C N R Prabashan - PeerSpot reviewer
Assistant Manager - Information Security & Infrastructure at lankatiles
Real User
Top 5
Comprehensive technical reports clearly identify any issues
Pros and Cons
  • "Technical reports clearly identify system checks, locations and areas, how many times things escape, which firewall is affected, and source IDs."
  • "Software reports are good but should match the dashboard and include top-level output instead of just base or low-level devices."

What is our primary use case?

Our company uses the solution to capture our Forti Firewall into a centralized box and auditing folder that is analyzed at least once per year. Four staff members use the solution, produce detailed reports, and manage operations. 

We initially implemented the solution on-premises at our data center in Colombo City. Now, we are implementing things to the cloud so our next plan is to secure cloud-level protection. 

What is most valuable?

Technical reports clearly identify system checks, locations and areas, how many times things escape, which firewall is affected, and source IDs. 

What needs improvement?

Software reports are good but should match the dashboard and include top-level output instead of just base or low-level devices. Currently, we need to look into web URLs to analyze information. We are planning to move to the next level because we need threads for other devices such as HDMI or VGA output. 

For how long have I used the solution?

I have been using the solution for four years. 

Buyer's Guide
Fortinet FortiAnalyzer
May 2024
Learn what your peers think about Fortinet FortiAnalyzer. Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
771,212 professionals have used our research since 2012.

What do I think about the stability of the solution?

The solution is stable. 

What do I think about the scalability of the solution?

The solution is scalable. 

The management side requires an additional user account that is maintained and AD authenticated by the analyzer. It would be easier to integrate features without this required account that limits scalability from the management side. 

How are customer service and support?

A few years ago, we were implementing and had a session expired issue because the application session had expired on the national channel level. We contacted local agents who reached out to support. The help desk successfully sorted out and fixed the issue. Support is located in India and uses the English language. 

How was the initial setup?

The setup is straightforward with a very easy deployment program. Some IT knowledge is helpful but it is not hard to setup or manage the solution. 

What's my experience with pricing, setup cost, and licensing?

Base features used to be priced lower but now are a bit higher. We have some requirements and combine more than 100 showrooms to the SDN with the MLPS connection. Compared to other products, the price is a little bit high. 

I rate pricing an eight out of ten.

Which other solutions did I evaluate?

We did not evaluate other options. 

What other advice do I have?

The solution has good availability and provides good information. A few features can be improved to a degree.

I rate the solution an eight out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Alain ClovisBapfunya - PeerSpot reviewer
Cyber Security Specialist at EAST-NB
Real User
Top 10
It aggregates and correlates all the events from multiple sources
Pros and Cons
  • "Many of my clients are financial institutions that transmit files from around the country across a VPN. In a setup like this, it's helpful to have a centralized dashboard to manage firewalls and other security solutions across a distributed environment. You can do all sorts of analysis and configure it to trigger alarms."
  • "FortiAnalyzer only integrates with Fortinet solutions. That is a limitation because many organizations use multiple vendors. It's often a mixture of Cisco network hardware and equipment from other vendors, such as switches, access points, etc."

What is our primary use case?

FortiAnalyzer provides a centralized dashboard for analyzing the output of all our Fortinet solutions, like FortiGate, FortiManager, FortiSandbox, etc. It aggregates and correlates all the events.

What is most valuable?

Many of my clients are financial institutions that transmit files from around the country across a VPN. In a setup like this, it's helpful to have a centralized dashboard to manage firewalls and other security solutions across a distributed environment. You can do all sorts of analysis and configure it to trigger alarms. 

What needs improvement?

FortiAnalyzer only integrates with Fortinet solutions. That is a limitation because many organizations use multiple vendors. It's often a mixture of Cisco network hardware and equipment from other vendors, such as switches, access points, etc. 

For how long have I used the solution?

We have used FortiAnalyzer for one year.

What do I think about the stability of the solution?

FortiAnalyzer is stable as long as you don't push it. It can cause trouble if you are overreliant on virtual machines and you don't have hardware acceleration. You might see some performance problems. 

What do I think about the scalability of the solution?

