We are using Fortinet FortiAnalyzer for analyzing network traffic and it provides us with log analytics.
Security Engineer at a financial services firm with 501-1,000 employees
Overall features useful, reliable, but need more integration
Pros and Cons
- "Overall we are satisfied with all the features the solution provides."
- "There are a lot of solutions on the market and Fortinet FortiAnalyzer is limited. It cannot be used across multiple vendors. They can improve by advancing their technology."
What is our primary use case?
What is most valuable?
Overall we are satisfied with all the features the solution provides.
What needs improvement?
There are a lot of solutions on the market and Fortinet FortiAnalyzer is limited. It cannot be used across multiple vendors. They can improve by advancing their technology.
The solution could improve by having better integration and support with Apple, Linux, and Microsoft solutions.
For how long have I used the solution?
I have been using Fortinet FortiAnalyzer for approximately five years.
Buyer's Guide
Fortinet FortiAnalyzer
May 2025

Learn what your peers think about Fortinet FortiAnalyzer. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,823 professionals have used our research since 2012.
What do I think about the stability of the solution?
We have been making changes to the cloud signatures and categories because the market is changing and Fortinet FortiAnalyzer has been stable and reliable.
What do I think about the scalability of the solution?
The solution is scalable but there are additional costs if you want to increase the scalability.
How are customer service and support?
We have been satisfied with the support.
How was the initial setup?
The installation was not difficult.
What about the implementation team?
We did the implementation ourselves.
What's my experience with pricing, setup cost, and licensing?
In the local market sometimes people are being charged more than other solutions. Although the market is competitive, legitimate suppliers do not receive a large enough discount to pass onto the customers.
Fortinet FortiAnalyzer is not suitable for everyone, it is best suited for mid-sized businesses but if the price could be reduced there would be more customers in all-sized businesses.
What other advice do I have?
I rate Fortinet FortiAnalyzer a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.

System & Network Administrator at a tech services company with 11-50 employees
Gives us a simplified and user-friendly interface to work with
Pros and Cons
- "It has a simplified and user-friendly interface."
- "When it comes to pushing logs to a SIEM, most of the time we have some issues when it comes to filtering."
What is our primary use case?
We use the analyzer for reporting, to know what exactly is happening on the network. We use it to see which accesses are granted, which accesses are denied, which sites are visited, which botnets are coming in, which viruses, etc.
The solution is on-premise. Most of the time we set it up on the client's premises, depending on their needs. The cloud is there for testing.
What is most valuable?
It has a simplified and user-friendly interface.
What needs improvement?
With FortiAnalyzer, most of the time, although the interface is simplified, when you are new to it you have issues of navigating through it.
And when it comes to pushing logs to a SIEM, most of the time we have some issues when it comes to filtering.
Also, reports need to be simplified because its reporting currently includes more detailed and technical things. If we could get a simplified or executive summary, that would be good.
For how long have I used the solution?
We have been using this solution for about four or five years.
What do I think about the stability of the solution?
It's very stable, unlike the previous version which, when the logs were huge, would crash and we would have to reset it and start all over again.
What do I think about the scalability of the solution?
The scalability is also fine if you do your prerequisites right. If so, you won't have any issues. But if you don't do your scoping right, and more logs come into the system - more than it can handle - you will face issues. You need to do your scoping right to get it to be stable and scalable.
How are customer service and technical support?
Technical support is kind of slow. When you have 24/7 support, the response is quick. But when you send something in, it takes a long time to get a response. Fortinet support is a little bit slow when using their portal for support.
In our case, because we are partners, we have a couple of tech guys we can call to get support done. When an end-user requests support through the portal, and even when we do, it takes hours to get a response.
Which solution did I use previously and why did I switch?
We work with multiple solutions and Fortinet has been the number-one.
How was the initial setup?
For me, the initial setup was straightforward. The deployment takes approximately ten minutes. In some cases we could be waiting for results, waiting for logs to get up to do some analysis.
What's my experience with pricing, setup cost, and licensing?
