The normal use case for FortiAnalyzer is log review, log analysis, etc.
Security Engineer at a recreational facilities/services company with 10,001+ employees
It runs very well on its own and doesn't really need much TLC
Pros and Cons
- "FortiAnalyzer has a robust ability to find a compromised host on your network, and when you identify a compromised host, you can address it."
- "Though FortiAnalyzer has improved over the last few versions, the user interface still has room for improvement. It's a bit dated-looking."
What is our primary use case?
How has it helped my organization?
FortiAnalyzer makes it much easier for us to find an apparently compromised host on the network.
What is most valuable?
FortiAnalyzer has a robust ability to find a compromised host on your network, and when you identify a compromised host, you can address it.
What needs improvement?
Though FortiAnalyzer has improved over the last few versions, the user interface still has room for improvement. It's a bit dated-looking. I guess that's the nicest way to describe it. In FortiAnalyzer, I would like the ability to turn off some of the services. So, for example, FortiAnalyzer can take data from FortiCamera products and turn off the FortiCamera stuff to lighten the load on the box or turn off the FortiSock product.
Buyer's Guide
Fortinet FortiAnalyzer
June 2025

Learn what your peers think about Fortinet FortiAnalyzer. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,592 professionals have used our research since 2012.
For how long have I used the solution?
I've been using FortiAnalyzer for about seven years.
What do I think about the stability of the solution?
FortiAnalyzer is really stable. It runs very well on its own and doesn't really need much TLC. It's a good product.
What do I think about the scalability of the solution?
It's pretty scalable. The units that we have are the right size for the amount of stuff that we're running, but they do have products that scale up to handle significantly more Fortigate firewalls in log stuff than we do. I would say about 20 people use FortiAnalyzer. There's me, the security engineer, and the network engineering team, which uses it to look at stuff on the firewalls or check the firewall logs. And our information security group uses it to look at stuff that's going on with the firewalls as well as compromised hosts. It is being used pretty well as we get further down the path of deploying our FortiGate-managed endpoint product. There'll be more users and probably more use cases for it in the future.
Which solution did I use previously and why did I switch?
I haven't really used a different solution previously. We've always used FortiAnalyzer in concert with Splunk.
How was the initial setup?
FortiAnalyzer is a pretty straightforward product to deploy. It took half a day to deploy a pair of FortiAnalyzers and set them up in high availability mode. I deployed it by myself. These are hardware appliances, so there were a couple of devices that needed to be racked, powered, and configured.
What's my experience with pricing, setup cost, and licensing?
I believe that these devices were procured with a five-year maintenance and support license up front. I work at a university, so the vendor provides a considerable higher ed discount.
Which other solutions did I evaluate?
It's all part of our Fortinet ecosystem, so we didn't really consider alternatives. I have a significant investment in FortiGate firewalls, so it just made sense to add FortiAnalyzer.
What other advice do I have?
I rate FortiAnalyzer eight out of 10. It does an outstanding job of what it does. But the vendor doesn't necessarily live up to the hype, which is why it only got an eight out of 10. There's a lot of hype about the Fortinet security fabric. But for the large customers that buy their large firewalls and deploy them in infrastructure components, the Fortinet fabric does not work. If you are considering FortiAnalyzer, I suggest having a complete understanding of how your firewall infrastructure works in terms of what data you're going to and from it for analysis and what you're looking for in that analysis.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Senior Technical Sales Engineer at Logicalis
A solution for firewall, URL filtering, and SD-WAN
Pros and Cons
- "We use the solution for enterprise firewalls, URL filtering, and SD-WAN."
- "The solution could embed monitoring."
What is our primary use case?
We use the solution for enterprise firewalls, URL filtering, and SD-WAN.
What needs improvement?
The solution could embed monitoring.
For how long have I used the solution?
I have been using Fortinet FortiAnalyzer for a year. We are using V6.2 of the solution.
What do I think about the scalability of the solution?
The solution’s scalability is good. 500 users are using this solution. The solution is suitable for small and medium businesses.
I rate the solution’s scalability a seven out of ten.
How are customer service and support?
When the case is unresolved, the following person takes time to get involved in the tickets. The information may be complex.
How would you rate customer service and support?
Neutral
How was the initial setup?
The initial setup is easy. I rate the initial setup an eight out of ten, where one is difficult and ten is easy.
What's my experience with pricing, setup cost, and licensing?
The solution's pricing is good.
