Network Security Engineer at ZOL Zimbabwe
Real User
Offers visibility of critical data in real-time for our clients, but the reports are over-summarized
Pros and Cons
  • "The most valuable features are customizing reports, and the ability to drill down to display critical information in real-time."
  • "The reports are good, but they are over-summarized."

What is our primary use case?

We use this solution for reporting. We also use it to keep logs for our clients that require logs with a history of more than seven days.

In addition to our own firewalls, we have several clients with firewalls that report into the same FortiAnalyzer.

We have a private cloud deployment, set up on-premises.

What is most valuable?

The most valuable features are customizing reports, and the ability to drill down to display critical information in real-time. FortiGate itself, for example, doesn't offer all of this information on the entry-level firewalls. You can get more detailed information from FortiAnalyzer based on the log that is retrieved from FortiGate while it is operating.

What needs improvement?

I would like to be able to do more customization. For example, I would like to be able to develop my own set of reports that I can upload to the analyzer, and then it can report in a fashionable way as to what I really expect, rather than the ones that are preconfigured. Then we can play around with them in terms of where you can position your top bandwidth users, and such.

The reports are good, but they are over-summarized.

For how long have I used the solution?

We have been using this solution for four years.
Buyer's Guide
Fortinet FortiAnalyzer
April 2024
Learn what your peers think about Fortinet FortiAnalyzer. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
769,599 professionals have used our research since 2012.

What do I think about the stability of the solution?

The device has been pretty much stable. We haven't really had issues with it in the time that we've been using it.

What do I think about the scalability of the solution?

The licensing limits the storage in terms of how much information it can store. For example, you can collect seven gigs of log files in a day.

We have twenty firewalls connecting to FortiAnalyzer. We are moving some of them to the FortiCloud platform because we get thirty days of reporting on a non-subscription basis with FortiCloud. With FortiAnalyzer, we would have to pay for more licenses.

At this stage, we do not plan to increase usage. The majority of our clients who have entry-level firewalls are now depending on FortiCloud. It is more robust than us having more of the FortiAnalyzer devices. Because FortiCloud is accessible from anywhere, a client can easily manage it, rather than us giving them access to the Fortianalyzer. So, we're finding FortiCloud being a better option than us having an on-site FortiAnalyzer.

How are customer service and support?

When I speak with Fortinet technical support it is usually in regards to FortiGate. I would rate their support team an eight out of ten. Sometimes, what happens is that we open a webchat with them where you don't have to open a ticket. The problem is that you may end up dealing with the level-one support who doesn't really give you the answer, so they then refer you to open a ticket. This delay can be a problem when you have a client that needs an issue resolved right then and there.

Which solution did I use previously and why did I switch?

We have not used any other solutions for log analysis.

How was the initial setup?

The initial setup of this solution is pretty straightforward. We have a few FortiGate firewalls, and they communicate with FortiAnalyzer over the public networks by sending their logs.

The deployment was not difficult and did not take much time. It is just the initial configuration on FortiAnalyzer, which takes no more than ten minutes. Then, the analyzer will be synchronized with FortiGate. It is just a matter of entering the FortiAnalyzer IP address, then allowing it to register. In total, it takes about twenty minutes.

There are three administrators for this solution, and I handle the maintenance myself.

What about the implementation team?

We handled the deployment ourselves. The documentation from Fortinet is pretty straightforward.

What's my experience with pricing, setup cost, and licensing?

The pricing of this solution is fair, and it is based on what you can manage. There are no costs in addition to the licensing fees.

Which other solutions did I evaluate?

We tried NetFlow Analyzer, and the product was good but it was highly expensive.

What other advice do I have?

This solution, at every stage, does what I expect it to.

My advice for anybody researching this solution is to consider the size of their organization. If it is very big and they need to retain a log for a specific number of days or a period of time, for example, going back to thirty days and they also need to analyze the traffic in real-time, then FortiAnalyzer would be ideal. However, the same service is now available on FortiCloud, which is something else that I highly recommend.

