The primary use case for Analyzer, is for keeping the logs and for different types of reporting.
CEO at Corem Technologies
Robust reporting and flexible connectivity
Pros and Cons
- "The features that our customers have found most valuable are their different type of reports including the drill down report, as well as the flexibility to connect to any number of appliances which can be connected to it centrally."
- "For customers who need to have different types of reporting presentable to different levels of hierarchy, FortiAnalyzer is a lovely solution."
- "Pricing-wise, it not affordable for the normal customer. Most of the people want to see different types of reporting, but FortiAnalyzer's fee is a little bit difficult."
- "Pricing-wise, it is not affordable for the normal customer."
What is our primary use case?
What is most valuable?
The features that our customers have found most valuable are their different type of reports including the drill down report, as well as the flexibility to connect to any number of appliances which can be connected to it centrally.
What needs improvement?
In terms of what can be improved, of course the cloud storage possibilities are there, but the cost and the renewal parts are high. Pricing-wise, it not affordable for the normal customer. Most of the people want to see different types of reporting, but FortiAnalyzer's fee is a little bit difficult.
For how long have I used the solution?
We have been selling and supporting FortiAnalyzer for customers for three to four years.
Buyer's Guide
Fortinet FortiAnalyzer
September 2026
Learn what your peers think about Fortinet FortiAnalyzer. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,262 professionals have used our research since 2012.
What do I think about the stability of the solution?
All the Fortinet services are very stable products.
Maintenance and networking are under the Fortinet warranty so we cannot do anything on that. It means we can just coordinate things. It is based on the ticket.
What do I think about the scalability of the solution?
I don't think the built-in memory can be upgraded for the Analyzer. I think it is not possible. That means that the hardware is more suitable for large companies.
How are customer service and support?
Their support is fairly good.
How was the initial setup?
The initial setup was simple.
What's my experience with pricing, setup cost, and licensing?
In terms of fees, one is subscription and one is the hardware warranty. There are two types of subscriptions - one is a security subscription and the other one is the support.
A lot of products are coming with built-in facilities, but FortiAnalyzer is a much better solution. People may like it, but affordability is a problem.
What other advice do I have?
For customers who need to have different types of reporting presentable to different levels of hierarchy, FortiAnalyzer is a lovely solution. Otherwise, there is no point in getting some logs. It should be presentable.
On a scale of one to ten, I'll give FortiAnalyzer an eight or nine.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Security Engineer at a recreational facilities/services company with 10,001+ employees
It runs very well on its own and doesn't really need much TLC
Pros and Cons
- "FortiAnalyzer has a robust ability to find a compromised host on your network, and when you identify a compromised host, you can address it."
- "FortiAnalyzer makes it much easier for us to find an apparently compromised host on the network."
- "Though FortiAnalyzer has improved over the last few versions, the user interface still has room for improvement. It's a bit dated-looking."
What is our primary use case?
The normal use case for FortiAnalyzer is log review, log analysis, etc.
How has it helped my organization?
FortiAnalyzer makes it much easier for us to find an apparently compromised host on the network.
What is most valuable?
FortiAnalyzer has a robust ability to find a compromised host on your network, and when you identify a compromised host, you can address it.
What needs improvement?
Though FortiAnalyzer has improved over the last few versions, the user interface still has room for improvement. It's a bit dated-looking. I guess that's the nicest way to describe it. In FortiAnalyzer, I would like the ability to turn off some of the services. So, for example, FortiAnalyzer can take data from FortiCamera products and turn off the FortiCamera stuff to lighten the load on the box or turn off the FortiSock product.
For how long have I used the solution?
I've been using FortiAnalyzer for about seven years.
What do I think about the stability of the solution?
FortiAnalyzer is really stable. It runs very well on its own and doesn't really need much TLC. It's a good product.
What do I think about the scalability of the solution?
It's pretty scalable. The units that we have are the right size for the amount of stuff that we're running, but they do have products that scale up to handle significantly more Fortigate firewalls in log stuff than we do. I would say about 20 people use FortiAnalyzer. There's me, the security engineer, and the network engineering team, which uses it to look at stuff on the firewalls or check the firewall logs. And our information security group uses it to look at stuff that's going on with the firewalls as well as compromised hosts. It is being used pretty well as we get further down the path of deploying our FortiGate-managed endpoint product. There'll be more users and probably more use cases for it in the future.
