FortiAnalyzer is the central log collection, retention, analytics and reporting platform of the Fortinet Security Fabric. It normalizes records arriving primarily from FortiGate firewalls, but also from FortiClient, FortiMail, FortiWeb and third-party sources, into a single data lake; it correlates events, produces the ready-made reports used as evidence in KVKK (Turkey's data protection law) and PCI DSS audits, and automates incident response with built-in SIEM/SOAR capabilities. In short, FortiAnalyzer is the layer that tells you not what your firewall blocked but what happened on your network.
Central logging is no longer a nice-to-have. According to Verizon's 2025 Data Breach Investigations Report, exploitation of vulnerabilities reached 20% as an initial access vector, and edge devices and VPNs made up 22% of those exploitation actions — almost eight times the previous year (Verizon DBIR, 2025). The same report measures that organizations fully remediated only about 54% of edge device vulnerabilities, taking a median of 32 days to do so. If patch delay is unavoidable, the only thing that shortens the time an attacker spends on your network is visibility: being able to answer within minutes who connected, when, to where, and with which identity.
The picture in Europe points in the same direction. ENISA Threat Landscape 2025 examined 4,875 incidents between 1 July 2024 and 30 June 2025; exploitation of vulnerabilities accounted for 21.3% of initial access and phishing for 60% (ENISA Threat Landscape, 2025). What these vectors have in common is that each individual device produces records that look "normal" in isolation. A FortiGate session log, a FortiClient authentication record and a FortiMail delivery log are unremarkable when viewed separately; placed side by side they form an attack chain. Putting them side by side is exactly FortiAnalyzer's reason for existing.
What exactly does FortiAnalyzer do?
FortiAnalyzer does three jobs at once: it accumulates logs, it makes those logs analysable, and it triggers action based on the findings. Fortinet describes this in the official data sheet as "the data lake of the Security Fabric": telemetry from network, endpoint and cloud environments is gathered in one place, enriched with AI/ML-driven analytics, and turned into structured dashboards for IoT, SOC, email and endpoint vulnerabilities (Fortinet FortiAnalyzer Data Sheet, 2026).
The data collection layer: which sources, by which method
FortiAnalyzer does not tie log ingestion to a single protocol. According to the data sheet, syslog, APIs, an alert ingestion service and agent-based forwarding through FortiClient are supported (Fortinet FortiAnalyzer Data Sheet, 2026). In practice this means: your FortiGate firewalls write to the same data lake over a direct Security Fabric connection, your Linux servers over syslog, your SaaS applications over API, and your user endpoints through the FortiClient agent. Role-based access control and data retention policies are also defined at this layer; in other words, which team can see which tenant's logs is controlled within the product.
The analytics and correlation layer: from raw log to incident
A raw log is not audit evidence on its own; it has to be given meaning. FortiAnalyzer runs built-in analytics and correlation across Security Fabric components, merging seemingly unrelated events into a single incident record. FortiGuard Labs integration enriches those records with current threat intelligence; the FortiGuard IOC service provides forensic data with 500,000 indicators of compromise (IOCs) per day, and historical logs can be rescanned against those indicators for threat hunting (Fortinet FortiAnalyzer Data Sheet, 2026). The question "did this IP address also appear on my network three months ago?" only has an answer if your log still exists and has been indexed.
The response layer: XDR and enforcement points
FortiAnalyzer does not only produce reports; it can also issue commands to enforcement points across the Fabric. According to the data sheet, it builds an XDR layer by integrating with FortiEDR, FortiNDR, FortiDeceptor, FortiCNAPP and FortiDLP, while automated response is triggered through points such as FortiGate, FortiManager, FortiMail, FortiEDR endpoint protection and FortiAuthenticator (Fortinet FortiAnalyzer Data Sheet, 2026). When ransomware behaviour is observed on an endpoint, quarantining the device from the network, dropping the relevant user's session and writing a temporary blocking rule on FortiGate can all be sequenced within the same playbook.
What is the difference between FortiAnalyzer and FortiManager?
