We use the solution for log analysis.
Senior Network Architect at NTT Global Networks Incorporated
Stable, but the initial setup is complex
Pros and Cons
- "The analyzer is the most valuable feature."
- "The deployment is complex and has room for improvement."
What is our primary use case?
What is most valuable?
The analyzer is the most valuable feature.
What needs improvement?
The deployment is complex and has room for improvement.
For how long have I used the solution?
I have been using the solution for five years.
Buyer's Guide
Fortinet FortiAnalyzer
June 2025

Learn what your peers think about Fortinet FortiAnalyzer. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,592 professionals have used our research since 2012.
What do I think about the stability of the solution?
The solution is stable.
How was the initial setup?
The initial setup is complex. The deployment took a few hours.
What about the implementation team?
The implementation was completed with an integrator.
What's my experience with pricing, setup cost, and licensing?
We pay for an annual license.
What other advice do I have?
I give the solution a six out of ten.
I do not recommend the solution.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Network Security Engineer at Social Security Commission
A good firewall activity reporting tool with next to real-time reporting capabilities, but lacking auto-detection when upgrades take place
Pros and Cons
- "We like the fact that we can run minute-by-minute reporting form this solution."
- "We would like to see some improvement on the upgrade process around this solution. There are sometimes communication issues when a new version of the firewall is implemented, and it fails to report back to this product."
What is our primary use case?
We use this solution to actively pick up and report on all activities and connectivity going through the FortiGate firewall.
What is most valuable?
We like the fact that we can run minute-by-minute reporting form this solution.
We also appreciate that the interface of this solution is very good, and doesn't require a lot of configuration, updating, or maintenance.
What needs improvement?
We would like to see some improvement on the upgrade process around this solution. There are sometimes communication issues when a new version of the firewall is implemented, and it fails to report back to this product.
We would also like to be able to pull off incident reports and display them graphically using this solution.
For how long have I used the solution?
We have been using this solution for about three years now.
What do I think about the stability of the solution?
The stability of this solution is okay. There is some room for improvement, and so we would rate the stability as an eight out of ten.
What do I think about the scalability of the solution?
We have found this to be a fairly scalable solution.
How was the initial setup?
The initial setup of this solution is very easy, and takes around three hours to complete the implementation.
What about the implementation team?
We carried out the implementation using in-house resources.
What's my experience with pricing, setup cost, and licensing?
The renewals for this solution are carried out yearly.
What other advice do I have?
We would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Fortinet FortiAnalyzer
June 2025

Learn what your peers think about Fortinet FortiAnalyzer. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,592 professionals have used our research since 2012.
Solutions Consultant at a manufacturing company with 11-50 employees
Easy to deploy, stable, and scalable
Pros and Cons
- "The most valuable feature of the solution is reporting."
- "The solution can improve the incident response function to provide more detailed information on where the incident is originating."
What is our primary use case?
The customer purchased a Fortinet Firewall in order to run it as a decentralized block and collect amazing security logs from their internet usage or other data from the box. The benefit of having an on-premise firewall is that they don't have to worry about any subscription, and the storage space it consumes is minimal due to the internal hard drive of the FortiAnalyzer. Furthermore, the firewall does not consume a lot of traffic from the internet due to it being on-premise.
What is most valuable?
The most valuable feature of the solution is reporting. The report that accompanies the solution includes the top 10 usages, threats to be aware of, and any highlights. Additionally, the API can be connected to other systems to receive more notifications.
What needs improvement?
The solution can improve the incident response function to provide more detailed information on where the incident is originating.
For how long have I used the solution?
I have been using the solution for three months.
What do I think about the stability of the solution?
The solution is stable and we have never experienced downtime.
What do I think about the scalability of the solution?
I give the scalability of the solution an eight out of ten.
This solution is suitable for enterprise customers with a large number of devices and logs. Fortinet FortiAnalyzer enables the compilation of log files over a period of time, such as 90 days in Thailand. This is especially useful for gathering and analyzing data.