Which solution did I use previously and why did I switch?
I haven't really used a different solution previously. We've always used FortiAnalyzer in concert with Splunk.
How was the initial setup?
FortiAnalyzer is a pretty straightforward product to deploy. It took half a day to deploy a pair of FortiAnalyzers and set them up in high availability mode. I deployed it by myself. These are hardware appliances, so there were a couple of devices that needed to be racked, powered, and configured.
What's my experience with pricing, setup cost, and licensing?
I believe that these devices were procured with a five-year maintenance and support license up front. I work at a university, so the vendor provides a considerable higher ed discount.
Which other solutions did I evaluate?
It's all part of our Fortinet ecosystem, so we didn't really consider alternatives. I have a significant investment in FortiGate firewalls, so it just made sense to add FortiAnalyzer.
What other advice do I have?
I rate FortiAnalyzer eight out of 10. It does an outstanding job of what it does. But the vendor doesn't necessarily live up to the hype, which is why it only got an eight out of 10. There's a lot of hype about the Fortinet security fabric. But for the large customers that buy their large firewalls and deploy them in infrastructure components, the Fortinet fabric does not work. If you are considering FortiAnalyzer, I suggest having a complete understanding of how your firewall infrastructure works in terms of what data you're going to and from it for analysis and what you're looking for in that analysis.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Fortinet FortiAnalyzer
September 2026
Learn what your peers think about Fortinet FortiAnalyzer. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,262 professionals have used our research since 2012.
Co-founder at Korunet
User-friendly interface with a quick response and good analytics
Pros and Cons
- "FortiAnalyzer has a user-friendly interface with a quick response and good analytics. It's very secure because it's taking the log from the devices on a secure channel, so there is no problem with that in your network."
- "The cost of FortiAnalyzer could be cheaper, especially when you are installing to a VM. For 90 percent of customers, the VM solution is enough."
What is our primary use case?
For most of our customers, we are installing FortiAnalyzer as a VM-based solution. We installed a big analyzer for just one customer because they needed too much storage capacity. We have about 10 clients using it currently.
How has it helped my organization?
We prepare reports for our customers, and when the manager sees them, he's pleased. They show how many users connected, how many attacks happened, and the number of attacks stopped. The management of the IP depends on your report, so the customers need it. We are customizing these reports every day or every week, depending on what the customers need. We send emails with these reports, and the managers are also pleased about it. Also, technical guys are thrilled because they can solve problems very quickly. It's working on the SQL Server, so techs can do a quick search in real-time and see everything in the port analyzer's interface query.
What is most valuable?
FortiAnalyzer has a user-friendly interface with a quick response and good analytics. It's very secure because it's taking the log from the devices on a secure channel, so there is no problem with that in your network. Because you're getting the information from a secure channel, it's also possible to back it up in a storage solution.
For how long have I used the solution?
We have been installing FortiAnalyzer bundled with other products for about six or seven years.
How was the initial setup?
Setting up FortiAnalyzer is very straightforward. It takes just 30 minutes or less. With our installation, we sent our FortiGates log, email logs, and other logs for the three devices we're currently running to the analyzers we are using within the public architecture.
What's my experience with pricing, setup cost, and licensing?
The license depends on the storage capacity. If you want to take a log of up to 1 gigabyte daily, it's free, if I remember correctly. But if you want 5 gigabytes daily, it's licensed at different prices. The cost of FortiAnalyzer could be cheaper, especially when you are installing to a VM. For 90 percent of customers, the VM solution is enough.
What other advice do I have?
I would rate FortiAnalyzer 10 out of 10
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
System Specialist at Databros
Easy to get reports and read specific logs
Pros and Cons
- "With Fortinet FortiAnalyzer, it is easy to get reports and read specific logs."
- "Fortinet has a new bug every month, which needs to be improved."
What is our primary use case?
Our clients use Fortinet FortiAnalyzer to analyze and locate the traffic in their network. Since it's a big customer, they have both Fortinet FortiAnalyzer and Fortinet FortiManager.
What is most valuable?
With Fortinet FortiAnalyzer, it is easy to get reports and read specific logs. It provides fast log analysis for getting information. The solution helps locate if a destination is blocked or a machine communicates with the right port or server. Basic debugging can be done quickly using Fortinet FortiAnalyzer.
What needs improvement?
Fortinet has a new bug every month, which needs to be improved.
For how long have I used the solution?