What other advice do I have?
I recommend it because it's a perfect solution.
Overall, I rate the solution a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Buyer's Guide
Fortinet FortiAnalyzer
June 2025

Learn what your peers think about Fortinet FortiAnalyzer. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,592 professionals have used our research since 2012.
Information Technology Administrator at Omnient SRL
Offers a great overview of the logs and integrates perfectly
Pros and Cons
- "It is easy to integrate Fortinet FortiAnalyzer with other products. You have a better overview of what's going on."
- "The only issue that I can see is with the cost. For example, if you buy support for one year, you are messed up next year. It's better to buy another gateway."
What is our primary use case?
We collect the logs from Fortinet in order to search and get a better view of everything that's coming from FortiGate because the overview on FortiGate isn't the same. FortiAnalyzer provides an overview of the logs and everything that's happening there. We integrate FortiGate and FortiAnalyzer with the SOC that we're working on, which is an open-source security solution.
The other use case is to have logs. Because otherwise, in FortiGate, you don't have logs for a long period of time. You only have seven days if you don't have an account in FortiGuard. So, FortiAnalyzer provides a better understanding of what's happening there. And for our clients, we always recommend FortiAnalyzer.
FortiGate by itself is a good choice, but without FortiAnalyzer, you lose a lot of features. Even the free version of FortiAnalyzer provides some useful features.
What is most valuable?
It is easy to integrate Fortinet FortiAnalyzer with other products. You have a better overview of what's going on. For example, you get a smaller alert for an infected workstation if it causes some suspicious traffic, you see it right away in Fortinet.
What needs improvement?
The only issue that I can see is with the cost. For example, if you buy support for one year, you are messed up next year. It's better to buy another gateway.
For how long have I used the solution?
I have been using Fortinet FortiAnalyzer for one year, and I am currently working with the latest version.
What do I think about the stability of the solution?
It is a very stable solution and integrates perfectly.
What do I think about the scalability of the solution?
It is a scalable solution. Our company is very proud of FortiGate solutions.
How are customer service and support?
The support team is good. We have some cases open with them, and they resolve them very quickly. Even when there is a breach of security, they patch it quickly.
How was the initial setup?
It is very easy to set up and deploy. Even someone with little networking knowledge or a manager can quickly understand what's happening in the network, such as an increase in traffic from specific endpoints or which websites are being browsed, including social media.
What's my experience with pricing, setup cost, and licensing?
You get a gateway, but without support, it's not worth much. We've also tried FortiGate virtual machines, but the price is so high that it's better to buy other appliances than to buy the license for the VM.
We also work with third-party solutions. However, this solution is not for everyone, and even though it's free, it's easy to implement when you have money.
Overall, I would rate it an eight out of ten.
What other advice do I have?
I would advise buying FortiGate and FortiAnalyzer together. They get it free of charge. When you buy FortiGate, you can put in a FortiAnalyzer VM for free. Although the free version has its limitations, you should get it because it doesn't cost you anything. When you try the free version of FortiAnalyzer, you'll see its potential, and you'll want more.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Chief Technology Officer at Litmus
Can be used by institutions whose data needs to be on-premises and not in the cloud
Pros and Cons
- "I have found incident management and also identifying new threats, analyzing the network traffic, and finding out the issues with the network traffic such as any security issues to be valuable. I also like the compliance reports."
- "One thing we struggled with FortiAnalyzer was integration with SIEM. We also had issues with the new threats and APTs. There were false positives, so we needed to have some ratings related to false positives."
What is our primary use case?
Most of our clients are banking and financial institutions, so their data doesn't go to the cloud as such. Their data is on-premises only. Some of our clients can go to the cloud to save the price and do management, administration, and so on, but then most of our clients, use on-premises FortiAnalyzer.
How has it helped my organization?
Fortianalyzer helped us to manage fortigate devices and update them from central location.
What is most valuable?
I have found incident management and also identifying new threats, analyzing the network traffic, and finding out the issues with the network traffic such as any security issues to be valuable. I also like the compliance reports.
It is a very stable and scalable solution.
What needs improvement?
One thing we struggled with FortiAnalyzer was integration with SIEM. We also had issues with the new threats and APTs. There were false positives, so we needed to have some ratings related to false positives.
It is easy to set up is you have FortiGate firewalls. We tried setting up with other devices, and I don't think it supports other firewalls or other devices. If it did, then it would have been great because we would have been able to use FortiAnalyzer for hybrid environments with different OEM firewalls.