How was the initial setup?
The initial setup is simple. Fortinet FortiAnalyzer is an out-of-the-box solution, so we can start customizing as soon as we finish the installation.
What's my experience with pricing, setup cost, and licensing?
I give the cost a seven out of ten. I believe that Fortinet is a cost-effective brand, making it a competitive option in terms of pricing.
Which other solutions did I evaluate?
An alternative solution is SolarWinds, which analyzes server performance, and could be a competitor's CM solution or a managed service that sends data from sensors on the site to their facility. The primary distinguishing feature of SolarWinds is its form factor. SolarWinds must be installed on a server and requires server resources. In the past, a large amount of OS and other resources were necessary, but the form factor has remained the same.
What other advice do I have?
I give the solution an eight out of ten.
Due to the high cost, Fortinet FortiAnalyzer is not feasible to use for certain office or branch office environments. A possible compromise could be to use a combination of two solutions: for banks, the file-based solution may be beneficial, but for on-premises locations, it could be worthwhile to make use of the existing value and use it to centrally control and manage the data.
I recommend utilizing the FortiAnalyzer if our log volume is sufficient and we have a FortiGate.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
You can also download premade reports on the portal, but the user experience could be better
Pros and Cons
- "FortiAnalyzer helps us discover what's happening on the network."
- "They could always improve the interface and the user experience."
What is our primary use case?
FortiAnalyzer is a log analytics tool. Our company has around 600 to 700 people.
What is most valuable?
FortiAnalyzer helps us discover what's happening on the network.
What needs improvement?
They could always improve the interface and the user experience.
For how long have I used the solution?
I have used FortiAnalyzer for four or five years.
What do I think about the stability of the solution?
I rate FortiAnalyzer eight out of 10 for stability.
What do I think about the scalability of the solution?
Scalability is irrelevant to me because we have a small setup. One analyzer is enough for me.
How was the initial setup?
Setting up FortiAnalyzer isn't complex and takes two or three hours. They have a prebuilt OVA we can deploy using Ansible. Next, we configure FortiGate to send the logs to the FortiAnalyzer. You can also download premade reports on the portal.
What's my experience with pricing, setup cost, and licensing?
You pay an annual license based on the volume of logs per day.
What other advice do I have?
I rate FortiAnalyzer seven out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Solutions Architect at a manufacturing company with 1,001-5,000 employees
User-friendly and easy to set up with good logging
Pros and Cons
- "Logging is the best feature."
- "We would like to do the reporting, logging, and administration of all the public devices and all the IoT devices. We wish to add the switches, and routers from different vendors, so it's not a vendor-specific diagnostic solution."
What is our primary use case?
Most importantly, it is for the administration of Forti fabric devices and reporting of Forti fabric, and being able to generate reports. It's for logging. All 40 fabric devices are able to send logs to FortiAnalyzer. Basically, the use cases are for administration, reporting, and logging.
What is most valuable?
Logging is the best feature.
I like how everything is integrated with the FortiGate devices, FortiAuthenticator, and other fabric devices. You're able to see all the login details for the administration of FortiGate. It offers great user connectivity using that Fortinet embodiment of the user. It gives you all those login information details.
It's easy to set up.
The solution is stable.
It can scale well.
It's very user-friendly.
What needs improvement?
The fact that it only works with FortiGate devices is quite unfair. We would like to do the reporting, logging, and administration of all the public devices and all the IoT devices. We wish to add the switches, and routers from different vendors, so it's not a vendor-specific diagnostic solution.
For how long have I used the solution?
I've been using the solution for four years now.
What do I think about the stability of the solution?
The product is 100% stable. I haven't found any issues with FortiAnalyzer. It's reliable.
What do I think about the scalability of the solution?
Depending on the licenses you procure, the number of devices, and the storage space that you have, to be able to attain those logs and reports, the solution can scale.
How are customer service and support?