I have been using Fortinet FortiAnalyzer for four years.
What do I think about the stability of the solution?
Fortinet FortiAnalyzer is a really stable solution and does not have any bugs.
What do I think about the scalability of the solution?
Fortinet FortiAnalyzer is a scalable solution.
Which solution did I use previously and why did I switch?
I have previously used the Kibana tool.
How was the initial setup?
The solution's initial setup is easy because it's a virtual machine. You have to upgrade it once every two to three years, which is a slow process. However, there aren't many features that need to be updated because the product is good.
What was our ROI?
The solution has been in our organization before I joined. Based on that, I have to say it's a good investment.
What's my experience with pricing, setup cost, and licensing?
Fortinet FortiAnalyzer is quite an expensive tool.
On a scale from one to ten, where one is cheap and ten is expensive, I rate the solution's pricing an eight out of ten.
What other advice do I have?
Users should never upgrade to the newest firmware. In the last decade, we have learned to always wait and see. Fortinet has had some bad releases. You must have good quality assurance that the product is bug-free. It is easy to maintain the solution.
Overall, I rate the solution an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Head Cyberdefense at a tech vendor with 5,001-10,000 employees
Offers fast report generation and logging with easy deployment
Pros and Cons
- "Report generation is very easy"
- "The upgradation process is slow"
What is our primary use case?
As part of a company, we manage customers of Fortinet FortiAnalyzer. The solution is used to analyze and locate traffic in a particular network.
How has it helped my organization?
Fortinet FortiAnalyzer has helped my organization improve operational efficiency. The company has been using it for ten years.
What is most valuable?
Report generation is very easy when using Fortinet FortiAnalyzer. Checking and reading the logs becomes seamless with the solution. Fortinet FortiAnalyzer also allows fast logging on a license when requesting information. For example, when you are trying to locate a logged destination or using the tool to find an error or fault, the basic networking is very fast.
What needs improvement?
The upgrade process for Fortinet FortiAnalyzer is slow.
For how long have I used the solution?
I have been using Fortinet FortiAnalyzer for four years.
What do I think about the stability of the solution?
Fortinet FortiAnalyzer is a stable product.
What do I think about the scalability of the solution?
The solution is highly scalable.
How was the initial setup?
It's easy to deploy Fortinet FortiAnalyzer. The solution needs to be upgraded every two or three years. The product is very easy to maintain.
What's my experience with pricing, setup cost, and licensing?
Due to the multiple features and the large environment compatibility, the solution is quite expensive. I would rate the pricing an eight out of ten.
Which other solutions did I evaluate?
At our company, Kibana is sometimes used to pull logs and develop graphical representations from it.
What other advice do I have?
I would rate the solution an eight out of ten. I would advise others never to jump into upgrading to the latest firmware; wait until the present environment products are being used. There have been bad releases in the past, so everyone needs to carefully analyze options.
Disclosure: My company has a business relationship with this vendor other than being a customer.
Security Manager at Yarix S.r.l.
We can gather logs and generate reports, but the license cost is high
Pros and Cons
- "The most valuable feature is the capability to gather logs and generate reports."
- "The integration with other vendors for log collection could be enhanced."
What is our primary use case?
Fortinet FortiAnalyzer is utilized to gather logs from all Fortinet products and generate reports.
What is most valuable?
The most valuable feature is the capability to gather logs and generate reports. Without this solution, the firewalls exhibit limited proficiency in displaying logs.
What needs improvement?
The integration with other vendors for log collection could be enhanced.
The licensing cost has room for improvement.
For how long have I used the solution?
I have been using Fortinet FortiAnalyzer for over three years.
What do I think about the stability of the solution?
I rate FortiAnalyzer's stability a nine out of ten. We have had instances of data loss or source loss.
What do I think about the scalability of the solution?
For our needs, FortiAnalyzer is scalable because we are not dealing with thousands of firewalls.
How are customer service and support?
The technical support is good.
How was the initial setup?
The initial setup is straightforward. The deployment took a couple of days.
For the deployment, we needed to create the server for deploying the FortiAnalyzer image and create the policy rules. We also had to complete the basic configuration of FortiAnalyzer. Following that, we configured all the resources and logs within FortiAnalyzer to collect and correlate the logs, which are then used to generate reports.
What about the implementation team?
We used a consultant for the implementation.
What's my experience with pricing, setup cost, and licensing?