FortiAnalyzer is scalable. It covers FortiGate firewalls, switches, etc. You can always buy more licenses or hardware if you need to upgrade. 

How are customer service and support?

The response times could be faster.

How was the initial setup?

Setting up FortiAnalyzer is straightforward. It doesn't take long because everything is already built for you unless you need to do some virtualization. The specific steps depend on your environment and what kind of device fabrics you use. 

What's my experience with pricing, setup cost, and licensing?

They have three-year licenses, but I usually recommend starting with a one-year license to try FortiAnalyzer out. After that, you can switch to a three-year license. 

What other advice do I have?

I rate FortiAnalyzer nine out of 10. I recommend FortiAnalyzer to anyone who is using Fortinet products. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Implementer
PeerSpot user
Buyer's Guide
Fortinet FortiAnalyzer
May 2024
Learn what your peers think about Fortinet FortiAnalyzer. Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
771,212 professionals have used our research since 2012.
IgnitiusMolepo - PeerSpot reviewer
Senior IP Network Defense at MTN
Real User
Top 5Leaderboard
Reporting features like graphs, threat intelligence, and vulnerabilities analysis are helpful
Pros and Cons
  • "FortiAnalyzer's reporting features like graphs, threat intelligence, and vulnerabilities analysis are helpful. Fortinet knows how to do reporting. You can customize your reports to show exactly what you want to analyze. It's user-friendly and doesn't require a lot of effort."
  • "If Fortinet could introduce some firewalling or maybe FortiAnalyzer on the cloud, that would be interesting because I've never seen it on a cloud."

What is our primary use case?

We use FortiAnalyzer as our indicator of compromise solution, and I'm also running some SOC into it. 

What is most valuable?

FortiAnalyzer's reporting features like graphs, threat intelligence, and vulnerabilities analysis are helpful. Fortinet knows how to do reporting. You can customize your reports to show exactly what you want to analyze. It's user-friendly and doesn't require a lot of effort. 

The hub is another feature that's good to use. FortiAnalyzer can be connected to other Fortinet devices via the hub. It isn't restricted, and it's all controlled by FortiManager. It can also integrate all the opcodes to one box. 

What needs improvement?

If Fortinet could introduce some firewalling or maybe FortiAnalyzer on the cloud, that would be interesting because I've never seen it on a cloud. 

For how long have I used the solution?

We've been using FortiAnalyzer since 2015. 

What do I think about the stability of the solution?

FortiAnalyzer is stable. It will do the work as long as your FortiGate is stable. It depends more on the FortiGate, so if your FortiGate is cool, there's no problem. If there is a problem, you can bypass it most of the time. I can't say that there are no issues. I don't want to lie.

What do I think about the scalability of the solution?

FortiAnalyzer is scalable. It can even take over traffic from other analyzers. You can connect as many analyzers as you want to it. 

Which solution did I use previously and why did I switch?

I used a McAfee SIEM solution before at my previous employer, but it's not as powerful as FortiAnalyzer. I used a Rapid7 solution and Cisco FirePOWER, which are both weak.

How was the initial setup?

We don't need to do much to install FortiAnalyzer because it always depends on FortiGate. You need to deploy FortiGate before you install it. That's why I say that I see it as a dummy box. I don't see anything interesting in it. It's only a support structure.

What other advice do I have?

I rate FortiAnalyzer seven out of 10. It's a very user-friendly box. You don't even need to know the CLI. It has a CLI, but you don't need to know it because the GUI is excellent. It's always doing its duty to keep up with the reporting. 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Security Manager at Yarix S.r.l.
Real User
Top 5Leaderboard
We can gather logs and generate reports, but the license cost is high
Pros and Cons
  • "The most valuable feature is the capability to gather logs and generate reports."
  • "The integration with other vendors for log collection could be enhanced."

What is our primary use case?

Fortinet FortiAnalyzer is utilized to gather logs from all Fortinet products and generate reports.

What is most valuable?

The most valuable feature is the capability to gather logs and generate reports. Without this solution, the firewalls exhibit limited proficiency in displaying logs.

What needs improvement?