Support is great. Usually, when you call on them, they are right on time, and they'll be able to assign an engineer for remote session support.
How would you rate customer service and support?
Positive
How was the initial setup?
Setting the solution up is pretty easy. It's just a matter of integrating with the Fortinet public devices. FortiGate will start sending logs and then reports to FortiAnalyzer.
Once it is set up, the solution is easy to maintain.
What's my experience with pricing, setup cost, and licensing?
I'm not sure about the exact licensing costs.
What other advice do I have?
I'm working with the latest version of the solution.
We've done on-premises and cloud deployments.
Usually, clients who don't have SIEM or Nag solutions find FortiAnalyzer quite effective as it's going to give them identification of the user activity reports on different IO devices and the usage of devices. It gives you visibility of your entire infrastructure.
I'd recommend the solution. It's very user-friendly.
I'd rate the solution eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Implementer
IT Specialist at ELTEK Multimedia
Good documentation, a nice interface and a simple setup
Pros and Cons
- "It's a very stable product."
- "Their pricing model is not the best and needs work."
What is our primary use case?
Our customers are working with this product in their companies.
I haven't really played around with it so much. Basically, we're just doing log reviews, and that's it.
What is most valuable?
The initial setup is easy.
It's a very stable product.
We can scale the product as well.
Support has been good in general.
It offers pretty good documentation.
I like the interface they offer.
What needs improvement?
I'm a reseller and integrator.
I can't really tell if anything is missing. Maybe we'll find something in the future, however, I'm not sure at the moment.
Their pricing model is not the best and needs work.
It would be nice if there were more third-party integration capabilities.
For how long have I used the solution?
I've been using the solution for six months. It hasn't been that long.
What do I think about the stability of the solution?
Like all Fortinet products, it is pretty stable. There are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
The solution is scalable and expandable. It's not an issue at all.
We have three people working on it in our organization.
How are customer service and support?
Technical support is fairly good. I haven't really needed to call support just yet.
Which solution did I use previously and why did I switch?
Our company is a Fortinet supplier. We don't deal with other solutions.
How was the initial setup?
It's an easy initial setup. The implementation is not overly complex. The deployment is pretty fast and only takes two or three hours.
What's my experience with pricing, setup cost, and licensing?
I'm not a fan of the licensing system in general. I don't like their pricing model.
What other advice do I have?
I'd rate the solution nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Senior Manager (Engineering Department) at a comms service provider with 10,001+ employees
User-friendly, easy to deploy and simple to create reports
Pros and Cons
- "The solution is quite easy to deploy."
- "The solution should be more price competitive."
How has it helped my organization?
The clients using this solution have wifi for their guests and for their own users. They want to know which user has used their wifi to access the internet, and probably use this knowledge for a kind of security management purpose.
What is most valuable?
The solution is quite easy to deploy. For the user, they don't need to have a lot of technical know-how. It is easy to generate the report for review by the management.
The solution is stable and reliable.
We have not faced any scalability issues.
What needs improvement?
The solution should be more price competitive.
For how long have I used the solution?
I've used the solution for one or two years. I used it on a recent project.
However, the first time I used this product was in 2006 for our own infrastructure. We are not using it in our infrastructure anymore.
What do I think about the stability of the solution?
The solution is stable. There are no bugs or glitches. It doesn't crash or freeze. The performance is reliable.
What do I think about the scalability of the solution?
In terms of scalability, it really depends. For our customer, the SME customer, not that many people need it. If you talk about scalability around analysis, related to the hub and space, the hub disk size, and the capacity of the box, for the on-prem model, we need to choose it with some buffer. We can't foresee any scalability issue for that customer.
We only have one client on the solution.
How are customer service and support?
While I haven't directly dealt with technical support, I have not heard any complaints from my colleagues that may have. I would say that the support has been satisfactory for the moment.
How was the initial setup?
The initial setup is pretty straightforward. That said, I didn't handle it directly. We had an internal team that did the implementation.