We pay for an annual license, but we have the ability to determine the payment schedule with our distributor.
The cost of the license is high.
What other advice do I have?
I would give Fortinet FortiAnalyzer a rating of six out of ten. I am not satisfied with the solution as it falls short of a proper SIEM. Therefore, we would prefer to allocate more funds towards a SIEM in order to effectively collect logs.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network and Security Engineer at RaytonCOrp
Provides detailed reporting, customizable dashboards, and an easy deployment
Pros and Cons
- "The most valuable feature is the capability to create a customized dashboard."
- "The integration between specific tenants and FortiAnalyzer can be simplified when utilizing a multi-tenant EMS for our FortiClient."
What is our primary use case?
Fortinet FortiAnalyzer is primarily utilized to generate quarterly reports showcasing blocked attacks and vulnerabilities. It employs features like WAV porting triggers and DNS triggers to effectively demonstrate to the client the security of their environment.
How has it helped my organization?
Fortinet FortiAnalyzer assists in showcasing the value of Fortinet and facilitates the upselling of additional Fortinet products to our customers.
What is most valuable?
The most valuable feature is the capability to create a customized dashboard. We can subsequently input our EMS, FortiClient, and FortiGate data into it and generate reports.
What needs improvement?
The integration between specific tenants and FortiAnalyzer can be simplified when utilizing a multi-tenant EMS for our FortiClient.
For how long have I used the solution?
I have been using Fortinet FortiAnalyzer for three months.
What do I think about the stability of the solution?
Fortinet FortiAnalyzer is stable.
What do I think about the scalability of the solution?
Fortinet FortiAnalyzer is scalable.
How are customer service and support?
I utilized the technical support services once, and I received a prompt response.
How was the initial setup?
The initial setup is straightforward. The deployment was an easy and smooth process. The deployment took one day and I did it myself.
What other advice do I have?
I would rate Fortinet FortiAnalyzer a nine out of ten.
Fortinet FortiAnalyzer does not require maintenance after the initial report setup. We simply have to remove and add FortiGate as needed for each report.
Before utilizing Fortinet FortiAnalyzer, individuals should determine the type of reporting they require. Additionally, they ought to be acquainted with FortiGate before endeavoring to use FortiAnalyzer.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
Security Manager at a computer software company with 11-50 employees
Scales well, helpful GUI, and useful automation
Pros and Cons
- "The most valuable features of Fortinet FortiAnalyzer are the GUI and there is automation that can be done with playbooks and mini-books."
- "Fortinet FortiAnalyzer can improve by introducing integration with other Fortinet solutions with automation with one interface would be helpful."
What is our primary use case?
My clients mainly use Fortinet FortiAnalyzer for the log and automation.
This solution can be deployed on-premise and on the cloud.
What is most valuable?
The most valuable features of Fortinet FortiAnalyzer are the GUI and there is automation that can be done with playbooks and mini-books.
What needs improvement?
Fortinet FortiAnalyzer can improve by introducing integration with other Fortinet solutions with automation with one interface would be helpful.
For how long have I used the solution?
I have been using Fortinet FortiAnalyzer for approximately four years.
What do I think about the stability of the solution?
The stability of Fortinet FortiAnalyzer is good.
I rate the stability of Fortinet FortiAnalyzer a ten out of ten.
What do I think about the scalability of the solution?
The solution is scalable.
This solution is suitable for all sized companies.
I rate the scalability of Fortinet FortiAnalyzer a nine out of ten.
How are customer service and support?
My clients had a mixed experience with the support from Fortinet FortiAnalyzer. Some had good experiences and others had poor experiences.
I rate the support of Fortinet FortiAnalyzer a ten out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
My customers have tried Palo Alto Panorama and we only had positive feedback from Fortinet FortiAnalyzer.
How was the initial setup?
The initial setup of Fortinet FortiAnalyzer is simple.
What's my experience with pricing, setup cost, and licensing?
The price of Fortinet FortiAnalyzer is expensive.
I rate the price of Fortinet FortiAnalyzer a ten out of ten.
What other advice do I have?
I rate Fortinet FortiAnalyzer a ten out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Information security officer at a financial services firm with 1-10 employees
Good value for money, works well with other Fortinet solutions, and has helpful support
Pros and Cons
- "The log events are quite useful for us."
- "We'd like to see more embedded features."
What is our primary use case?
The solution is used for grabbing logs. It is designed for log aggregation of all Fortigate firewalls and to give visibility of traffic and usage.
