Sora Yazılım
English
Custom software solutions from Türkiye
Fortinet · Network Security

FortiAnalyzer

Central logging, compliance reporting and SOC automation for the Security Fabric.

Quick answer

FortiAnalyzer is the central log collection, analytics and reporting platform of the Fortinet Security Fabric; it normalizes records arriving from FortiGate, FortiClient, FortiMail and third-party sources into a single data lake, correlates them, produces ready-made compliance reports such as PCI-DSS and HIPAA, and retains the audit trail expected by KVKK (Turkey's data protection law) technical measures. Built-in SIEM/SOAR capabilities, playbook automation and the FortiAI assistant shorten response times for small SOC teams.

FortiAnalyzer is the central log collection, retention, analytics and reporting platform of the Fortinet Security Fabric. It normalizes records arriving primarily from FortiGate firewalls, but also from FortiClient, FortiMail, FortiWeb and third-party sources, into a single data lake; it correlates events, produces the ready-made reports used as evidence in KVKK (Turkey's data protection law) and PCI DSS audits, and automates incident response with built-in SIEM/SOAR capabilities. In short, FortiAnalyzer is the layer that tells you not what your firewall blocked but what happened on your network.

Central logging is no longer a nice-to-have. According to Verizon's 2025 Data Breach Investigations Report, exploitation of vulnerabilities reached 20% as an initial access vector, and edge devices and VPNs made up 22% of those exploitation actions — almost eight times the previous year (Verizon DBIR, 2025). The same report measures that organizations fully remediated only about 54% of edge device vulnerabilities, taking a median of 32 days to do so. If patch delay is unavoidable, the only thing that shortens the time an attacker spends on your network is visibility: being able to answer within minutes who connected, when, to where, and with which identity.

The picture in Europe points in the same direction. ENISA Threat Landscape 2025 examined 4,875 incidents between 1 July 2024 and 30 June 2025; exploitation of vulnerabilities accounted for 21.3% of initial access and phishing for 60% (ENISA Threat Landscape, 2025). What these vectors have in common is that each individual device produces records that look "normal" in isolation. A FortiGate session log, a FortiClient authentication record and a FortiMail delivery log are unremarkable when viewed separately; placed side by side they form an attack chain. Putting them side by side is exactly FortiAnalyzer's reason for existing.

What exactly does FortiAnalyzer do?

FortiAnalyzer does three jobs at once: it accumulates logs, it makes those logs analysable, and it triggers action based on the findings. Fortinet describes this in the official data sheet as "the data lake of the Security Fabric": telemetry from network, endpoint and cloud environments is gathered in one place, enriched with AI/ML-driven analytics, and turned into structured dashboards for IoT, SOC, email and endpoint vulnerabilities (Fortinet FortiAnalyzer Data Sheet, 2026).

The data collection layer: which sources, by which method

FortiAnalyzer does not tie log ingestion to a single protocol. According to the data sheet, syslog, APIs, an alert ingestion service and agent-based forwarding through FortiClient are supported (Fortinet FortiAnalyzer Data Sheet, 2026). In practice this means: your FortiGate firewalls write to the same data lake over a direct Security Fabric connection, your Linux servers over syslog, your SaaS applications over API, and your user endpoints through the FortiClient agent. Role-based access control and data retention policies are also defined at this layer; in other words, which team can see which tenant's logs is controlled within the product.

The analytics and correlation layer: from raw log to incident

A raw log is not audit evidence on its own; it has to be given meaning. FortiAnalyzer runs built-in analytics and correlation across Security Fabric components, merging seemingly unrelated events into a single incident record. FortiGuard Labs integration enriches those records with current threat intelligence; the FortiGuard IOC service provides forensic data with 500,000 indicators of compromise (IOCs) per day, and historical logs can be rescanned against those indicators for threat hunting (Fortinet FortiAnalyzer Data Sheet, 2026). The question "did this IP address also appear on my network three months ago?" only has an answer if your log still exists and has been indexed.