The shortest distinction is this: FortiManager manages devices, FortiAnalyzer manages the data those devices produce. FortiManager is for configuration, policy distribution and version/revision control; FortiAnalyzer is for log collection, analytics, reporting and incident response. The two are complementary, not competitors. In a multi-branch organization, FortiManager answers "how do I push the same web filtering profile to 120 branches at once?", while FortiAnalyzer answers "which user accessed this server from which device at 02:14 last night?".
| Comparison dimension | FortiManager | FortiAnalyzer |
|---|
| Core function | Central configuration, policy and provisioning | Central log collection, analytics, reporting and incident response |
| Typical user | Network/security engineer, operations team | SOC analyst, compliance and internal audit team |
| Scale statement | Up to 100,000 Fortinet devices (FortiGate, FortiSwitch, FortiAP, SD-WAN, FortiSASE) | Between 180 and 10,000 devices/VDOMs depending on the model |
| Data held | Configuration objects, templates, revision history | Traffic and UTM logs, incident records, IOC matches, forensic data |
| Contribution to compliance | Change records, approval workflow, configuration rollback | Log retention, audit trail, ready-made compliance reports (e.g. PCI-DSS, HIPAA) |
| Multi-tenancy | ADOM — between 30 and 10,000 by default depending on the model, licensed maximum 12,000 | Tenant/unit-level log and report isolation with ADOM |
| High availability | HA cluster | HA cluster of up to four nodes |
The scale figures in the table are taken from official sources: FortiManager's support for 100,000 devices from the product page (Fortinet FortiManager product page, 2026), the ADOM capacities from Appendix B of the 7.6.4 release notes (Fortinet Document Library, 2026), and FortiAnalyzer's device/VDOM and HA values from the data sheet (Fortinet FortiAnalyzer Data Sheet, 2026). In practice what separates the two products is not the purchasing decision but the operating model: you can still manage FortiGates one by one without FortiManager, but without FortiAnalyzer you cannot ask questions about the past. And an audit question is always about the past.
A common misconception in small and mid-sized organizations is that buying FortiManager also solves the logging problem. FortiManager's own log viewing capabilities are operational in purpose; long-term retention, analytical indexing and scheduled compliance reporting are FortiAnalyzer's job. The reverse is also true: FortiAnalyzer does not distribute policy. The right question is not "which one?" but "which one first?" — in a single-site organization FortiAnalyzer usually comes first, while in a multi-branch organization the two are deployed together.
How does FortiAnalyzer address KVKK log retention obligations?
Short answer: KVKK does not impose a named "logging appliance" requirement; however, the technical measures framework published by the Authority expects user transaction activity to be recorded regularly and those records to be monitored. FortiAnalyzer is the technical control that meets this expectation: records collected centrally in tamper-resistant form, protected by role-based access, and reportable at audit time.
Where does logging sit in the KVKK technical measures list?
KVKK's Personal Data Security Guide (Technical and Administrative Measures) states, under the heading of monitoring personal data security, that the software and services running on information networks must be controlled, that intrusions or activity that should not be occurring must be identified, that log records of all user transaction activity must be kept regularly, and that security issues must be reported quickly. In the same guide's summary table of technical measures, "Access Logs", "Log Records", "Network Security", "Intrusion Detection and Prevention Systems" and "Firewalls" are listed as separate items (KVKK, Personal Data Security Guide, January 2018). The guide also defines the firewall and gateway as the "first line of defence" against unauthorized access threats from the internet. FortiGate establishes that first line; FortiAnalyzer retains the evidence that line produces.
Retention is determined by legislation and your retention-and-disposal policy, not by the product
The frequently repeated industry claim that "FortiAnalyzer retains logs for 1 year" is not a product feature. Fortinet's official data sheet gives only the Max Number of Days Analytics value: the number of days reached if the device continuously receives logs at the maximum analytics rate (30, 50 or 60 days depending on the model). If your average log rate is lower, that period extends. Retention is therefore a capacity planning outcome; the correct sentence is framed as "this many days at this volume".