The price is quite expensive. Fortinet products are very expensive. That is something which they should also look at, because if you compare Fortinet product to, say, Sophos for example, Fortinet is really high and that's the only thing which is a drawback for most users. Although their plan is a value-for-money appliance, the price is expensive.
What other advice do I have?
Anyone who asks me about a Fortinet product, I'll give that person a thumbs-up. So far, Fortinet has been the best for me. It's a value-for-money appliance, it has an easy to use interface, and it gives you exactly what you want. The only drawback would be the price.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
Buyer's Guide
Fortinet FortiAnalyzer
May 2025

Learn what your peers think about Fortinet FortiAnalyzer. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,823 professionals have used our research since 2012.
Information Security Specialist at Ministry of Heritage and Culture
Good network protection and web filtering capabilities with responsive technical support
Pros and Cons
- "The IBS (Intent Based Segmentation) and application web filtering are the most valuable aspects of the solution."
- "The solution could use more graphics and be more specific in the dashboard. This way, I'm able to understand everything and effectively understand what's going on, including what's incoming and outgoing. Right now, I have to look up everything. I need a dashboard so that I can see specific items right there in one place."
What is our primary use case?
We primarily use the solution to protect the network and to control how the users access and use the internet.
What is most valuable?
The IBS (Intent Based Segmentation) and application web filtering are the most valuable aspects of the solution.
What needs improvement?
The solution is quite expensive.
The solution could use more graphics and be more specific in the dashboard. This way, I'm able to understand everything and effectively understand what's going on, including what's incoming and outgoing. Right now, I have to look up everything. I need a dashboard so that I can see specific items right there in one place.
For how long have I used the solution?
I've been using the solution for three years.
What do I think about the scalability of the solution?
We have 600 users and do plan to increase usage in the future.
How are customer service and technical support?
Technical support is good. We've talked with them a few times. We have third-party support here in Oman.
Which solution did I use previously and why did I switch?
I didn't previously use another solution.
What about the implementation team?
A third party vendor assisted us with the implementation.
What's my experience with pricing, setup cost, and licensing?
We have around 12 devices and yearly we spend approximately $14,000.
What other advice do I have?
We are using the private cloud deployment model.
I would rate the solution nine out of ten. I don't have much to compare it to, but it's been fairly good.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Fraud Risk Analyst at a university with 1,001-5,000 employees
Provides analyzing tools, monitoring tools, and log management
Pros and Cons
- "From my perspective, we need to see the traffic in a good way so we can know what has happened in our network. The analyzing tools and the monitoring tools and the logs are the important part in the network."
- "The traffic monitoring could be better, and stability could be improved."
What is our primary use case?
The primary use cases are log management and the reporting fraud forum. It provides a vision of the network.
What is most valuable?
From my perspective, we need to see the traffic in a good way so we can know what has happened in our network. The analyzing tools and the monitoring tools and the logs are the important part in the network.
What needs improvement?
The traffic monitoring could be better, and stability could be improved.
For how long have I used the solution?
I have been using this solution for about two years.
What do I think about the stability of the solution?
The solution should be more stable.
What do I think about the scalability of the solution?
For the cloud version, you can expand it as you need it.
How are customer service and support?
I haven't contacted technical support.
How was the initial setup?
The solution is easy to install.
What's my experience with pricing, setup cost, and licensing?
FortiAnalyzer was in the product itself, but two years ago they split it from Fortinet. We paid the license two years ago.
What other advice do I have?
I would rate this solution 9 out of 10.
I can recommend this solution for other users.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Systems Architect at ZENTIUS
Great UI, good performance, and never crashes
Pros and Cons
- "Log collection is the most valuable. The UI looks great. It has a very good look and feel. We don't have the need to use solid state drives. We use mechanic drives, and we don't see any performance issues, so basically, it is doing fine."
- "It will be better if behavior or indicators of compromise were on the same licensing schema. Currently, it is an advanced feature that you have to purchase as an add-on. This is the reason we're trying to do the ELK so that we can integrate them and create those rules by using open-source software. It will also be better if it has some more integration with IT service management tools so that we can do endpoint protection and response based on those indicators of compromise or those behavior analysis rules that create events that can automatically flow. We can inject that data into a service incident ticket on our IT service management tool, and that way we can assign the ticket to the proper teams and respond right away. Currently, we only have integration with ServiceNow."
