The key functions for us are the next-gen firewall and network analytics. To ensure the best protection, we need to constantly analyze the situation in the network, as well as internal and external threats, as well as actual AV protection. The Fortinet products and FortiGuard services give us all of this.
Project manager at IRIDIS Group
Our company uses a virtual infrastructure. Implementing this product supplements the protection of our infrastructure.
What is most valuable?
How has it helped my organization?
Our company uses a virtual infrastructure. Implementing this product supplements the protection of our infrastructure.
What needs improvement?
The current version of the product is easy to use. Based on my experience, I can't recommend any areas of improvement. It's important, however, to know what you want prior to implementation. Otherwise, it may not meet your future needs based on the initial configurations.
For how long have I used the solution?
We've used it for about four months.
Buyer's Guide
Fortinet FortiAnalyzer
May 2025

Learn what your peers think about Fortinet FortiAnalyzer. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,604 professionals have used our research since 2012.
What was my experience with deployment of the solution?
During installation, we had no problems with deployment.
What do I think about the stability of the solution?
We have had no problems with stability.
What do I think about the scalability of the solution?
We have had no problems with scalability.
How are customer service and support?
The level of local customer service was very good. Per our request, tested the product. We got all answers to our questions from technical support. I rate both of them highly.
Which solution did I use previously and why did I switch?
We used Wallix AdminBastion together with it.
How was the initial setup?
The initial setup was straightforward.
What about the implementation team?
A successful implementation for this product depends on how clearly the customer understands what they have and what they need in the future. In most cases, the customer turns out to be unsatisfied when it's unclear that they knew what they wanted prior to implementation. My main recommendation is to implement it together with the vendor, writing down the tasks, solutions, and the expected result before you begin.
What's my experience with pricing, setup cost, and licensing?
I think Fortinet has a balanced offering of prices and licenses.
What other advice do I have?
Fortinet's strategy is based on the dividing the product line depending on functionality. This allows customers to choose only the necessary feature set for them.
The Fortinet product line is wide – you can choose from SOHO to Enterprise, and from hardware to virtual solution. The presence of a free client (Win/Android/OS X) provides protection for client workstations. Each customer will be able to find the most suitable solution for them.
The balanced policy product line and licensing allows customers to choose only the necessary feature set for them. Also you can easily migrate from other vendors using single tools for conversion. Another tool helps you plan the placement of Wi-Fi points in the building. Also, it's very important that equipment has international and national certification such as PCI, DSS, etc. Presentation of products for SDN (Software-defined Networks including SDDC - Software-defined Data Center) confirms the company's leading position in the market.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Consultor de Seguridad at Netrix, LLC (X956)
It supports SQL for logging and reporting
Pros and Cons
- "It supports SQL for logging and reporting. Log data is inserted into the SQL database for log view and report generation."
- "It is very important that FAZ can support FortiController as the architecture designed for the network. FortiController should be registered in FAZ at least for event logs."
What is our primary use case?
It receives logs from the FortiGate 5000 Series (about 12 FortiGate blades), and it was configured for keep logs for about 1,050 days. The logs are divided by archive (raw logs) and analytics (logs indexed in a database).
The use case is primarily for getting graphical data to make quick decisions.
How has it helped my organization?
FAZ has improved the organization because it stores events in the past so we can correlate incidents using another monitor tools; the problem is that it can´t recognize logs from FortiController blades, not even specifying it as a syslog device so this is a big lack. Devices from another brand are compatible only as syslog devices if they support.
What is most valuable?
It supports SQL for logging and reporting. Log data is inserted into the SQL database for log view and report generation.
Another feature is the custom reports, where you can obtain a chart builder from a log view: traffic, event, or security log.
What needs improvement?
It is very important that FAZ can support FortiController as the architecture designed for the network. FortiController should be registered in FAZ at least for event logs.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
No issues at all. It is a reliable product.
The problems come when you are using different OS versions between FortiGate and FortiAnalyzer.
What do I think about the scalability of the solution?
No scalability issues. You should know how many logs per second or minute are generated in your network to avoid issues with scalability.
How are customer service and technical support?
The technical support with Fortinet has risen considerably. Now, they respond in three to four hours instead of two days.
Which solution did I use previously and why did I switch?
We did not use a previous solution.
How was the initial setup?
The FAZ includes a wizard, which is very simple to follow during the initial setup.