The response layer: XDR and enforcement points

FortiAnalyzer does not only produce reports; it can also issue commands to enforcement points across the Fabric. According to the data sheet, it builds an XDR layer by integrating with FortiEDR, FortiNDR, FortiDeceptor, FortiCNAPP and FortiDLP, while automated response is triggered through points such as FortiGate, FortiManager, FortiMail, FortiEDR endpoint protection and FortiAuthenticator (Fortinet FortiAnalyzer Data Sheet, 2026). When ransomware behaviour is observed on an endpoint, quarantining the device from the network, dropping the relevant user's session and writing a temporary blocking rule on FortiGate can all be sequenced within the same playbook.

What is the difference between FortiAnalyzer and FortiManager?

The shortest distinction is this: FortiManager manages devices, FortiAnalyzer manages the data those devices produce. FortiManager is for configuration, policy distribution and version/revision control; FortiAnalyzer is for log collection, analytics, reporting and incident response. The two are complementary, not competitors. In a multi-branch organization, FortiManager answers "how do I push the same web filtering profile to 120 branches at once?", while FortiAnalyzer answers "which user accessed this server from which device at 02:14 last night?".

Comparison dimensionFortiManagerFortiAnalyzer
Core functionCentral configuration, policy and provisioningCentral log collection, analytics, reporting and incident response
Typical userNetwork/security engineer, operations teamSOC analyst, compliance and internal audit team
Scale statementUp to 100,000 Fortinet devices (FortiGate, FortiSwitch, FortiAP, SD-WAN, FortiSASE)Between 180 and 10,000 devices/VDOMs depending on the model
Data heldConfiguration objects, templates, revision historyTraffic and UTM logs, incident records, IOC matches, forensic data
Contribution to complianceChange records, approval workflow, configuration rollbackLog retention, audit trail, ready-made compliance reports (e.g. PCI-DSS, HIPAA)
Multi-tenancyADOM — between 30 and 10,000 by default depending on the model, licensed maximum 12,000Tenant/unit-level log and report isolation with ADOM
High availabilityHA clusterHA cluster of up to four nodes

The scale figures in the table are taken from official sources: FortiManager's support for 100,000 devices from the product page (Fortinet FortiManager product page, 2026), the ADOM capacities from Appendix B of the 7.6.4 release notes (Fortinet Document Library, 2026), and FortiAnalyzer's device/VDOM and HA values from the data sheet (Fortinet FortiAnalyzer Data Sheet, 2026). In practice what separates the two products is not the purchasing decision but the operating model: you can still manage FortiGates one by one without FortiManager, but without FortiAnalyzer you cannot ask questions about the past. And an audit question is always about the past.

A common misconception in small and mid-sized organizations is that buying FortiManager also solves the logging problem. FortiManager's own log viewing capabilities are operational in purpose; long-term retention, analytical indexing and scheduled compliance reporting are FortiAnalyzer's job. The reverse is also true: FortiAnalyzer does not distribute policy. The right question is not "which one?" but "which one first?" — in a single-site organization FortiAnalyzer usually comes first, while in a multi-branch organization the two are deployed together.

How does FortiAnalyzer address KVKK log retention obligations?

Short answer: KVKK does not impose a named "logging appliance" requirement; however, the technical measures framework published by the Authority expects user transaction activity to be recorded regularly and those records to be monitored. FortiAnalyzer is the technical control that meets this expectation: records collected centrally in tamper-resistant form, protected by role-based access, and reportable at audit time.

Where does logging sit in the KVKK technical measures list?

KVKK's Personal Data Security Guide (Technical and Administrative Measures) states, under the heading of monitoring personal data security, that the software and services running on information networks must be controlled, that intrusions or activity that should not be occurring must be identified, that log records of all user transaction activity must be kept regularly, and that security issues must be reported quickly. In the same guide's summary table of technical measures, "Access Logs", "Log Records", "Network Security", "Intrusion Detection and Prevention Systems" and "Firewalls" are listed as separate items (KVKK, Personal Data Security Guide, January 2018). The guide also defines the firewall and gateway as the "first line of defence" against unauthorized access threats from the internet. FortiGate establishes that first line; FortiAnalyzer retains the evidence that line produces.

Retention is determined by legislation and your retention-and-disposal policy, not by the product

The frequently repeated industry claim that "FortiAnalyzer retains logs for 1 year" is not a product feature. Fortinet's official data sheet gives only the Max Number of Days Analytics value: the number of days reached if the device continuously receives logs at the maximum analytics rate (30, 50 or 60 days depending on the model). If your average log rate is lower, that period extends. Retention is therefore a capacity planning outcome; the correct sentence is framed as "this many days at this volume".