With other solutions, such as NetFlow Analyzer, you can really customize your report to what you expect. Together you can insert logs, you can customize your reports with the logs that you're receiving, unlike with FortiAnalyzer. This is a major drawback.

I would rate this solution a seven out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
PeerSpot user
Janderson Mira - PeerSpot reviewer
Diretor Técnico at TND Brasil
Reseller
Top 5
Has good report templates and works very well for reporting and analysis
Pros and Cons
  • "The report templates are valuable. It works very well, and integrations also work well."
  • "Feature-wise, it is working very well for us. We don't need any additional features. However, its pricing can be improved. For small business customers, price is an important factor."

What is our primary use case?

We use it for reports and analysis.

What is most valuable?

The report templates are valuable. It works very well, and integrations also work well.

What needs improvement?

Feature-wise, it is working very well for us. We don't need any additional features. However, its pricing can be improved. For small business customers, price is an important factor.

For how long have I used the solution?

I have been using this solution for two years.

What do I think about the stability of the solution?

It is stable.

What do I think about the scalability of the solution?

It is easy to scale.

What's my experience with pricing, setup cost, and licensing?

It is expensive for small business customers. It is only available for customers with a high number of firewalls to manage or to report. If a customer has only five boxes of FortiGate, the price of FortiAnalyzer can be more than the five boxes. So, we can't easily put this solution for small business customers.

What other advice do I have?

I would rate this solution a nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
PeerSpot user
Buyer's Guide
Fortinet FortiAnalyzer
April 2024
Learn what your peers think about Fortinet FortiAnalyzer. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
769,599 professionals have used our research since 2012.
Head of Service at MPM
Real User
Has a useful dashboard and good scalability
Pros and Cons
  • "The feature I find most useful is the handy dashboard."
  • "I would like to see an improvement in the technical support. Stronger authentication will also be a plus."

What is our primary use case?

Our primary use case of this solution is for bandwidth. We are very satisfied with this program.

What is most valuable?

The feature I find most useful is the handy dashboard.

What needs improvement?

I would like to see an improvement in the technical support. Stronger authentication will also be a plus.

In the next version, I would like to have authentication for 40 tokens.

For how long have I used the solution?

I have been using Fortinet FortiAnalyzer for a month now on private cloud.

What do I think about the scalability of the solution?

We have between 20 and 25 users and we plan to increase this number, so I believe the program is scalable.

How are customer service and technical support?

We are very satisfied with the customer service.

How was the initial setup?

The initial setup was straightforward and deployment took us about eight months. The reason for this is that we installed other programs during this time too, like Fireworks Data Center, Switch Data Center, Cisco Nexus Data Center, and Forcepoint. We use Stitch as our local manager. 

What's my experience with pricing, setup cost, and licensing?

All Fortinet programs come at a good price.

What other advice do I have?

I will definitely recommend this solution to others. My rating is a ten out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user494214 - PeerSpot reviewer
System & Network Administrator at a tech services company with 11-50 employees
Real User
Gives us a simplified and user-friendly interface to work with
Pros and Cons
  • "It has a simplified and user-friendly interface."
  • "When it comes to pushing logs to a SIEM, most of the time we have some issues when it comes to filtering."

What is our primary use case?

We use the analyzer for reporting, to know what exactly is happening on the network. We use it to see which accesses are granted, which accesses are denied, which sites are visited, which botnets are coming in, which viruses, etc.

The solution is on-premise. Most of the time we set it up on the client's premises, depending on their needs. The cloud is there for testing.

What is most valuable?

It has a simplified and user-friendly interface.

What needs improvement?

With FortiAnalyzer, most of the time, although the interface is simplified, when you are new to it you have issues of navigating through it.

And when it comes to pushing logs to a SIEM, most of the time we have some issues when it comes to filtering.

Also, reports need to be simplified because its reporting currently includes more detailed and technical things. If we could get a simplified or executive summary, that would be good.

For how long have I used the solution?

We have been using this solution for about four or five years.

What do I think about the stability of the solution?

It's very stable, unlike the previous version which, when the logs were huge, would crash and we would have to reset it and start all over again.

What do I think about the scalability of the solution?