This distinction matters at audit. The KVKK guide does not impose a single retention period; the period is determined by the type of personal data processed, the relevant sector-specific legislation and the organization's personal data retention and disposal policy. The right approach is therefore to clarify the legal requirement first and then size FortiAnalyzer with a disk and archive architecture that meets that period. In practice we build this in two tiers: a hot tier (analytics, indexed, searchable) and an archive tier. On the archive side, FortiAnalyzer's near-real-time log forwarding to another FortiAnalyzer, a syslog server or a CEF server can be used; when forwarding is enabled, the local copy is also retained (Fortinet FortiAnalyzer Data Sheet, 2026).
What changes in the context of PCI DSS, BDDK and Law No. 5651?
For organizations that process card data, PCI DSS v4.0 requires network security control (NSC) configurations to be reviewed at least once every six months (requirement 1.2.7) and, if segmentation is used, segmentation controls to be penetration tested at least once every 12 months and after every change (requirement 11.4.5) (PCI Security Standards Council, PCI DSS v4.0 SAQ D, April 2022). These requirements do not literally say "keep logs", but both demand evidence; the data showing when and by whom a rule change was made, and that the segment really is isolated, lives on the logging side. FortiAnalyzer's ready-made PCI-DSS and HIPAA report templates (Fortinet FortiAnalyzer Data Sheet, 2026) make it easier to produce that evidence in the format the auditor expects.
For financial institutions subject to BDDK (Turkish banking regulator) regulations and for organizations acting as mass-use providers under Turkey's Law No. 5651, internal IP allocation records and access records are expected to be retained in a way that preserves their integrity. Because the scope and periods of these regulations vary from organization to organization, we do not quote a single figure here; the correct period should be determined together with your legal counsel and your auditor, and the technical design should then follow that period. At Sora Yazılım we always carry out the sizing exercise in that order.
Which FortiAnalyzer model suits which log volume?
Model selection is not made by looking at a single number; daily log volume (GB/day), sustained log rate (logs/sec), the number of devices/VDOMs to be connected and the targeted number of analytics days are evaluated together. Fortinet's hardware family scales from 100 GB of logs per day (FAZ-300G) to 8,300 GB per day (FAZ-3750G); the analytics sustained log rate ranges from 2,000 to 100,000 logs/sec (Fortinet FortiAnalyzer Data Sheet, 2026).
| Model | Daily log capacity | Analytics sustained rate | Collector sustained rate | Devices/VDOMs (max.) | Usable storage (after RAID) | Max. analytics days* |
|---|
| FAZ-300G | 100 GB/day | 2,000 logs/sec | 3,000 logs/sec | 180 | 4 TB | 50 days |
| FAZ-810G | 200 GB/day | 4,000 logs/sec | 6,000 logs/sec | 800 | 8 TB | 50 days |
| FAZ-1000G | 660 GB/day | 20,000 logs/sec | 30,000 logs/sec | 2,000 | 24 TB | 60 days |
| FAZ-3100G | 3,000 GB/day | 42,000 logs/sec | 60,000 logs/sec | 4,000 | 56 TB | 30 days |
| FAZ-3750G | 8,300 GB/day | 100,000 logs/sec | 150,000 logs/sec | 10,000 | 305 TB | 60 days |
* Fortinet's footnote: the sustained rate is the maximum steady log message rate the platform can maintain for at least 48 hours without degrading the SQL database and system performance. Max. analytics days is the number of days reached if the device receives logs continuously at that rate; if your real average rate is lower, the period extends (Fortinet FortiAnalyzer Data Sheet, 2026). That is why we do not select a model without measuring the real volume: in a typical project we first bring the log settings on the existing FortiGates to the target level, measure several weeks of real production data, and then size with headroom for growth.
When should Analyzer and Collector modes be separated?
FortiAnalyzer offers two operating modes. In Collector mode the device's primary job is to receive the logs of connected devices, archive them and forward them to an Analyzer. A device in Analyzer mode focuses on analytics and report generation. As the log rate rises, offloading the resource-intensive "log ingestion" job to a Collector preserves the Analyzer's reporting and correlation performance (Fortinet FortiAnalyzer Data Sheet, 2026). The fact that the Collector sustained rates in the table exceed the Analyzer rates (by roughly 1.4–1.5 times depending on the model) is the hardware-side reflection of that division of labour.
