We compared Fortinet FortiAnalyzer and Graylog based on our users' reviews in five categories. We reviewed all of the data and you can find the conclusion below.
Features: Fortinet FortiAnalyzer features exceptional log collection capabilities and customizable reporting. Graylog stands out with its exceptional search functions, seamless integration with Elasticsearch, and real-time data access. FortiAnalyzer enables users to centrally manage and analyze logs in real time. Fortinet FortiAnalyzer could simplify its reporting module and cloud storage capabilities. Graylog could benefit from additional customization options and an improved rule-creation process.
Service and Support: Some Fortinet customers were dissatisfied with support, but others said it was helpful and responsive. Graylog's customer service is generally well-regarded, with reviewers noting effective solutions and satisfactory experiences. While response times may differ, Graylog's support is considered superior compared to that of other products.
Ease of Deployment: FortiAnalyzer's initial setup is uncomplicated and manageable, typically taking approximately 30 minutes to a few hours. Some IT knowledge may be required. Some Graylog users said the setup was easy. Other reviewers faced challenges, but these were easily resolved with help from the vendor’s support staff. Graylog is easier to set up in smaller environments, but it could get complicated in large clusters.
Pricing: While FortiAnalyzer isn't the most expensive option, users say the pricing could be more competitive. FortiAnalyzer's cost depends on the storage requirements, and many customers consider it reasonable. Graylog offers an enterprise edition and an open-source option with a daily capacity restriction. Some users said that data costs can be expensive.
ROI: FortiAnalyzer helps customers by providing insight into network traffic and speeding up issue resolution. Graylog can offer some cost savings. The precise ROI may vary depending on the organization’s size and use case.
"Technical reports clearly identify system checks, locations and areas, how many times things escape, which firewall is affected, and source IDs."
"The solution provides good standardized reports and is easy to troubleshoot."
"It's a very stable product."
"It gives us reporting features, which are helpful in the case of troubleshooting and audit purposes."
"The initial setup is straightforward."
"The solution allows for a lot of customization."
"Logging is the best feature."
"We use this functionality every day, and obtain reports on things like how many people are using the VPN, which websites are being accessed, and whether hackers are trying to penetrate into our network."
"The product is scalable. The solution is stable."
"The best feature of Graylog is the Elasticsearch integration. We can integrate and we can run filters, such as an event of interest, and those logs we can send to any SIEM tool or as an analytic. Additionally, there are clear and well-documented implementation instructions on their website to follow if needed."
"This had increased productivity for the dev and support teams, because we are directly notifying them."
"One of the most valuable features is that you are able to do a very detailed search through the log messages in the overview."
"The solution's most valuable feature is its new interface."
"UDP is a fast and lightweight protocol, perfect for sending large volumes of logs with minimal overhead."
"I like the correlation and the alerting."
"I am very proud of how very stable the solution is."
"When it comes to pushing logs to a SIEM, most of the time we have some issues when it comes to filtering."
"FortiAnalyzer only integrates with Fortinet solutions. That is a limitation because many organizations use multiple vendors. It's often a mixture of Cisco network hardware and equipment from other vendors, such as switches, access points, etc."
"The FortiAnalyzer is not scalable."
"Technical support could respond to queries faster."
"The solution can improve the incident response function to provide more detailed information on where the incident is originating."
"One thing we struggled with FortiAnalyzer was integration with SIEM. We also had issues with the new threats and APTs. There were false positives, so we needed to have some ratings related to false positives."
"I would like to see an improvement in the technical support. Stronger authentication will also be a plus."
"The cloud version can be expensive. If the customers could get the resources to store the logs on-premises, it would be much better."
"With technical support, you are on your own without an enterprise license."
"Graylog can improve the index rotation as it's quite a complex solution."
"I would like to see a date and time in the Graylog Grok patterns so that I can save time when searching for a log. I like how the streams and the search query work, but adding a date and time will allow me to pull out a log in a milli-second."
"Dashboards, stream alerts and parsing could be improved."
"We ran into problems with Elasticsearch throwing a circuit-breaking exception due to field data size being too large. It turned out that the heap size directly impacted this size in a high-throughput environment, causing unexplained instability in Graylog. We were able to troubleshoot on the Elasticsearch size, but we should have been able to reference some minimum requirements for Graylog to know that our settings weren't sufficient."
"It would be great if Graylog could provide a better Python package in order to make it easier to use for the Python community."
"More customization is always useful."
"There should be some user groups and an auto sign-in feature."
Fortinet FortiAnalyzer is ranked 7th in Log Management with 44 reviews while Graylog is ranked 11th in Log Management with 6 reviews. Fortinet FortiAnalyzer is rated 8.0, while Graylog is rated 8.0. The top reviewer of Fortinet FortiAnalyzer writes "It creates a central point of management and control, giving you real-time insight into what is going on. ". On the other hand, the top reviewer of Graylog writes "Real-time analysis, easy setup, and open source". Fortinet FortiAnalyzer is most compared with Wazuh, Splunk Enterprise Security, ManageEngine EventLog Analyzer, LogRhythm SIEM and IBM Security QRadar, whereas Graylog is most compared with Grafana Loki, Wazuh, syslog-ng, Splunk Enterprise Security and Elastic Security. See our Fortinet FortiAnalyzer vs. Graylog report.
See our list of best Log Management vendors.
We monitor all Log Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.