The scalability is also fine if you do your prerequisites right. If so, you won't have any issues. But if you don't do your scoping right, and more logs come into the system - more than it can handle - you will face issues. You need to do your scoping right to get it to be stable and scalable.

How are customer service and technical support?

Technical support is kind of slow. When you have 24/7 support, the response is quick. But when you send something in, it takes a long time to get a response. Fortinet support is a little bit slow when using their portal for support.

In our case, because we are partners, we have a couple of tech guys we can call to get support done. When an end-user requests support through the portal, and even when we do, it takes hours to get a response.

Which solution did I use previously and why did I switch?

We work with multiple solutions and Fortinet has been the number-one.

How was the initial setup?

For me, the initial setup was straightforward. The deployment takes approximately ten minutes. In some cases we could be waiting for results, waiting for logs to get up to do some analysis.

What's my experience with pricing, setup cost, and licensing?

The price is quite expensive. Fortinet products are very expensive. That is something which they should also look at, because if you compare Fortinet product to, say, Sophos for example, Fortinet is really high and that's the only thing which is a drawback for most users. Although their plan is a value-for-money appliance, the price is expensive.

What other advice do I have?

Anyone who asks me about a Fortinet product, I'll give that person a thumbs-up. So far, Fortinet has been the best for me. It's a value-for-money appliance, it has an easy to use interface, and it gives you exactly what you want. The only drawback would be the price. 

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
PeerSpot user
Systems Architect at ZENTIUS
Reseller
Great UI, good performance, and never crashes
Pros and Cons
  • "Log collection is the most valuable. The UI looks great. It has a very good look and feel. We don't have the need to use solid state drives. We use mechanic drives, and we don't see any performance issues, so basically, it is doing fine."
  • "It will be better if behavior or indicators of compromise were on the same licensing schema. Currently, it is an advanced feature that you have to purchase as an add-on. This is the reason we're trying to do the ELK so that we can integrate them and create those rules by using open-source software. It will also be better if it has some more integration with IT service management tools so that we can do endpoint protection and response based on those indicators of compromise or those behavior analysis rules that create events that can automatically flow. We can inject that data into a service incident ticket on our IT service management tool, and that way we can assign the ticket to the proper teams and respond right away. Currently, we only have integration with ServiceNow."

What is our primary use case?

We mostly use the FortiAnalyzer VM. We sell the license for this solution and also the professional service to have it. 

There are different types of business needs of our clients because they're in different business areas. We have firewalls on them. Some of them are on the perimeter network, and some of them are being used as the core network solution. We collect all the logs from their FortiGates. 

In some cases, we also use FortiWeb, which is a web application firewall. We also use FortiMail, which is an email protection solution or email security solution. We gather all the logs on FortiAnalyzer, and we try to do some flat counting and identify behavior or do behavior analysis from those logs and see what is interesting. Our team analyzes those events so that we can prevent any disruption of service because of the security, vulnerability, or issue.

What is most valuable?

Log collection is the most valuable. The UI looks great. It has a very good look and feel. We don't have the need to use solid state drives. We use mechanic drives, and we don't see any performance issues, so basically, it is doing fine.

What needs improvement?

It will be better if behavior or indicators of compromise were on the same licensing schema. Currently, it is an advanced feature that you have to purchase as an add-on. This is the reason we're trying to do the ELK so that we can integrate them and create those rules by using open-source software.

It will also be better if it has some more integration with IT service management tools so that we can do endpoint protection and response based on those indicators of compromise or those behavior analysis rules that create events that can automatically flow. We can inject that data into a service incident ticket on our IT service management tool, and that way we can assign the ticket to the proper teams and respond right away. Currently, we only have integration with ServiceNow

For how long have I used the solution?

I have been using this solution for five years. 

What do I think about the stability of the solution?

We have the box or the VM running for more than a couple of years now. We do upgrade so that we can add new features that Fortinet is releasing, but it is pretty stable. It never crashes.

What do I think about the scalability of the solution?

It is a little complex in terms of scalability and mostly because we're using a kind of high-end systems. For scaling, you have to order a different licensing and move more power and computing into a new architecture. It doesn't have that much scalability.