The integration with other vendors for log collection could be enhanced.

The licensing cost has room for improvement.

For how long have I used the solution?

I have been using Fortinet FortiAnalyzer for over three years.

What do I think about the stability of the solution?

I rate FortiAnalyzer's stability a nine out of ten. We have had instances of data loss or source loss.

What do I think about the scalability of the solution?

For our needs, FortiAnalyzer is scalable because we are not dealing with thousands of firewalls.

How are customer service and support?

The technical support is good.

How was the initial setup?

The initial setup is straightforward. The deployment took a couple of days.

For the deployment, we needed to create the server for deploying the FortiAnalyzer image and create the policy rules. We also had to complete the basic configuration of FortiAnalyzer. Following that, we configured all the resources and logs within FortiAnalyzer to collect and correlate the logs, which are then used to generate reports.

What about the implementation team?

We used a consultant for the implementation.

What's my experience with pricing, setup cost, and licensing?

We pay for an annual license, but we have the ability to determine the payment schedule with our distributor.

The cost of the license is high.

What other advice do I have?

I would give Fortinet FortiAnalyzer a rating of six out of ten. I am not satisfied with the solution as it falls short of a proper SIEM. Therefore, we would prefer to allocate more funds towards a SIEM in order to effectively collect logs.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Baherathan Kathirgamanathan - PeerSpot reviewer
Assistant Manager - Cloud Planning and Development at a comms service provider with 1,001-5,000 employees
Real User
Top 10
An economical solution that provides good standard reports and is easy to troubleshoot
Pros and Cons
  • "The solution provides good standardized reports and is easy to troubleshoot."
  • "The solution should include the ability to customize reports so that customers receive greater value and high level reporting."

What is our primary use case?

Our company is partners with Fortinet and we provide log monitoring services to our customers. More than one hundred people in our company use the solution. 

What is most valuable?

The solution provides good standardized reports and is easy to troubleshoot. 

What needs improvement?

The solution should include the ability to customize reports so that customers receive greater value and high level reporting. 

I would also like to be able to view a real-time log. 

For how long have I used the solution?

I have been using the solution for seven years. 

What do I think about the stability of the solution?

The solution is stable. I rate it an eight out of ten. 

What do I think about the scalability of the solution?

The solution is scalable. I rate it a seven out of ten. 

How are customer service and support?

Technical support is very good. 

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is very straightforward and is accomplished via quick installation.  

What about the implementation team?

We install the solution for customers. One of our technicians handles base deployment which can take two or three years depending on our customer's needs. 

What's my experience with pricing, setup cost, and licensing?

The hardware has a one-time cost and maintenance is paid by annual subscription. 

Customers contracts are on a monthly basis and include log monitoring services, maintenance, and technical support provided by two technicians. 

The solution is not that expensive and I rate it a five out of ten. 

What other advice do I have?

The solution pairs very well with other Fortinet products.

I rate the solution an eight out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Daniel Coleman - PeerSpot reviewer
CEO/CTO at Eunoia Design
Real User
Top 10
It creates a central point of management and control, giving you real-time insight into what is going on.
Pros and Cons
  • "One of the most valuable features is the ability to analyze data in real-time using AR features to pull data from the industrial DB. You can know what is going on and see in milliseconds where the network is underperforming."
  • "The UI could use some improvement. It can be tough for a beginner to navigate because you don't know what to do even if you read the guide. I've talked to some users who said that they couldn't figure out what to do even after looking at the documentation."

What is our primary use case?

We have multiple firewalls linked through a VPN. There is traffic from several branches and multiple points of failure, so you need to analyze this traffic to know what's coming in and going out. When you have more chains, there are more points of failure that can be exploited.  

I use FortiAnalyzer on-premise and on the cloud. I update the solution at least once a year. I always update the firewall to the latest edition, so I can have three months or four months to test it in the VM. I use even more products and also AWS and Azure Cloud. About 9 percent of my company is responsible for security and networking. Everybody's on my team works with FortiAnalyzer.

Our department has three security architects and four network engineers. They are beginning to place assistant administrators on the network. 

How has it helped my organization?

