Overview

Product video
FortiAnalyzer enhances security operations by integrating threat intelligence, AI-driven assistance, and security automation into a unified framework for IT and OT systems. Its lightweight deployment enables organizations to transform raw data into actionable insights, streamlining operations and improving both historical and real-time analysis capabilities. By centralizing Security Fabric configurations, events, and alerts, FortiAnalyzer simplifies operations while providing advanced threat visualization through intuitive dashboards and detailed threat topologies.
With its seamless integration of FortiAI, FortiAnalyzer leverages generative AI to deliver context-aware threat management, offering AI-recommended practices and preconfigured automation packs, including playbooks and premium reports. These tools help SecOps teams prioritize strategic tasks and accelerate threat response.
The FortiAnalyzer Attack Surface Security Rating Service continuously evaluates an organizations security posture in real-time, monitoring unpatched vulnerabilities and critical settings while providing actionable insights. This service empowers decision-making by offering security posture scores, Fabric coverage analysis, and optimization recommendations, ensuring a comprehensive approach to enhancing security architecture. FortiAnalyzer ultimately improves operational efficiency and strengthens an organizations overall security strategy.
This product supports the flexibility of scaling the underlying instance up or down to achieve the desired feature capacity to match your requirements. The following information is an example of how to size your cloud instance to support a logging rate of 2GB/DAY with a recommended disk space to store 6 months of logs and then increase from 2GB/DAY to 100GB/Day.
Select an instance size with 8vCPU to support a 2GB/DAY logging rate and is configured with 360GB of storage space.
To increase the logging rate to 100GB/Day, shut down the existing instance, select and apply an instance size with 16vCPU, and add storage space to equal 18 TB.
For more information see: https://docs.fortinet.com/document/fortianalyzer-public-cloud/8.0.0/aws-administration-guide/372778/order-types
Highlights
- Streamlined Operations: FortiAnalyzer centralizes Security Fabric configurations, events, and alerts, providing advanced threat visualization and actionable insights for efficient SecOps management.
- AI-Driven Automation: Integrated with FortiAI, it leverages generative AI for context-aware threat management, offering ready-to-deploy playbooks, automation packs, and continuous updates to accelerate security responses.
- Continuous Security Posture Assessment: The Attack Surface Security Rating Service provides real-time evaluations of vulnerabilities and security settings, offering actionable scores to enhance security architecture and decision-making.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Trust Center
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Free trial
Dimension | Cost/hour |
|---|---|
m6i.2xlarge Recommended | $1.06 |
m7a.2xlarge | $1.06 |
c7i.4xlarge | $1.51 |
m6a.16xlarge | $12.08 |
m6a.2xlarge | $1.06 |
m7a.16xlarge | $12.08 |
c7i.xlarge | $0.54 |
c7i.2xlarge | $1.06 |
r7i.16xlarge | $12.08 |
m7i.xlarge | $0.54 |
Vendor refund policy
You may terminate the instance at anytime to stop incurring charges.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Additional details
Usage instructions
This product supports the flexibility of scaling the underlying instance up or down to achieve the desired feature capacity to match your requirements. The following information is an example of how to size your cloud instance to support a logging rate of 2GB/DAY with a recommended disk space to store 6 months of logs and then increase from 2GB/DAY to 100GB/Day.
Select an instance size with 8vCPU to support a 2GB/DAY logging rate and is configured with 360GB of storage space.
To increase the logging rate to 100GB/Day, shut down the existing instance, select and apply an instance size with 16vCPU, and add storage space to equal 18 TB.
Choose an instance with 8vCPU to support a logging rate of 2GB/Day and configured with 360GB of storage
Choose an instance with 16vCPU to support a logging rate of 100GB/Day and configured with 18TB of storage
Choose an instance with 32vCPU to support a logging rate of 500GB/Day and configured with 90TB of storage
Choose an instance with 64vCPU to support a logging rate of 1500GB/Day and configured with 270TB of storage
For more information see: https://docs.fortinet.com/document/fortianalyzer-public-cloud/7.6.0/aws-administration-guide/372778/order-types
Admin Guide: https://docs.fortinet.com/document/fortianalyzer-public-cloud/7.6.0/aws-administration-guide/
Please ensure the connectivity to FortiCare (https://directregistration.fortinet.com:443 ) by checking all related setup on security groups, ACLs, IGW, route tables, public IP address...etc.