This distinction matters at audit. The KVKK guide does not impose a single retention period; the period is determined by the type of personal data processed, the relevant sector-specific legislation and the organization's personal data retention and disposal policy. The right approach is therefore to clarify the legal requirement first and then size FortiAnalyzer with a disk and archive architecture that meets that period. In practice we build this in two tiers: a hot tier (analytics, indexed, searchable) and an archive tier. On the archive side, FortiAnalyzer's near-real-time log forwarding to another FortiAnalyzer, a syslog server or a CEF server can be used; when forwarding is enabled, the local copy is also retained (Fortinet FortiAnalyzer Data Sheet, 2026).

What changes in the context of PCI DSS, BDDK and Law No. 5651?

For organizations that process card data, PCI DSS v4.0 requires network security control (NSC) configurations to be reviewed at least once every six months (requirement 1.2.7) and, if segmentation is used, segmentation controls to be penetration tested at least once every 12 months and after every change (requirement 11.4.5) (PCI Security Standards Council, PCI DSS v4.0 SAQ D, April 2022). These requirements do not literally say "keep logs", but both demand evidence; the data showing when and by whom a rule change was made, and that the segment really is isolated, lives on the logging side. FortiAnalyzer's ready-made PCI-DSS and HIPAA report templates (Fortinet FortiAnalyzer Data Sheet, 2026) make it easier to produce that evidence in the format the auditor expects.

For financial institutions subject to BDDK (Turkish banking regulator) regulations and for organizations acting as mass-use providers under Turkey's Law No. 5651, internal IP allocation records and access records are expected to be retained in a way that preserves their integrity. Because the scope and periods of these regulations vary from organization to organization, we do not quote a single figure here; the correct period should be determined together with your legal counsel and your auditor, and the technical design should then follow that period. At Sora Yazılım we always carry out the sizing exercise in that order.

Which FortiAnalyzer model suits which log volume?

Model selection is not made by looking at a single number; daily log volume (GB/day), sustained log rate (logs/sec), the number of devices/VDOMs to be connected and the targeted number of analytics days are evaluated together. Fortinet's hardware family scales from 100 GB of logs per day (FAZ-300G) to 8,300 GB per day (FAZ-3750G); the analytics sustained log rate ranges from 2,000 to 100,000 logs/sec (Fortinet FortiAnalyzer Data Sheet, 2026).

ModelDaily log capacityAnalytics sustained rateCollector sustained rateDevices/VDOMs (max.)Usable storage (after RAID)Max. analytics days*
FAZ-300G100 GB/day2,000 logs/sec3,000 logs/sec1804 TB50 days
FAZ-810G200 GB/day4,000 logs/sec6,000 logs/sec8008 TB50 days
FAZ-1000G660 GB/day20,000 logs/sec30,000 logs/sec2,00024 TB60 days
FAZ-3100G3,000 GB/day42,000 logs/sec60,000 logs/sec4,00056 TB30 days
FAZ-3750G8,300 GB/day100,000 logs/sec150,000 logs/sec10,000305 TB60 days

* Fortinet's footnote: the sustained rate is the maximum steady log message rate the platform can maintain for at least 48 hours without degrading the SQL database and system performance. Max. analytics days is the number of days reached if the device receives logs continuously at that rate; if your real average rate is lower, the period extends (Fortinet FortiAnalyzer Data Sheet, 2026). That is why we do not select a model without measuring the real volume: in a typical project we first bring the log settings on the existing FortiGates to the target level, measure several weeks of real production data, and then size with headroom for growth.

When should Analyzer and Collector modes be separated?

FortiAnalyzer offers two operating modes. In Collector mode the device's primary job is to receive the logs of connected devices, archive them and forward them to an Analyzer. A device in Analyzer mode focuses on analytics and report generation. As the log rate rises, offloading the resource-intensive "log ingestion" job to a Collector preserves the Analyzer's reporting and correlation performance (Fortinet FortiAnalyzer Data Sheet, 2026). The fact that the Collector sustained rates in the table exceed the Analyzer rates (by roughly 1.4–1.5 times depending on the model) is the hardware-side reflection of that division of labour.