Our clients are SMB or small and medium businesses, but we also have plenty of customers on the campus wide area network.

How are customer service and technical support?

I would rate them a five out of ten. They will have to move their base locations to a different city. I'm not a native speaker of English, and sometimes, when we're trying, there is a language barrier. They're located in India or some Middle East city. They can do really better. Sometimes their response is not as adequate as other vendors.

How was the initial setup?

It was very straightforward. The deployment could take a couple of days to fine-tune all the rules for log management.

What other advice do I have?

There are plenty of solutions. Fortinet FortiAnalyzer is very helpful if you are really into FortiGate devices. We handle other firewalls, but 80% to 85% of them are Fortinet, so it is a very good solution because it has native integration with everything, but I wouldn't recommend it if you have less than 50% of Fortinet firewalls. If you have agnostic technology, you can integrate all of them into the same solution. FortiAnalyzer is only for FortiGates right now.

I would rate Fortinet FortiAnalyzer a nine out of ten. It just needs more integration with IT service management tools for endpoint detection and response, which is the main objective.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
PeerSpot user
Technical Presales Engineer at Dristi Tech Pvt.ltd
Real User
Provides very good metrics, visibility of the network and does what a network analyzer should do
Pros and Cons
  • "The feature that I have found the most valuable is to be able to see everything in our network in a single task. A single menu and the graphical bar charts that it provides to give insights are very useful. It also gives very good metrics on bandwidth utilization, CPU, and device performance. It is very simple and easy to use as well."
  • "They can include integration with devices, such as firewalls, endpoints, from other vendors. They can include graphic monitoring of everything in the network, not just Fortinet products. It would also be good to include customizable reports and customizable views of the reports."

What is our primary use case?

Generally, Fortinet FortiAnalyzer gives you visibility around the network. You can track and monitor devices and pick the surrounding network. You can see which packets are being sent to the network, who the users are, and what are they using. You can also view the policies and firewall rules that are being used, the IDs that are being connected to, and the IP address a particular user is using.

Basically, it's a SOC. It's a security operations device. We use it for continuous monitoring, and it takes a team to do so. In my organization, three to four people are using it on a daily basis.

What is most valuable?

The feature that I have found the most valuable is to be able to see everything in our network in a single task. A single menu and the graphical bar charts that it provides to give insights are very useful. 

It also gives very good metrics on bandwidth utilization, CPU, and device performance. It is very simple and easy to use as well.

What needs improvement?

They can include integration with devices, such as firewalls, endpoints, from other vendors. They can include graphic monitoring of everything in the network, not just Fortinet products.

It would also be good to include customizable reports and customizable views of the reports. 

For how long have I used the solution?

I have been using Fortinet FortiAnalyzer for about five to eight months. We are using the latest version. We have deployed it on-premises as a VM.

What do I think about the stability of the solution?

It's pretty stable.

What do I think about the scalability of the solution?

I'd say that it's very scalable. Scalability depends on which version of the appliance you're using. 

If you're using a hardware-based appliance, it's obviously tough to scale as that would require purchasing new devices. If you go to cloud services or virtual services, it's pretty easy to scale. You need to purchase new VMs and add the IOCs that you need, which is easy. 

How are customer service and technical support?

I have contacted technical support, but not particularly regarding Fortinet FortiAnalyzer. I have only contacted them for firewalls and routing issues. I have not yet contacted them for things related to Fortinet FortiAnalyzer.

How was the initial setup?

It's very easy and straightforward. You just need the point the FortiGate devices to your Fortinet FortiAnalyzer, and it just automatically configures the security fabric. The time depends on how many devices you're actually using. Configuring one device into your Fortinet FortiAnalyzer takes about five minutes or so.

What about the implementation team?

The deployment was pretty straightforward. I didn't need any help in setting it up. I did it myself very easily. It comes with useful guidelines for setting it up. They also provide documentation and information through their website.

One person can easily do the deployment, but the main goal of the solution is to continue to monitor the regular network traffic for which a team is required. Our software team is responsible for handling such things.