If we can have an intelligent analysis system which will detect false positives and detect the exact problem, it would be great. If FortiAnalyzer can integrate with FortiSIEM and give us threat reports, that will also help because then I won't need to have another tool or another dashboard which I need to look out for.
For how long have I used the solution?
I've been using it for four years.
What do I think about the stability of the solution?
It is a very stable product, and we have had no issues at all.
What do I think about the scalability of the solution?
It is easy to scale; there are no challenges.
How are customer service and support?
The technical support is good. Most of the time, when we escalate the tickets the second line of support, FortiGate support, has been very good. The first line might take up time, but the second line of support resolves the case quite quickly.
Which solution did I use previously and why did I switch?
Yes we used checkpoint for our organisation , but it was a complex system to manage, we expect a firewall to be a simple device to avoid complexity.
How was the initial setup?
The initial setup is quite simple with FortiGate devices. So, if you have FortiGate firewalls, it is quite easy to set up. Once Fortinet FortiAnalyzer is configured, then the only thing we need to do is to monitor it.
What's my experience with pricing, setup cost, and licensing?
When you compare with other firewall vendors, FortiAnalyzer is quite competitive in pricing. They are very aggressive as well.
Which other solutions did I evaluate?
Yes we did evaluate paloa alto , but it went into backburner due cost factor.
What other advice do I have?
If you have critical objects to protect or critical data to protect, then you should go for FortiAnalyzer.
On a scale from one to ten, I would rate Fortinet FortiAnalyzer at eight.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Section Head, Enterprise Solutions & SI Management at HGC Global Communications Limited
Good performance, reliable, but interface could improve
Pros and Cons
- "The most valuable feature of Fortinet FortiAnalyzer is its performance."
- "Fortinet FortiAnalyzer could improve the user interface, and the experience of users receiving the reports and tracking could be better."
What is our primary use case?
We are using Fortinet FortiAnalyzer for the managing surface for our customers. We are a service provider and we are focusing on providing a service to our customers.
What is most valuable?
The most valuable feature of Fortinet FortiAnalyzer is its performance.
What needs improvement?
Fortinet FortiAnalyzer could improve the user interface, and the experience of users receiving the reports and tracking could be better.
For how long have I used the solution?
I have been using Fortinet FortiAnalyzer for approximately three years.
What do I think about the stability of the solution?
Fortinet FortiAnalyzer is stable.
How are customer service and support?
The support from Fortinet FortiAnalyzer is good.
How was the initial setup?
The initial setup of Fortinet FortiAnalyzer is fine. There is a lot of browsing and a lot of hierarchy that you need to have a particularly good understanding of in order to track the right things that you want to select.
What's my experience with pricing, setup cost, and licensing?
There is a license needed to use this solution.
What other advice do I have?
My advice to others is they have to assess well what kind of specific function or what kind of solution they are looking for.
I recommend this solution to others, but it depends on their usage.
I rate Fortinet FortiAnalyzer a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Senior Manager at Technometrics Limited
Stable and scalable solution, but the technical support could be better
Pros and Cons
- "We have the most data visibility."
- "The user interface could be a bit more user-friendly."
What is our primary use case?
We have the most data visibility with this solution.
What needs improvement?
The user interface could be a bit more user-friendly, and they could have more robust support. The support does not respond quickly. They should be able to solve the problems in one or two days, but sometimes it takes time. They constantly ask for logs, and it takes time.
For how long have I used the solution?
We have been using this solution for three years, and we are using the latest version. It is deployed on-premises and cloud. It gets all the logs in a single platform because we have multiple sites.
What do I think about the stability of the solution?
The stability is good. I rate it an eight out of ten.
What do I think about the scalability of the solution?
For cloud, the solution is always scalable. We have about ten customers using Fortinet FortiAnalyzer.
How are customer service and support?
I rate the technical support a five out of ten.
How was the initial setup?
The initial setup was not complex.
What other advice do I have?
I rate this solution a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Project Manager at a tech services company with 51-200 employees
Enriches visibility for security solutions
Pros and Cons
- "FortiAnalyzer's best feature is centralized log analysis. It's based on SQL database, so I can fully customize my report, chart-wise and log-wise, and can create as many reports as I want without any limit."
- "FortiAnalyzer's price could be lower."
What is our primary use case?