Geographic distribution is also solved with this model: placing a Collector in each region and carrying only the necessary data to the central site over the WAN makes it easier to manage both circuit cost and data locality constraints. In large organizations with many FortiAnalyzers, FortiAnalyzer Fabric comes into play: with Supervisor and Member modes, the ADOMs, authorized logging devices, incident and alert records of member devices are viewed from a single point, and global search across all members can be performed from Log View (Fortinet FortiAnalyzer Data Sheet, 2026).

Does FortiAnalyzer replace a SIEM?

Partly. FortiAnalyzer includes built-in SIEM and SOAR capabilities and, in Fortinet's own words, is designed "to complement and work alongside whatever SIEM or logging solution the customer uses" (Fortinet FortiAnalyzer Data Sheet, 2026). In organizations weighted towards the Fortinet ecosystem, with limited third-party log sources, FortiAnalyzer is sufficient on its own. Conversely, if you need deep correlation of Windows event logs, databases, ERP, network devices from many different vendors and custom application logs, a full-scope SIEM — FortiSIEM within the Fortinet family — is a better fit.

It is worth speaking without exaggeration here: according to the positions Fortinet lists on its own Gartner Magic Quadrant page, the company was positioned as a Challenger in the 2025 Gartner Magic Quadrant for Security Information and Event Management, not a Leader (Fortinet, Gartner Magic Quadrants page, 2026). On the same page, the category in which Fortinet is a Leader is the 2025 Hybrid Mesh Firewall Magic Quadrant. So it would not be correct to position FortiAnalyzer as "the best SIEM on the market"; the correct positioning is that it is a security operations platform with low deployment and operating cost that delivers value quickly in a Fortinet-heavy environment. Indeed, the Security Fabric's integration ecosystem covering more than 500 third-party solutions is built on exactly this complementarity (Fortinet, About Us, 2026).

The practical criterion when deciding is this: if the vast majority of your log sources are Fortinet and your team is small, start with FortiAnalyzer. If source diversity is high and regulation demands a vendor-independent SIEM, position FortiAnalyzer as the collector and pre-processor for the Fortinet side and send only enriched events to the SIEM. This second pattern delivers significant savings in environments where SIEM licence cost rises in direct proportion to raw log volume.

What can a SOC team automate with FortiAnalyzer?

Short answer: most of the chain from alert generation to first response. FortiAnalyzer manages the incident lifecycle in a single console, from alert monitoring and prioritization through to deep investigation and response; built-in correlation, indicator enrichment and user, asset and identity tracking speed up the analyst's work (Fortinet FortiAnalyzer Data Sheet, 2026). In practice the four areas that deliver the most value are these:

  • Monthly SOC automation content packs. FortiGuard Labs publishes ready-made use cases every month: log parsers, reports, correlation rules, event handlers and automated playbooks. This makes it possible to onboard a new log source and detect new threats without writing rules by hand.
  • FortiGuard IOC and Outbreak Detection services. Forensic data fed by 500,000 IOCs per day allows historical logs to be rescanned; the outbreak package brings the related report, event handler and report template together.
  • Playbook-based response. Alert handling, ticketing and notification flows can be automated; response is triggered through enforcement points such as FortiGate, FortiMail, FortiEDR and FortiAuthenticator.
  • Generative AI assistant (FortiAI). Analysts can write queries in natural language, have incidents summarized and generate complex database queries without knowing the query language. This feature is offered under a separate FortiAI subscription.

The volume of intelligence behind this automation is not to be underestimated either: FortiGuard Labs processes and analyses more than 100 billion events per day with artificial intelligence and machine learning systems (Fortinet, About Us, 2026). When this context — which an organization could never produce on its own — is attached to every alert in FortiAnalyzer, the time an analyst spends on the question "is this real?" shrinks. The most expensive resource of a small team is analyst minutes; that is also where the return on automation is measured.

In addition, the OT Security Service (advanced OT analytics for industrial environments, risk and compliance reports, event handlers), the Attack Surface Security Rating and Compliance Service (security posture scoring and configuration recommendations), the FortiGuard Threat Intel Platform service and 7x24 SOCaaS monitoring/management can be added as subscriptions (Fortinet FortiAnalyzer Data Sheet, 2026). We determine together which subscriptions are genuinely necessary by looking at your team size and shift model — an unused subscription is nothing but unnecessary cost at renewal time.

