluating Log Management tools and software, what aspect do you think is the most important to look for?
- Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
- Which Windows event log monitoring tool do you recommend?
- What is the difference between log management and SIEM?
- Splunk vs. Elastic Stack
- How can Cloudtrail logs be used effectively to improve log monitoring?
- Why hot data and cold data differences in SIEM solutions are not discussed sufficiently?
- When evaluating Log Management solutions, what aspect do you think is the most important to look for?
- When evaluating Log Management solutions, what aspects do you think are the most important to look for?
- Why are Log Management tools important for companies?