Geographic distribution is also solved with this model: placing a Collector in each region and carrying only the necessary data to the central site over the WAN makes it easier to manage both circuit cost and data locality constraints. In large organizations with many FortiAnalyzers, FortiAnalyzer Fabric comes into play: with Supervisor and Member modes, the ADOMs, authorized logging devices, incident and alert records of member devices are viewed from a single point, and global search across all members can be performed from Log View (Fortinet FortiAnalyzer Data Sheet, 2026).
Does FortiAnalyzer replace a SIEM?
Partly. FortiAnalyzer includes built-in SIEM and SOAR capabilities and, in Fortinet's own words, is designed "to complement and work alongside whatever SIEM or logging solution the customer uses" (Fortinet FortiAnalyzer Data Sheet, 2026). In organizations weighted towards the Fortinet ecosystem, with limited third-party log sources, FortiAnalyzer is sufficient on its own. Conversely, if you need deep correlation of Windows event logs, databases, ERP, network devices from many different vendors and custom application logs, a full-scope SIEM — FortiSIEM within the Fortinet family — is a better fit.
It is worth speaking without exaggeration here: according to the positions Fortinet lists on its own Gartner Magic Quadrant page, the company was positioned as a Challenger in the 2025 Gartner Magic Quadrant for Security Information and Event Management, not a Leader (Fortinet, Gartner Magic Quadrants page, 2026). On the same page, the category in which Fortinet is a Leader is the 2025 Hybrid Mesh Firewall Magic Quadrant. So it would not be correct to position FortiAnalyzer as "the best SIEM on the market"; the correct positioning is that it is a security operations platform with low deployment and operating cost that delivers value quickly in a Fortinet-heavy environment. Indeed, the Security Fabric's integration ecosystem covering more than 500 third-party solutions is built on exactly this complementarity (Fortinet, About Us, 2026).
The practical criterion when deciding is this: if the vast majority of your log sources are Fortinet and your team is small, start with FortiAnalyzer. If source diversity is high and regulation demands a vendor-independent SIEM, position FortiAnalyzer as the collector and pre-processor for the Fortinet side and send only enriched events to the SIEM. This second pattern delivers significant savings in environments where SIEM licence cost rises in direct proportion to raw log volume.
What can a SOC team automate with FortiAnalyzer?
Short answer: most of the chain from alert generation to first response. FortiAnalyzer manages the incident lifecycle in a single console, from alert monitoring and prioritization through to deep investigation and response; built-in correlation, indicator enrichment and user, asset and identity tracking speed up the analyst's work (Fortinet FortiAnalyzer Data Sheet, 2026). In practice the four areas that deliver the most value are these:
- Monthly SOC automation content packs. FortiGuard Labs publishes ready-made use cases every month: log parsers, reports, correlation rules, event handlers and automated playbooks. This makes it possible to onboard a new log source and detect new threats without writing rules by hand.
- FortiGuard IOC and Outbreak Detection services. Forensic data fed by 500,000 IOCs per day allows historical logs to be rescanned; the outbreak package brings the related report, event handler and report template together.
- Playbook-based response. Alert handling, ticketing and notification flows can be automated; response is triggered through enforcement points such as FortiGate, FortiMail, FortiEDR and FortiAuthenticator.
- Generative AI assistant (FortiAI). Analysts can write queries in natural language, have incidents summarized and generate complex database queries without knowing the query language. This feature is offered under a separate FortiAI subscription.
The volume of intelligence behind this automation is not to be underestimated either: FortiGuard Labs processes and analyses more than 100 billion events per day with artificial intelligence and machine learning systems (Fortinet, About Us, 2026). When this context — which an organization could never produce on its own — is attached to every alert in FortiAnalyzer, the time an analyst spends on the question "is this real?" shrinks. The most expensive resource of a small team is analyst minutes; that is also where the return on automation is measured.