FortiAnanalyzer ensures you have an accurate view of all your devices, so you don't need to check each one. The analyzer creates a central point of management and control, giving you insight into what is going on. 

So you want to move through that traffic that's coming in as the lock the analyzer will like to analyze the traffic in real-time so you can know what is going on. Yeah, so you customize it to be able to analyze what you want it to be able to analyze.

What is most valuable?

One of the most valuable features is the ability to analyze data in real-time using AR features to pull data from the industrial DB. You can know what is going on and see in milliseconds where the network is underperforming. 

FortiAnalyzer also has good storage capacity for storing the logs. The notification capabilities are excellent, too. It sends alerts so always know what is going on. For example, if you're on a break and something goes wrong, it lets you know so can immediately go back and fix it. You don't need to be constantly sitting in front of it. 

What needs improvement?

The UI could use some improvement. It can be tough for a beginner to navigate because you don't know what to do even if you read the guide. I've talked to some users who said that they couldn't figure out what to do even after looking at the documentation. 

They need to update guide so it's more aligned with what the UI shows. The guide has lots of stuff in it, there sometimes you still don't get it. It takes too long for a new version of the documentation to come out. It still works, but the problem is that the UI is completely different, so it's challenging to find things. 

For how long have I used the solution?

I have used FortiAnalyzer for the last three and a half years.

What do I think about the stability of the solution?

FortiAnalyzer is stable at the time of release. You don't have problems when you install it. There aren't configuration breaks that you have to go fix. When you update, the transition is smooth. 

What do I think about the scalability of the solution?

FortiAnalyzer is scalable.

How are customer service and support?

I have contacted Fortinet support once or twice, but not for FortiAnalyzer. Some of my clients had a problem with FortiGate and the traffic-shaping policy. The traffic-shaping policy in the later version of FortiGate doesn't work like it used to. 

Fortinet's technical support was dependable, helpful, and knowledgeable about the product. They were prompt and responsive, so it was good. I rate Fortinet support 10 out of 10. 

Which solution did I use previously and why did I switch?

I was using Cisco ASA before FortiAnalyzer. I started using SonicWall six years ago, and five years I discovered FortiGate. I find FortiAnalyzer easier to use than the other products.

How was the initial setup?

Setting up FortiAnalyzer is a bit complex for a beginner because you have a shallow understanding of what it is. Configuring the advanced features is somewhat challenging, but the basic setup isn't that tough. 

Setting up FortiAnalyzer takes around five to 10 minutes. I rate my setup experience 10 out of 10. After deployment, there isn't too much maintenance. It's just the usual updates. That's it.

What about the implementation team?

I do the setup in-house. If I'm setting FortiAnalyzer for a client, I will typically walk them through step by step with the team, so they know how to set it up and what everything does. 

What's my experience with pricing, setup cost, and licensing?

I rate FortiAnalyzer six out of 10 for affordability. FortiAnalyzer pricing isn't steady. It changes each quarter or year. That's one of the main problems in West Abaco because most businesses here are small or medium-sized enterprises. It makes budgeting complicated. You always want to pay the same price on the subscription.

At the same time, I think Fortinet pricing is reasonable compared to all the others. The value you get from Fortinet is better because it beats other vendors in terms of performance, functionality, and efficiency. New firewalls like Alexa are trying to compete in pricing, and people are looking into it to see, but Fortinet is good for now. However, they need to work on keeping the price consistent.  

What other advice do I have?

I rate FortiAnalyzer nine out of 10. My advice to anyone implementing FortiAnalyzer is to read about a product. If you do your homework, it's easier to set up. The next thing is to understand your environment, especially if you have multiple links over your network that leave you more vulnerable to attacks. 

The more links you have, the more exposed you are to attacks. It is possible that one link can be vulnerable, and you won't take notice.FortiAnalyzer is the best choice. 

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
João Carvalho - PeerSpot reviewer
TIO at Fundação de Serralves
Real User
Useful for log management and endpoint protection
Pros and Cons
  • "The most valuable features of the solution are the reports and the playbooks."
  • "I feel that Fortinet FortiAnalyzer is a little bit heavy, making it an area where improvements are required."