Which other solutions did I evaluate?

This product is only dedicated to packet analyzing, automation, and things like that. I have not used analyzers of other vendors. However, other solutions do provide similar functionalities. 

What other advice do I have?

It is kind of a very good network packet analyzer solution. It does what a network analyzer should do, and it does it very well. 

In terms of firewalls and using network analyzers, Fortinet has always been the leader among the leaders. Fortinet provides very good features and products. Specifically, if you want to use Fortinet FortiAnalyzer, you need to have a FortiGate environment. You need at least one FortiGate or other similar product in your network. So, if you are already using or are into Fortinet products, then FortiAnalyzer is a very good product to add on top of other products. Having only FortiAnalyzer in your network is kind of useless.

I would rate Fortinet FortiAnalyzer a nine out of ten. It's a very good product.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
IT Security Engineer at a tech services company with 201-500 employees
Real User
Straightforward to set up and simple to use but could have a better reporting module
Pros and Cons
  • "The initial setup is straightforward."
  • "The pricing could be better. They could work to make it more competitive on the market."

What is our primary use case?

We primarily use it for logging collection. 

What is most valuable?

It's a simple log collection tool. There isn't too much that's special or unique about it. 

It meets our expectations for the most part.

The solution does offer very useful integration capabilities. 

The interface is fine.

The initial setup is straightforward. 

What needs improvement?

The pricing could be better. They could work to make it more competitive on the market.

The report module could be simplified a bit to make it easier to use. 

Technical support has been very bad. They should work to improve their level of service.

For how long have I used the solution?

I've been dealing with the solution for about seven years at this point. It's been a while. I have a lot of experience with it. 

What do I think about the stability of the solution?

The solution is stable and there are no bugs or glitches. It doesn't crash or freeze. It's reliable. The performance is good. 

What do I think about the scalability of the solution?

The scalability might be limited depending on the installation.

How are customer service and technical support?

We haven't been happy with technical support. We find the service to be quite bad. For example, in our last experience dealing with them, we had multiple issues and the outcomes were not great. We were disappointed with the help we received. 

How was the initial setup?

The initial setup is not overly complex or difficult. It's straightforward enough. A company shouldn't have any issues with the setup.

What's my experience with pricing, setup cost, and licensing?

The pricing isn't the least expensive on the market. They could work to improve it to make it more interesting for other companies. Adjusting pricing might be a good move.

Which other solutions did I evaluate?

I've personally looked into other security solutions, just to understand the market for myself. I've personally compared Fortinet, Meraki, Check Point, and Cisco ASA Firewall in terms of their safety and security capabilities. 

What other advice do I have?

We're Fortinet partners. We have a business relationship with the company.

I'd give the solution a rating of six out of ten.

I'd still recommend it to other users, however. If the reporting, interface, and tech support were a bit better, I'd rate it higher. 

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Presales Technical Specialist at a computer software company with 201-500 employees
Real User
Simple, straightforward, and stable
Pros and Cons
  • "I like its simplicity. It is straightforward. We get reports and emails about the logs, and that's it."
  • "The cloud version can be expensive. If the customers could get the resources to store the logs on-premises, it would be much better."

What is our primary use case?

It is used to get the logs of all boxes that a customer has.

What is most valuable?

I like its simplicity. It is straightforward. We get reports and emails about the logs, and that's it. 

What needs improvement?

The cloud version can be expensive. If the customers could get the resources to store the logs on-premises, it would be much better.

In terms of features, there is no need for additional features.

For how long have I used the solution?

I have been using this solution for three years.

What do I think about the stability of the solution?

It is stable.

What do I think about the scalability of the solution?

It is scalable.

What about the implementation team?

We need only one engineer for its deployment and maintenance.

What's my experience with pricing, setup cost, and licensing?

It is acceptable for on-premises, but it is expensive for the cloud. 

What other advice do I have?

I would rate it a 10 out of 10.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Fortinet FortiAnalyzer Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2024
Product Categories
Log Management
Buyer's Guide
Download our free Fortinet FortiAnalyzer Report and get advice and tips from experienced pros sharing their opinions.