How do you choose between hardware, virtual machine and cloud?

All three options run the same software; the difference lies in deployment, scaling and data locality. Fortinet offers FortiAnalyzer as a physical appliance, as a virtual appliance for private/public cloud, and as a hosted solution (Fortinet FortiAnalyzer Data Sheet, 2026). In Turkey, organizations with data locality sensitivities arising from KVKK generally lean towards on-premise hardware or a virtual machine in their own data centre.

OptionWhen it fitsWhat to watch for
Hardware appliance (FAZ-300G – FAZ-3750G)High log volume, long retention, data centre placementStorage is sized up front; headroom for growth must be left
FortiAnalyzer-VM (FAZ-VM-GB1 – GB2000)Virtualized data centre, incremental growth, DR scenariosMinimum 4 vCPUs and 16 GB memory; 1–12 virtual interfaces; maximum 10,000 devices/VDOMs
FortiAnalyzer Cloud (PaaS)Environments that prefer not to operate hardware, focused on FortiGate/SD-WANLogs are held in the Fortinet cloud; data locality requirements must be assessed in advance

In the virtual edition, licensing works incrementally on a GB/day basis: capacity increment licences from FAZ-VM-GB1 up to FAZ-VM-GB2000 can be stacked on top of one another, and VM subscription SKUs can be stacked in steps of 5, 50 and 500 GB/day. When deployed in Collector mode, no GB/day limit applies to the VM (Fortinet FortiAnalyzer Data Sheet, 2026). This is a practical detail that enables a "collect first, decide how much to analyse later" approach, and a pattern we use frequently in budget-constrained organizations.

On the resilience side, FortiAnalyzer HA allows a secondary device to take over when the primary fails, and clusters of up to four nodes are supported (Fortinet FortiAnalyzer Data Sheet, 2026). There is also a Backup to Cloud service for disaster recovery; this subscription covers backing up logs to the public cloud with 10 TB of annual data transfer. Ensuring that the logging infrastructure itself is not a single point of failure matters for audit as well: an auditor takes the finding "your logging appliance was down for two weeks" as seriously as missing records.

FortiAnalyzer should be planned not in isolation but as part of the whole Fortinet Security Fabric. When a data centre firewall at the edge such as a FortiGate 1000F, FortiMail email security, the FortiWeb web application firewall and FortiSASE for remote users all write to the same data lake, you obtain a single event chain stretching from the user to the application. The problem we most often encounter in piecemeal deployments is that the logs exist but cannot be connected to one another.

As a Fortinet authorized channel partner in Turkey, Sora Yazılım provides licensing, sizing, deployment, migration from an existing logging infrastructure and managed services on FortiAnalyzer projects. A typical engagement proceeds as follows: measuring the real log volume, clarifying the legal retention requirement, model and storage sizing, ADOM/role design, adapting the compliance report templates to your organization, and putting SOC playbooks into service. Preparation on the server, virtualization and backup side is carried out within the scope of our DevOps and infrastructure services; for organizations that want to build custom analytics or an assistant on top of log data, we provide support through our artificial intelligence and LLM services.

Let's determine the right FortiAnalyzer model together. Share how many FortiGates you have, your approximate daily log volume and your target retention period, and we will produce the sizing exercise and the deployment plan. Because pricing varies with capacity and the subscription set, we do not publish a standard list — for a quotation tailored to your organization, reach us through our contact page. If you already have a FortiAnalyzer, we can also plan a health check that reviews your retention, report and playbook configuration; you can send that request through the contact form as well.

Key features

What it offers

  • Unified log and telemetry data lake across the Security Fabric
  • Multi-source collection via syslog, API, alert ingestion and the FortiClient agent
  • Built-in SIEM and SOAR: correlation, event handlers and playbook automation
  • Forensic analysis over 500,000 indicators of compromise per day with the FortiGuard IOC service
  • Monthly SOC automation content packs from FortiGuard Labs
  • Ready-made compliance reports (PCI-DSS, HIPAA) and customizable dashboards
  • Natural-language queries and incident summaries with the FortiAI generative AI assistant
  • XDR correlation with FortiEDR, FortiNDR, FortiDeceptor, FortiCNAPP and FortiDLP
  • Automated response through FortiGate, FortiMail, FortiEDR and FortiAuthenticator
  • Division of labour at high log rates with Analyzer and Collector modes
  • FortiAnalyzer Fabric: Supervisor/Member architecture and global search across members
  • Multi-tenant log and report isolation with ADOM (MSP and holding structures)
  • Near-real-time log forwarding to syslog/CEF and to a second FortiAnalyzer
  • HA cluster of up to four nodes and disaster recovery with Backup to Cloud
Tech Summary