What is our primary use case?
We mostly use the FortiAnalyzer VM. We sell the license for this solution and also the professional service to have it.
There are different types of business needs of our clients because they're in different business areas. We have firewalls on them. Some of them are on the perimeter network, and some of them are being used as the core network solution. We collect all the logs from their FortiGates.
In some cases, we also use FortiWeb, which is a web application firewall. We also use FortiMail, which is an email protection solution or email security solution. We gather all the logs on FortiAnalyzer, and we try to do some flat counting and identify behavior or do behavior analysis from those logs and see what is interesting. Our team analyzes those events so that we can prevent any disruption of service because of the security, vulnerability, or issue.
What is most valuable?
Log collection is the most valuable. The UI looks great. It has a very good look and feel. We don't have the need to use solid state drives. We use mechanic drives, and we don't see any performance issues, so basically, it is doing fine.
What needs improvement?
It will be better if behavior or indicators of compromise were on the same licensing schema. Currently, it is an advanced feature that you have to purchase as an add-on. This is the reason we're trying to do the ELK so that we can integrate them and create those rules by using open-source software.
It will also be better if it has some more integration with IT service management tools so that we can do endpoint protection and response based on those indicators of compromise or those behavior analysis rules that create events that can automatically flow. We can inject that data into a service incident ticket on our IT service management tool, and that way we can assign the ticket to the proper teams and respond right away. Currently, we only have integration with ServiceNow.
For how long have I used the solution?
I have been using this solution for five years.
What do I think about the stability of the solution?
We have the box or the VM running for more than a couple of years now. We do upgrade so that we can add new features that Fortinet is releasing, but it is pretty stable. It never crashes.
What do I think about the scalability of the solution?
It is a little complex in terms of scalability and mostly because we're using a kind of high-end systems. For scaling, you have to order a different licensing and move more power and computing into a new architecture. It doesn't have that much scalability.
Our clients are SMB or small and medium businesses, but we also have plenty of customers on the campus wide area network.
How are customer service and technical support?
I would rate them a five out of ten. They will have to move their base locations to a different city. I'm not a native speaker of English, and sometimes, when we're trying, there is a language barrier. They're located in India or some Middle East city. They can do really better. Sometimes their response is not as adequate as other vendors.
How was the initial setup?
It was very straightforward. The deployment could take a couple of days to fine-tune all the rules for log management.
What other advice do I have?
There are plenty of solutions. Fortinet FortiAnalyzer is very helpful if you are really into FortiGate devices. We handle other firewalls, but 80% to 85% of them are Fortinet, so it is a very good solution because it has native integration with everything, but I wouldn't recommend it if you have less than 50% of Fortinet firewalls. If you have agnostic technology, you can integrate all of them into the same solution. FortiAnalyzer is only for FortiGates right now.
I would rate Fortinet FortiAnalyzer a nine out of ten. It just needs more integration with IT service management tools for endpoint detection and response, which is the main objective.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Head of Service at MPM
Has a useful dashboard and good scalability
Pros and Cons
- "The feature I find most useful is the handy dashboard."
- "I would like to see an improvement in the technical support. Stronger authentication will also be a plus."
What is our primary use case?
Our primary use case of this solution is for bandwidth. We are very satisfied with this program.
What is most valuable?
The feature I find most useful is the handy dashboard.
What needs improvement?
I would like to see an improvement in the technical support. Stronger authentication will also be a plus.
In the next version, I would like to have authentication for 40 tokens.
For how long have I used the solution?
I have been using Fortinet FortiAnalyzer for a month now on private cloud.
What do I think about the scalability of the solution?
We have between 20 and 25 users and we plan to increase this number, so I believe the program is scalable.
How are customer service and technical support?
We are very satisfied with the customer service.
How was the initial setup?