What about the implementation team?
We implemented it in-house. We have had some experience implementing FAZ.
What was our ROI?
I do not have this value yet.
What's my experience with pricing, setup cost, and licensing?
The cost and pricing should be in accordance with the calculation of log storage capacity for a time period required for historical analysis.
Which other solutions did I evaluate?
We did not look at any other options, because Fortinet was elected for use by the end user.
What other advice do I have?
My only experience is with a very important customer, the most recognized in Latin America.
Disclosure: My company has a business relationship with this vendor other than being a customer: We are Grupo CEPRA, a channel for Fortinet sales.
Buyer's Guide
Fortinet FortiAnalyzer
May 2025

Learn what your peers think about Fortinet FortiAnalyzer. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,604 professionals have used our research since 2012.
Diretor Técnico at TND Brasil
Has good report templates and works very well for reporting and analysis
Pros and Cons
- "The report templates are valuable. It works very well, and integrations also work well."
- "Feature-wise, it is working very well for us. We don't need any additional features. However, its pricing can be improved. For small business customers, price is an important factor."
What is our primary use case?
We use it for reports and analysis.
What is most valuable?
The report templates are valuable. It works very well, and integrations also work well.
What needs improvement?
Feature-wise, it is working very well for us. We don't need any additional features. However, its pricing can be improved. For small business customers, price is an important factor.
For how long have I used the solution?
I have been using this solution for two years.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
It is easy to scale.
What's my experience with pricing, setup cost, and licensing?
It is expensive for small business customers. It is only available for customers with a high number of firewalls to manage or to report. If a customer has only five boxes of FortiGate, the price of FortiAnalyzer can be more than the five boxes. So, we can't easily put this solution for small business customers.
What other advice do I have?
I would rate this solution a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Technical Presales Engineer at Dristi Tech Pvt.ltd
Provides very good metrics, visibility of the network and does what a network analyzer should do
Pros and Cons
- "The feature that I have found the most valuable is to be able to see everything in our network in a single task. A single menu and the graphical bar charts that it provides to give insights are very useful. It also gives very good metrics on bandwidth utilization, CPU, and device performance. It is very simple and easy to use as well."
- "They can include integration with devices, such as firewalls, endpoints, from other vendors. They can include graphic monitoring of everything in the network, not just Fortinet products. It would also be good to include customizable reports and customizable views of the reports."
What is our primary use case?
Generally, Fortinet FortiAnalyzer gives you visibility around the network. You can track and monitor devices and pick the surrounding network. You can see which packets are being sent to the network, who the users are, and what are they using. You can also view the policies and firewall rules that are being used, the IDs that are being connected to, and the IP address a particular user is using.
Basically, it's a SOC. It's a security operations device. We use it for continuous monitoring, and it takes a team to do so. In my organization, three to four people are using it on a daily basis.
What is most valuable?
The feature that I have found the most valuable is to be able to see everything in our network in a single task. A single menu and the graphical bar charts that it provides to give insights are very useful.
It also gives very good metrics on bandwidth utilization, CPU, and device performance. It is very simple and easy to use as well.
What needs improvement?
They can include integration with devices, such as firewalls, endpoints, from other vendors. They can include graphic monitoring of everything in the network, not just Fortinet products.
It would also be good to include customizable reports and customizable views of the reports.
For how long have I used the solution?
I have been using Fortinet FortiAnalyzer for about five to eight months. We are using the latest version. We have deployed it on-premises as a VM.
What do I think about the stability of the solution?
It's pretty stable.
What do I think about the scalability of the solution?
I'd say that it's very scalable. Scalability depends on which version of the appliance you're using.
If you're using a hardware-based appliance, it's obviously tough to scale as that would require purchasing new devices. If you go to cloud services or virtual services, it's pretty easy to scale. You need to purchase new VMs and add the IOCs that you need, which is easy.
How are customer service and technical support?
I have contacted technical support, but not particularly regarding Fortinet FortiAnalyzer. I have only contacted them for firewalls and routing issues. I have not yet contacted them for things related to Fortinet FortiAnalyzer.
How was the initial setup?
It's very easy and straightforward. You just need the point the FortiGate devices to your Fortinet FortiAnalyzer, and it just automatically configures the security fabric. The time depends on how many devices you're actually using. Configuring one device into your Fortinet FortiAnalyzer takes about five minutes or so.