Important technical data

Hardware models
FAZ-300G, FAZ-810G, FAZ-1000G, FAZ-3100G, FAZ-3750G
Daily log capacity
100 GB/day (FAZ-300G) – 8,300 GB/day (FAZ-3750G)
Analytics sustained log rate
2,000 – 100,000 logs/sec (depending on the model)
Collector sustained log rate
3,000 – 150,000 logs/sec (depending on the model)
Supported devices/VDOMs
180 – 10,000 (depending on the model)
Usable storage (after RAID)
4 TB (FAZ-300G) – 305 TB (FAZ-3750G)
Maximum analytics days
30 / 50 / 60 days depending on the model (at the sustained maximum analytics rate)
Form factor
1 RU (300G, 810G), 2 RU (1000G), 3 RU (3100G), 4 RU (3750G) rack
Virtual edition
FAZ-VM-GB1 → FAZ-VM-GB2000; minimum 4 vCPUs / 16 GB memory, 1–12 virtual interfaces
Virtual edition scale
Maximum 10,000 devices/VDOMs; no GB/day limit in Collector mode
Operating modes
Analyzer / Collector; FortiAnalyzer Fabric Supervisor / Member
High availability
Active-passive HA cluster of up to four nodes
Log forwarding
Syslog, CEF or another FortiAnalyzer (the local copy is retained)
Cloud
FortiAnalyzer Cloud (PaaS); Backup to Cloud service with 10 TB of annual data transfer
Subscription services
IOC & Outbreak Detection, SOC Automation, OT Security, Security Rating & Compliance, FortiGuard TIP, FortiAI, SOCaaS
Use Cases

When would you choose this product?

Finance

Audit-ready central logging architecture

In a multi-branch financial institution, the traffic and UTM logs of all FortiGates are collected on a central FortiAnalyzer; ready-made PCI-DSS report templates are produced on a schedule and the archive tier is forwarded to a separate destination. Retention is sized according to the organization's retention and disposal policy.

Public sector and healthcare

Demonstrating KVKK technical measures

Organizations that process personal data are expected to keep regular log records of user transaction activity and to protect access logs. FortiAnalyzer centralizes those records with role-based access; the access and incident reports requested during an audit are produced from ready-made templates.

Managed service provider (MSP)

Multi-tenant isolation with ADOM

On a single FortiAnalyzer, each customer is held in its own ADOM; logs and reports are isolated per tenant. In estates with many FortiAnalyzers, FortiAnalyzer Fabric Supervisor mode provides single-point visibility across members.

Manufacturing and OT

Bringing IT and OT logs together in one dashboard

Records from segments on the production floor are collected in the same data lake as the office network. The OT Security Service subscription adds advanced OT analytics, risk and compliance reports and use-case correlation rules; abnormal field traffic is escalated as an incident.

Retail and distributed branches

Regional log collection with Collector

In estates with hundreds of branches, a FortiAnalyzer in Collector mode is placed in each region; the resource-intensive log ingestion job is separated from the centre and the Analyzer focuses solely on analytics and reporting. The volume of data carried over the WAN is also brought under control this way.

Who is it for?

Network, security and internal audit teams in organizations that operate more than one Fortinet device and are subject to KVKK, PCI DSS, ISO 27001 or sector-specific audits, together with service providers managing multi-tenant estates.