I mainly use FortiAnalyzer to centralize logs from multiple devices and generate local reports. It can work in two operation modes: as a collector only or an analyzer.
How has it helped my organization?
FortiAnalyzer has enriched the visibility for all our security solutions.
What is most valuable?
FortiAnalyzer's best feature is centralized log analysis. It's based on SQL database, so I can fully customize my report, chart-wise and log-wise, and can create as many reports as I want without any limit. It also has an important feature called Indicators of Compromise, an artificial intelligence feature that detects and alerts you when there is a breach in your entity.
For how long have I used the solution?
I've been using FortiAnalyzer for ten years.
What do I think about the stability of the solution?
FortiAnalyzer is a very mature and stable product.
What do I think about the scalability of the solution?
FortiAnalyzer is scalable. When my organization expands in any way, I can implement a FortiAnalyzer as a collector only, it will collect the log, and I can send this to the main analyzer. If I use the virtual alert mode, this is a stackable license, so I can expand the log size or the internal hard-disc log size by purchasing a license. There is also a workaround solution, to automatically upload the old log file to shared storage and delete the old one, which gives more space in the hard drive.
How are customer service and support?
FortiAnalyzer's technical support is helpful.
How would you rate customer service and support?
Positive
How was the initial setup?
FortiAnalyzer is straightforward to implement and integrate, but a little experience is needed to generate a technical level.
What was our ROI?
We get good ROI from FortiAnalyzer.
What's my experience with pricing, setup cost, and licensing?
FortiAnalyzer's price could be lower, but it is cheaper than competitors like Palo Alto, Forcepoint, or Sophos. The basic license is available on a yearly basis, but some other licenses can be for three, six, or nine months as required. There are no hidden costs associated with this product.
What other advice do I have?
Don't just depend on the basic reports, you can get much more out of FortiAnalyzer if you know how to create customized reports from the SQL queries. I would give FortiAnalyzer a rating of eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Development and Innovation Manager at NSB
Good UI and customization with everything under one umbrella
Pros and Cons
- "The product can scale."
- "The pricing could be better."
What is our primary use case?
We are using it only for integration and getting information from FortiAnalyzer to use and analyze important events.
What is most valuable?
The stability is good.
They are able to integrate everything under one umbrella, which is nice.
The UI and customization are good right now.
The product can scale.
What needs improvement?
The pricing could be better.
We'd like integration with more providers.
The initial setup can be difficult.
For how long have I used the solution?
We've used the solution for about a year.
What do I think about the stability of the solution?
The stability of the product is good and it has been reliable. There are no bugs or glitches and it doesn't crash or freeze.
What do I think about the scalability of the solution?
The product can scale. It's simple to expand as necessary.
How are customer service and support?
I've never had to contact technical support. I cannot speak to how helpful or responsive they would be.
Which solution did I use previously and why did I switch?
We are using all the solutions from Fortinet, and FortiAnalyzer. We are planning to use FortiSIEM and FortiWeb.
How was the initial setup?
It's not too easy to set up. It can be a bit difficult. They could make it a little bit easier.
You only need two people (engineers) to handle deployment and maintenance.
What other advice do I have?
We are partners for Fortinet. So we are planning to use the FortiEDR, and then we're going to expand.
We only use FortiAnalyzer for internal purposes.
Our company is using the most up-to-date solution.
I'd advise potential users to look for a partner who knows how to handle the product and use their knowledge to give you quick training for your own people. The learning curve is not that easy.
I'd rate the solution eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner

Buyer's Guide
Download our free Fortinet FortiAnalyzer Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Log ManagementPopular Comparisons
Dynatrace
Splunk Enterprise Security
IBM Security QRadar
Elastic Security
Elastic Observability
Grafana Loki
Security Onion
LogRhythm SIEM
Elastic Stack
syslog-ng
Amazon CloudWatch
Buyer's Guide
Download our free Fortinet FortiAnalyzer Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- When evaluating Log Management tools and software, what aspect do you think is the most important to look for?
- Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
- Which Windows event log monitoring tool do you recommend?
- What is the difference between log management and SIEM?
- Splunk vs. Elastic Stack
- How can Cloudtrail logs be used effectively to improve log monitoring?
- Why hot data and cold data differences in SIEM solutions are not discussed sufficiently?
- When evaluating Log Management solutions, what aspect do you think is the most important to look for?
- When evaluating Log Management solutions, what aspects do you think are the most important to look for?
- Why are Log Management tools important for companies?