What about the implementation team?
The deployment was pretty straightforward. I didn't need any help in setting it up. I did it myself very easily. It comes with useful guidelines for setting it up. They also provide documentation and information through their website.
One person can easily do the deployment, but the main goal of the solution is to continue to monitor the regular network traffic for which a team is required. Our software team is responsible for handling such things.
Which other solutions did I evaluate?
This product is only dedicated to packet analyzing, automation, and things like that. I have not used analyzers of other vendors. However, other solutions do provide similar functionalities.
What other advice do I have?
It is kind of a very good network packet analyzer solution. It does what a network analyzer should do, and it does it very well.
In terms of firewalls and using network analyzers, Fortinet has always been the leader among the leaders. Fortinet provides very good features and products. Specifically, if you want to use Fortinet FortiAnalyzer, you need to have a FortiGate environment. You need at least one FortiGate or other similar product in your network. So, if you are already using or are into Fortinet products, then FortiAnalyzer is a very good product to add on top of other products. Having only FortiAnalyzer in your network is kind of useless.
I would rate Fortinet FortiAnalyzer a nine out of ten. It's a very good product.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Senior Associate Consultant - Network at a tech services company with 501-1,000 employees
It gives us reporting features, which are helpful in the case of troubleshooting and audit purposes. It should have straightforward customized reports.
Pros and Cons
- "It gives us reporting features, which are helpful in the case of troubleshooting and audit purposes."
- "It gives you live logs, which can be really helpful during troubleshooting."
- "It should have customized reports as well. While it currently has them, you need to write a script which is not straightforward."
- "The technical support takes at least two days to reply on any ticket post raised on their website."
What is our primary use case?
This product is only used for logs and reporting.
How has it helped my organization?
It gives us reporting features, which are helpful in the case of troubleshooting and audit purposes.
What is most valuable?
It has detailed reporting, e.g., user-wise reporting, threat analysis, etc. It also gives you live logs, which can be really helpful during troubleshooting.
What needs improvement?
It should have customized reports as well. While it currently has them, you need to write a script which is not straightforward.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
No issues.
What do I think about the scalability of the solution?
No issues.
How are customer service and technical support?
I would rate it as a two out of 10. The technical support takes at least two days to reply on any ticket post raised on their website.
Which solution did I use previously and why did I switch?
We did not have a previous solution.
How was the initial setup?
Initial setup is straightforward, and it has an easy setup.
What's my experience with pricing, setup cost, and licensing?
It depends upon the company.
Which other solutions did I evaluate?
We evaluated SonicWall and Cisco.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Implementation Manager at a tech services company with 51-200 employees
Easy to implement and robust with good technical support
Pros and Cons
- "The solution is very easy to deploy."
- "In future releases, we'd like to see more granular reporting. The reports on offer right now are pretty short."
What is our primary use case?
We're resellers of Fortinet. The solution is a product for doing diagnostics on their security environment. Our primary clients are banks or medical organizations.
What is most valuable?
The solution is very easy to deploy.
We are very familiar with the product. It makes it easy to use and implement.
The interface is easy to configure and fast to deploy. For that reason we use FortiAnalyzer.
What needs improvement?
FortiAnalyzer only works with other Fortinet products. If you need to analyze the data from other devices, other vendors, this solution is not the best one to use.
The interoperability with other vendors is lacking. It's very limited. You can scan the logs from other vendors within FortiAnalyzer, however, it only collects these logs. You can't analyze anything coming from other devices or vendors. This works very well with Fortinet products. When you need to interoperate with other vendors, it's difficult, because you don't have that support.
In future releases, we'd like to see more granular reporting. The reports on offer right now are pretty short.
For how long have I used the solution?
We've been using the solution for more than ten years at this point. It's been a decade or so.
What do I think about the stability of the solution?
The stability of the solution is excellent. It's very robust. We don't have issues with bugs or glitches. It doesn't crash or freeze. It's extremely reliable.
What do I think about the scalability of the solution?
The scalability is okay, however, it depends. If you do your homework and make the right sizing, you don't need the scalability. However, if you need scalability, it depends on the kind of client. You may need to change the box or move the FortiAnalyzer to another analyzer - something bigger - or maybe move the analyzer hardware to a better machine, depending on the customer.
Normally, we deal with small to medium-sized organizations.