Frequently Asked Questions

Frequently asked questions

What is the difference between FortiAnalyzer and FortiManager?
FortiManager is for configuration and policy management; it allows the same policy to be distributed to hundreds of devices and keeps revision history. FortiAnalyzer is for log collection, analytics, reporting and incident response. One distributes the policy, the other measures what that policy produces in the field. In mid-sized and large organizations the two are positioned together.
Is FortiAnalyzer mandatory for KVKK?
KVKK does not impose a named product requirement. However, the Authority's Personal Data Security Guide lists keeping regular log records of user transaction activity, protecting access logs and reporting security issues quickly among the technical measures. FortiAnalyzer is the technical control that meets these measures; in environments operating more than one Fortinet device it is the most direct way to centralize those records.
How many years does FortiAnalyzer retain logs?
There is no fixed number of years, and the statement "it retains logs for 1 year" is not a product feature. The Fortinet data sheet gives only the maximum number of analytics days: 30, 50 or 60 days depending on the model, if the device continuously receives logs at the maximum analytics rate. If your real average rate is lower, the period extends. The right approach is to determine your legal retention requirement and size the disk and archive tier accordingly.
Which FortiAnalyzer model should I choose?
Daily log volume, log rate and device count are the deciding factors. The hardware family starts with the FAZ-300G at 100 GB/day and 180 devices/VDOMs and reaches 8,300 GB/day, 100,000 logs/sec and 10,000 devices/VDOMs with the FAZ-3750G. We recommend measuring several weeks of real log production in the existing environment before choosing a model.
What is the difference between Analyzer and Collector mode?
The primary job of a device in Collector mode is to receive the logs of connected devices, archive them and forward them to an Analyzer. A device in Analyzer mode produces analytics and reports. As the log rate rises, offloading the resource-intensive log ingestion job to a Collector preserves Analyzer performance; according to the data sheet values, on the same hardware the Collector sustained rate is roughly 1.4–1.5 times the Analyzer rate.
Does FortiAnalyzer replace a SIEM?
In Fortinet-heavy environments, largely yes: it has built-in SIEM and SOAR capabilities, and Fortinet states that the product is designed to work alongside existing SIEM solutions. If you need log sources from many different vendors and deep correlation, a full-scope SIEM such as FortiSIEM is a better fit. Fortinet was positioned as a Challenger in the 2025 Gartner SIEM Magic Quadrant, not a Leader.
What is the difference between FortiAnalyzer Cloud and on-premise?
The same software, a different deployment model. The Cloud edition is offered as PaaS, removes the need to operate hardware and is accessed with FortiCloud single sign-on. On-premise hardware or a virtual machine keeps the log within the organization's boundaries. In Turkish projects with data locality sensitivities, the preference generally tends towards on-premise.
Does FortiAnalyzer run as a virtual machine?
Yes. FortiAnalyzer-VM is offered with incremental GB/day-based licences (from FAZ-VM-GB1 to GB2000) and requires a minimum of 4 vCPUs and 16 GB of memory; 1 to 12 virtual interfaces are supported and a maximum of 10,000 devices/VDOMs can be connected. When deployed in Collector mode, no GB/day limit applies. The list of supported hypervisors is published in the relevant release notes.
What is an ADOM and why does it matter?
An ADOM (Administrative Domain) is the structure that isolates logs and reports per tenant, unit or customer. It is critical for managed service providers and multi-company holdings: one tenant's records do not appear in another's dashboard, and authorization is applied at the ADOM boundary.
If FortiAnalyzer fails, are the logs lost?
In a correct design, no. FortiAnalyzer HA allows the secondary device to take over when the primary fails, and clusters of up to four nodes are supported. Logs can also be forwarded to another FortiAnalyzer, a syslog server or a CEF server; the local copy is retained during forwarding. Backing up to the public cloud is also possible with the Backup to Cloud service.
Can it also collect logs from third-party products?
Yes. Non-Fortinet sources can also be brought into the data lake through syslog, APIs and the alert ingestion service; FortiGuard Labs' monthly content packs deliver ready-made parsers for new log sources. Even so, in scenarios that require deep multi-vendor correlation we recommend considering whether to position it alongside a full-scope SIEM.
What is the price of FortiAnalyzer?
The price varies with the selected hardware or virtual licence capacity, the GB/day volume, the disk required for retention and the subscription services added. For that reason we do not publish list prices. Share your device count, estimated daily log volume and target retention period, and we will prepare sizing and a quotation tailored to your organization.
Vendor's official product page

Opens the vendor's original technical documentation and product page in a new tab.

FortinetFortiAnalyzer
Related Services

Services we deliver alongside this product

FortiAnalyzer licensing + deployment + support

Sora Yazılım handles licensing, deployment, training and ongoing management — all from a single team.

WhatsApp Support