The initial setup was straightforward and deployment took us about eight months. The reason for this is that we installed other programs during this time too, like Fireworks Data Center, Switch Data Center, Cisco Nexus Data Center, and Forcepoint. We use Stitch as our local manager.
What's my experience with pricing, setup cost, and licensing?
All Fortinet programs come at a good price.
What other advice do I have?
I will definitely recommend this solution to others. My rating is a ten out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Information security officer at a financial services firm with 1-10 employees
Good value for money, works well with other Fortinet solutions, and has helpful support
Pros and Cons
- "The log events are quite useful for us."
- "We'd like to see more embedded features."
What is our primary use case?
The solution is used for grabbing logs. It is designed for log aggregation of all Fortigate firewalls and to give visibility of traffic and usage.
What is most valuable?
The log events are quite useful for us. The events aggregation from various Fortigate products makes it very helpful.
Technical support is helpful.
The stability is excellent.
This is a highly scalable product.
The setup is straightforward.
What needs improvement?
We'd like to see more embedded features.
We'd like to see more SIEM capabilities. I'd love to see this merged with FortiSIEM for example.
For how long have I used the solution?
I've been using the solution for around 20 years.
What do I think about the stability of the solution?
The stability is great. I'd rate it ten out of ten for reliability. We rarely have any issues.
What do I think about the scalability of the solution?
You pay compared to the volume of logs you collect. It is very scalable. It's highly expandable. On a scale from one to ten, I'd rate the scalability ten out of ten.
We have less than five network engineers using the product.
How are customer service and support?
I've dealt with support in the past and found them helpful and responsive.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We use a variety of Fortigate products.
We did not use a different vendor previously. There is no other real option. We did try to use the free version of Splunk. We moved to Fortianalyzer as it works better in Fortinet products. Splunk is harder to fit into other Fortinet products.
How was the initial setup?
The installation process only takes a couple of hours. It is easy to install.
The maintenance is very minimal. One person can handle maintenance tasks.
What about the implementation team?
We do use specialized consultants occasionally. However, I have been able to do it by myself as well in the past.
What's my experience with pricing, setup cost, and licensing?
I cannot speak of the exact price. Someone else manages the contract. However, you do get good value for your money. It's not overly expensive.
As it is on-premises, you do need some on-prem resources. You need a traditional hypervisor and need the ability to host the solution on your premises.
What other advice do I have?
We're customers and end-users.
We are using the latest version of the solution typically.
I'd recommend the solution to other users.
I would rate the solution ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Director General CEO at SC Telecom
Overall effective equipment management
Pros and Cons
- "Fortinet FortiAnalyzer is a complete package for managing our equipment."
- "The support could be better for Fortinet FortiAnalyzer here in Mexico."
What is most valuable?
Fortinet FortiAnalyzer is a complete package for managing our equipment.
For how long have I used the solution?
I have been using Fortinet FortiAnalyzer for approximately six years.
How are customer service and support?
The support could be better for Fortinet FortiAnalyzer here in Mexico.
What other advice do I have?
I would rate Fortinet FortiAnalyzer a nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free Fortinet FortiAnalyzer Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2025
Product Categories
Log ManagementPopular Comparisons
Dynatrace
Splunk Enterprise Security
IBM Security QRadar
Elastic Security
Elastic Observability
Grafana Loki
Security Onion
LogRhythm SIEM
Elastic Stack
syslog-ng
Amazon CloudWatch
Sumo Logic Security
Buyer's Guide
Download our free Fortinet FortiAnalyzer Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- When evaluating Log Management tools and software, what aspect do you think is the most important to look for?
- Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
- Which Windows event log monitoring tool do you recommend?
- What is the difference between log management and SIEM?
- Splunk vs. Elastic Stack
- How can Cloudtrail logs be used effectively to improve log monitoring?
- Why hot data and cold data differences in SIEM solutions are not discussed sufficiently?
- When evaluating Log Management solutions, what aspect do you think is the most important to look for?
- When evaluating Log Management solutions, what aspects do you think are the most important to look for?
- Why are Log Management tools important for companies?