What is most valuable?
The log events are quite useful for us. The events aggregation from various Fortigate products makes it very helpful.
Technical support is helpful.
The stability is excellent.
This is a highly scalable product.
The setup is straightforward.
What needs improvement?
We'd like to see more embedded features.
We'd like to see more SIEM capabilities. I'd love to see this merged with FortiSIEM for example.
For how long have I used the solution?
I've been using the solution for around 20 years.
What do I think about the stability of the solution?
The stability is great. I'd rate it ten out of ten for reliability. We rarely have any issues.
What do I think about the scalability of the solution?
You pay compared to the volume of logs you collect. It is very scalable. It's highly expandable. On a scale from one to ten, I'd rate the scalability ten out of ten.
We have less than five network engineers using the product.
How are customer service and support?
I've dealt with support in the past and found them helpful and responsive.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We use a variety of Fortigate products.
We did not use a different vendor previously. There is no other real option. We did try to use the free version of Splunk. We moved to Fortianalyzer as it works better in Fortinet products. Splunk is harder to fit into other Fortinet products.
How was the initial setup?
The installation process only takes a couple of hours. It is easy to install.
The maintenance is very minimal. One person can handle maintenance tasks.
What about the implementation team?
We do use specialized consultants occasionally. However, I have been able to do it by myself as well in the past.
What's my experience with pricing, setup cost, and licensing?
I cannot speak of the exact price. Someone else manages the contract. However, you do get good value for your money. It's not overly expensive.
As it is on-premises, you do need some on-prem resources. You need a traditional hypervisor and need the ability to host the solution on your premises.
What other advice do I have?
We're customers and end-users.
We are using the latest version of the solution typically.
I'd recommend the solution to other users.
I would rate the solution ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Network Engineer at Dejpaad
Easy to set up with good performance and reliability
Pros and Cons
- "It's easy to set up the product."
- "The solution costs too much."
What is our primary use case?
We use the solution for just one company for the analysis of the FortiGate switch.
What is most valuable?
The solution is scalable.
The performance is good.
It's easy to set up the product.
What needs improvement?
The solution costs too much.
For how long have I used the solution?
I've used the solution for about three years.
What do I think about the stability of the solution?
The solution has been stable and reliable. There are no bugs or glitches, and it doesn't crash or freeze.
What do I think about the scalability of the solution?
It's a scalable product and expands well.
Only admins use the solution. There are three to four people with direct access to the product.
How are customer service and support?
I do not have access to technical support. In Iran, we have sanctions, and so we cannot get support.
How was the initial setup?
The initial setup is pretty straightforward and simple. It's not overly complex or difficult to manage. We can deploy it in about two hours. You only need one person to handle the deployment and maintenance tasks as it is very simple.
What was our ROI?
We have witnessed a bit of an ROI and find the product to be worth the cost.
What's my experience with pricing, setup cost, and licensing?
We do need to pay for a license, and the payment is made yearly. There are no extra costs associated with the product beyond the main licensing fee.
It is an expensive solution.
Which other solutions did I evaluate?
We did not evaluate other solutions before choosing this product.
What other advice do I have?
Overall, I'd rate the product eight out of ten in terms of its functionality. I have been pleased with its capabilities so far. I'd recommend the solution to others.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Fortinet FortiAnalyzer Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Product Categories
Log ManagementPopular Comparisons
Splunk Enterprise Security
Dynatrace
IBM Security QRadar
Elastic Security
LogRhythm SIEM
Elastic Observability
Coralogix
Grafana Loki
IBM SevOne Network Performance Management (NPM)
LevelBlue USM Anywhere
Graylog Enterprise
Amazon OpenSearch Service
Buyer's Guide
Download our free Fortinet FortiAnalyzer Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- When evaluating Log Management tools and software, what aspect do you think is the most important to look for?
- Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
- Which Windows event log monitoring tool do you recommend?
- What is the difference between log management and SIEM?
- Splunk vs. Elastic Stack
- How can Cloudtrail logs be used effectively to improve log monitoring?
- Why hot data and cold data differences in SIEM solutions are not discussed sufficiently?
- When evaluating Log Management solutions, what aspect do you think is the most important to look for?
- When evaluating Log Management solutions, what aspects do you think are the most important to look for?
- Why are Log Management tools important for companies?

