How are customer service and technical support?
The technical support is very good. We have support right here in our country, and they give us very good support. We don't have a problem in this case. We've very satisfied with the level of service we get.
How was the initial setup?
The initial setup is not complex at all. It's very, very straightforward.
The deployment is quick and it's easy to configure. How long it takes depends on the size of the company that we are working for. Normally, we're able to do it within the same day, and we deploy the device or the virtual machine within that time frame. Depending on the requirements of the company, we may also optimize the reporting.
What about the implementation team?
We handle the deployment ourselves. We've been doing it for so long at this point, we've very comfortable with it.
What other advice do I have?
We use different deployment versions of Fortinet solutions. We use, for example, 200E and 200D and 100 too. These are the most popular. Right now, use the virtual environment.
This is a product that is very good for when you're using a Fortinet ecosystem. If you have a mix of vendors, it's not recommended.
Overall, I would rate the solution at a nine out of ten. We've been quite happy with their offering.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
System Administrator at a logistics company with 51-200 employees
Offers solid anti-virus protection but isn't so scalable
Pros and Cons
- "The anti-virus protection it offers our clients is solid."
- "The technical support is not very reliable."
What is most valuable?
The anti-virus protection it offers our clients is solid.
What needs improvement?
Currently, no solution can offer you 100% protection from viruses such as WannaCry ransomware. Fortinet should strive to improve their prevention systems.
For how long have I used the solution?
I have been using this solution for about two to three years.
What do I think about the stability of the solution?
This solution is stable.
What do I think about the scalability of the solution?
FortiAnalyzer does slow down when there is a heavy load of users, but it still does its job. Also, when many logs are generated throughout many sessions, the Analyser slows down.
How are customer service and technical support?
The technical support is not very reliable. Sometimes it takes them up to a week to get back to us.
How was the initial setup?
The initial setup is not complex. The basic setup takes roughly 30 minutes to one hour — reconfiguration can take up to one day.
What other advice do I have?
If you have Fortinet Firewall, you must implement FortiAnalyzer because, without the Analyzer, you can't generate the polls.
On a scale from one to ten, I would give this solution a rating of seven. I would give them a higher rating if they improved their scalability.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
IT Director with 501-1,000 employees
I'm able to see each IP separately, including user name and other stats, but the admin UX needs improvement.
What is most valuable?
- Real time reports
- Reports on who tried to attack
- FortiGate monitor
How has it helped my organization?
Before using FortiAnalyzer, people would surf wherever and we could not monitor or see which computer in the company goes where. Everyone had the same IP. Now, using the analyzer, I am able to see each IP separately, including user name and other stats. One time the police called and told me someone from the company was breaking the law and I was able to monitor the specific computer.
What needs improvement?
They should learn from CheckPoint how to design UX for admins.
What was my experience with deployment of the solution?
No issues encountered.
What do I think about the stability of the solution?
It's very stable.
How are customer service and technical support?
Customer Service:
I've not used them yet.
Technical Support:I've not used them yet.
Which solution did I use previously and why did I switch?
We previously used a previous solution.
How was the initial setup?
It was straightforward.
What about the implementation team?
We did it in-house.
What was our ROI?
It's a great ROI for the price.
What's my experience with pricing, setup cost, and licensing?
Only get it if you need it.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free Fortinet FortiAnalyzer Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2025
Product Categories
Log ManagementPopular Comparisons
Dynatrace
Splunk Enterprise Security
IBM Security QRadar
Elastic Security
Elastic Observability
Grafana Loki
Security Onion
LogRhythm SIEM
Elastic Stack
syslog-ng
Amazon CloudWatch
Sumo Logic Security
Buyer's Guide
Download our free Fortinet FortiAnalyzer Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- When evaluating Log Management tools and software, what aspect do you think is the most important to look for?
- Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
- Which Windows event log monitoring tool do you recommend?
- What is the difference between log management and SIEM?
- Splunk vs. Elastic Stack
- How can Cloudtrail logs be used effectively to improve log monitoring?
- Why hot data and cold data differences in SIEM solutions are not discussed sufficiently?
- When evaluating Log Management solutions, what aspect do you think is the most important to look for?
- When evaluating Log Management solutions, what aspects do you think are the most important to look for?
- Why are Log Management tools important for companies?
I think Fortinet has a balanced offering of prices and licenses.
%50 %50