Most of the time, one engineer is sufficient for a small deployment, just two AP, one firewall, and one analyzer.
What about the implementation team?
The implementation work was done by my engineers. We did not need any outside assistance from any integrators or consultants.
What's my experience with pricing, setup cost, and licensing?
I can't remember if they have a new license for software maintenance. They have maintenance that is charged annually. Unlike a firewall, they have a UTM license you need to pay annually and then only an annual maintenance cost for the hardware, for FortiAnalyzer.
I'm not sure what the exact price is at the moment. However, my understanding is the pricing could be better.
What other advice do I have?
I would recommend the solution to others. We have been happy with its overall capabilities. I'd rate the solution at an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Vice President of Innovation and Customer Solutions at a tech services company with 201-500 employees
Useful reports, scalable, and priced well
Pros and Cons
- "The solution does what it is supposed to. I want it to do reports for Fortinet and it does it well."
- "The FortiAnalyzer is not good at managing multi-version environments. If all your FortiGate are at different versions in the field, that's difficult. The one thing we didn't like is the fact you have to have 100% of your environment at the same release, which is not pleasant, to have it fully functional. You can have a different release, but to have it fully functional 100% of your environment has to be the same release."
What is our primary use case?
We're a managed service provider and we use Fortinet FortiAnalyzer to generate reports for our customers. We manage our customer's Fortinet environment and FortiAnalyzer allows us to send a monthly report or on-demand report to our customers.
What is most valuable?
The solution does what it is supposed to. I want it to do reports for Fortinet and it does it well.
What needs improvement?
The FortiAnalyzer is not good at managing multi-version environments. If all your FortiGate are at different versions in the field, that's difficult. The one thing we didn't like is the fact you have to have 100% of your environment at the same release, which is not pleasant, to have it fully functional. You can have a different release, but to have it fully functional 100% of your environment has to be the same release.
In a future release, if they could turn they could turn Fortinet FortiAnalyzer into a multi-vendor supporting tool it would be awesome. However, I do not think this will happen.
For how long have I used the solution?
I used Fortinet FortiAnalyzer for approximately two years.
What do I think about the scalability of the solution?
Fortinet FortiAnalyzer is scalable.
Fortinet FortiAnalyzer is easy to scale. We have approximately 50-100 employees using this solution.
Which solution did I use previously and why did I switch?
We have other log analyzers, but we have found with Fortinet FortiAnalyzerwhen you have a Fortinet environment, it's fully integrated. This was what we were looking for, we were not looking for multi-vendor solutions, we were looking for the best log analysis tool for Fortinet.
How was the initial setup?
The solution is easy to set up.
What's my experience with pricing, setup cost, and licensing?
We found the price of Fortinet FortiAnalyzer to be reasonable.
What other advice do I have?
I would advise those wanting to use Fortinet FortiAnalyzer to use an MSP, to use a managed service provider, they can call us.
I rate Fortinet FortiAnalyzer an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner

Buyer's Guide
Download our free Fortinet FortiAnalyzer Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Log ManagementPopular Comparisons
Dynatrace
Splunk Enterprise Security
IBM Security QRadar
Elastic Security
Elastic Observability
Grafana Loki
Security Onion
LogRhythm SIEM
Elastic Stack
syslog-ng
Amazon CloudWatch
Buyer's Guide
Download our free Fortinet FortiAnalyzer Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- When evaluating Log Management tools and software, what aspect do you think is the most important to look for?
- Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
- Which Windows event log monitoring tool do you recommend?
- What is the difference between log management and SIEM?
- Splunk vs. Elastic Stack
- How can Cloudtrail logs be used effectively to improve log monitoring?
- Why hot data and cold data differences in SIEM solutions are not discussed sufficiently?
- When evaluating Log Management solutions, what aspect do you think is the most important to look for?
- When evaluating Log Management solutions, what aspects do you think are the most important to look for?
- Why are Log Management tools important for companies?