What is our primary use case?

I use the solution in my company for log management and to comply with requirements associated with endpoint protection and FortiGate, as well as with all the other solutions from Fortinet.

What is most valuable?

The most valuable features of the solution are the reports and the playbooks.

What needs improvement?

I feel that Fortinet FortiAnalyzer is a little bit heavy, making it an area where improvements are required.

For how long have I used the solution?

I have been using Fortinet FortiAnalyzer for three years. I am an end user of the solution.

What do I think about the stability of the solution?

Stability-wise, I rate the solution an eight out of ten.

What do I think about the scalability of the solution?

Scalability-wise, I rate the solution an eight out of ten.

Two people in my company use the product.

I use the solution in my company every day.

How are customer service and support?

I rate the technical support a nine out of ten.

Which solution did I use previously and why did I switch?

I have experience with some other solutions in the past. My company has not switched from the solution we use currently because we don't have an alternative product. My company does want to use an SIEM solution, and we purchased Fortinet FortiAnalyzer since it offered a bit of SIEM functionalities.

How was the initial setup?

My company took care of the tool's initial setup phase for our internal projects.

The solution is deployed on an on-premises model.

The solution can be deployed in two days.

What about the implementation team?

An implementer took care of the product's implementation process.

What was our ROI?

I have seen a return on investment from the use of the product. I rate the tool's ROI a nine out of ten.

What's my experience with pricing, setup cost, and licensing?

I rate the product's price a six on a scale of one to ten, where one is cheap, and ten is expensive.

What other advice do I have?

The log management capability has benefited our organization, and it is important because we need to write and send proactive information that playbooks can cater to, and the product also prevents my company's systems from being attacked.

I recommend the product to others since it is easy to work with and it works very well.

I don't know much about the artificial integration capabilities of the product, but the solution works to detect and analyze threats.

I rate the overall tool an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Senior Systems Engineer at a pharma/biotech company with 51-200 employees
Real User
Offers visibility and helps to analyze the traffic but improvement is needed in pricing
Pros and Cons
  • "Our use case for Fortinet FortiAnalyzer is analyzing traffic. We use it to investigate complaints about account access, check if something is blocked or working, and understand what's happening inside them."
  • "Fortinet FortiAnalyzer needs to improve its pricing flexibility."

What is our primary use case?

Our use case for Fortinet FortiAnalyzer is analyzing traffic. We use it to investigate complaints about account access, check if something is blocked or working, and understand what's happening inside them.

What is most valuable?

The solution provides visibility into traffic. We can view everything from one platform.

What needs improvement?

Fortinet FortiAnalyzer needs to improve its pricing flexibility. 

For how long have I used the solution?

I have been using the product for a couple of months. 

What do I think about the stability of the solution?

I rate the tool's stability a seven out of ten. We have experienced downtime and glitches while using it. These were during the deployment stages, and the vendor helped to fix them. 

What do I think about the scalability of the solution?

I rate Fortinet FortiAnalyzer's scalability a nine out of ten. My company has 100 users. 

Which solution did I use previously and why did I switch?

I used Palo Alto Panorama before Fortinet FortiAnalyzer. I think Palo Alto Panorama is better. It offers more functionality. We typically need separate solutions for different needs with Fortinet FortiAnalyzer, but Palo Alto Panorama bundles everything into one package. Whether deploying and managing firewalls, analyzing traffic, or managing users, Palo Alto Panorama consolidates it into a single dashboard.

How was the initial setup?

Fortinet FortiAnalyzer's deployment is easy. 

What about the implementation team?

The tool's deployment was done by a third party. 

What's my experience with pricing, setup cost, and licensing?

I rate Fortinet FortiAnalyzer's pricing as five out of ten. 

What other advice do I have?

We recently switched to the product and are in the stages of a learning curve. I rate the overall product a five out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Buyer's Guide
Download our free Fortinet FortiAnalyzer Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2024
Product Categories
Log Management
Buyer's Guide
Download our free Fortinet FortiAnalyzer Report and get advice and tips from experienced pros sharing their opinions.