In addition, the OT Security Service (advanced OT analytics for industrial environments, risk and compliance reports, event handlers), the Attack Surface Security Rating and Compliance Service (security posture scoring and configuration recommendations), the FortiGuard Threat Intel Platform service and 7x24 SOCaaS monitoring/management can be added as subscriptions (Fortinet FortiAnalyzer Data Sheet, 2026). We determine together which subscriptions are genuinely necessary by looking at your team size and shift model — an unused subscription is nothing but unnecessary cost at renewal time.
How do you choose between hardware, virtual machine and cloud?
All three options run the same software; the difference lies in deployment, scaling and data locality. Fortinet offers FortiAnalyzer as a physical appliance, as a virtual appliance for private/public cloud, and as a hosted solution (Fortinet FortiAnalyzer Data Sheet, 2026). In Turkey, organizations with data locality sensitivities arising from KVKK generally lean towards on-premise hardware or a virtual machine in their own data centre.
| Option | When it fits | What to watch for |
|---|
| Hardware appliance (FAZ-300G – FAZ-3750G) | High log volume, long retention, data centre placement | Storage is sized up front; headroom for growth must be left |
| FortiAnalyzer-VM (FAZ-VM-GB1 – GB2000) | Virtualized data centre, incremental growth, DR scenarios | Minimum 4 vCPUs and 16 GB memory; 1–12 virtual interfaces; maximum 10,000 devices/VDOMs |
| FortiAnalyzer Cloud (PaaS) | Environments that prefer not to operate hardware, focused on FortiGate/SD-WAN | Logs are held in the Fortinet cloud; data locality requirements must be assessed in advance |
In the virtual edition, licensing works incrementally on a GB/day basis: capacity increment licences from FAZ-VM-GB1 up to FAZ-VM-GB2000 can be stacked on top of one another, and VM subscription SKUs can be stacked in steps of 5, 50 and 500 GB/day. When deployed in Collector mode, no GB/day limit applies to the VM (Fortinet FortiAnalyzer Data Sheet, 2026). This is a practical detail that enables a "collect first, decide how much to analyse later" approach, and a pattern we use frequently in budget-constrained organizations.
On the resilience side, FortiAnalyzer HA allows a secondary device to take over when the primary fails, and clusters of up to four nodes are supported (Fortinet FortiAnalyzer Data Sheet, 2026). There is also a Backup to Cloud service for disaster recovery; this subscription covers backing up logs to the public cloud with 10 TB of annual data transfer. Ensuring that the logging infrastructure itself is not a single point of failure matters for audit as well: an auditor takes the finding "your logging appliance was down for two weeks" as seriously as missing records.
FortiAnalyzer should be planned not in isolation but as part of the whole Fortinet Security Fabric. When a data centre firewall at the edge such as a FortiGate 1000F, FortiMail email security, the FortiWeb web application firewall and FortiSASE for remote users all write to the same data lake, you obtain a single event chain stretching from the user to the application. The problem we most often encounter in piecemeal deployments is that the logs exist but cannot be connected to one another.
As a Fortinet authorized channel partner in Turkey, Sora Yazılım provides licensing, sizing, deployment, migration from an existing logging infrastructure and managed services on FortiAnalyzer projects. A typical engagement proceeds as follows: measuring the real log volume, clarifying the legal retention requirement, model and storage sizing, ADOM/role design, adapting the compliance report templates to your organization, and putting SOC playbooks into service. Preparation on the server, virtualization and backup side is carried out within the scope of our DevOps and infrastructure services; for organizations that want to build custom analytics or an assistant on top of log data, we provide support through our artificial intelligence and LLM services.
Let's determine the right FortiAnalyzer model together. Share how many FortiGates you have, your approximate daily log volume and your target retention period, and we will produce the sizing exercise and the deployment plan. Because pricing varies with capacity and the subscription set, we do not publish a standard list — for a quotation tailored to your organization, reach us through our contact page. If you already have a FortiAnalyzer, we can also plan a health check that reviews your retention, report and playbook configuration; you can send that request through the contact form as well.