After deploying the instance, click on Manage in AWS Console to see the running instance and public DNS address to continue the configuration of the FortiAnalyzer. Connect to the secured Web UI via the public DNS address: https://<public DNS address>. For any CLI configuration/settings, SSH is required to log into the CLI. Default login credentials are with a username of admin and the AWS Instance ID value as the password.
Resources
Support
Vendor support
Fortinet FortiCare support offerings provide global support for all Fortinet products and services. Please contact Customer Support with the following information:
- The serial number of your FortiGate instance (found on the GUI dashboard)
- The email ID of your Fortinet account (create one in https://support.fortinet.com/Credentials/Account/AccountCreation.aspx if you do not have).
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products


Customer reviews
Outstanding Centralized Log Management with Full Visibility Across Fortinet Devices
Robust Log Collection and Strong Reporting for Incidents and Events
FortiAnalyzer Delivers Centralized Visibility and Powerful Reporting
Reporting is something which needs to be appreciated. We have multiple reporting templates which really help us in multiple queries .
IMPORTANT : Handler and connector features really helps us in Proactive monitoring where we intergrated with Webhook and alerts are triggered in through our teams which is one of the key features
Inner joint queries are not working in FAZ report generation . In the past, we had to merge two reports with a common column ,I tried writing a sql query and it dint work . FAZ documentation need to be better.
Only who worked with Fortinet can manage FAZ
Comprehensive log analysis has improved traffic monitoring and streamlined risk mitigation
What is our primary use case?
I use Fortinet FortiAnalyzer for event monitoring and traffic monitoring to generate different types of reports for internal, external, internet traffic, or local LAN traffic.
I am looking for FortiNAC. I requested it from the local Fortinet manager and Forti sales manager. I contacted and emailed them to provide FortiNAC solution for my organization.
What is most valuable?
Log management in Fortinet FortiAnalyzer is excellent, as it stores approximately two years of logs.
Using Fortinet FortiAnalyzer, I analyze vulnerability risks and threats and sort out problems accordingly. I then create policies and mitigate the risk based on my findings.
I have created many customizable reports in Fortinet FortiAnalyzer. I have customized the reports to schedule them and generate reports every day that are sent to my email.
I am not using any SIEMs, but Fortinet FortiAnalyzer is the best and looks like a SIEM. I did not integrate Fortinet FortiAnalyzer with any security information and event management solutions.
With Fortinet FortiAnalyzer, I have streamlined the process to mitigate risks and save time to get event information on any type of threats, risks, and unwanted traffic. Risk and time are saved, and it is valuable for any organization.
What needs improvement?
Technical support should make some improvements.
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
Which solution did I use previously and why did I switch?
How was the initial setup?
What's my experience with pricing, setup cost, and licensing?
What other advice do I have?
Has provided valuable network insights while being straightforward to implement
What is our primary use case?
I am using Fortinet and Red Hat myself as a consultant. I am dealing with Fortinet products and can provide information about them. I am working with Fortinet products, including firewalls and other Fortinet products. I am working with Fortinet products such as Fortinet FortiAnalyzer and FortiManager. I use Fortinet FortiAnalyzer.
What is most valuable?
I find it easy to deploy Fortinet products, including the firewall, Fortinet FortiAnalyzer, and many other Fortinet products.
The interface of Fortinet FortiAnalyzer is intuitive enough. Fortinet provides training through many training documents and videos.
It is very important to integrate Fortinet products for my customers because it provides many network information for them.
What needs improvement?
I don't know what the main room for improvement is for Fortinet FortiAnalyzer, but perhaps I don't have much experience, so I cannot answer this question comprehensively.
For how long have I used the solution?
I have been working with Fortinet FortiAnalyzer for two years.
What do I think about the stability of the solution?
Fortinet FortiAnalyzer is very stable.
What do I think about the scalability of the solution?
I do not recommend Fortinet FortiAnalyzer for bigger companies because it is not scalable enough.
How are customer service and support?
I always ask Fortinet support about their technical support, and I think they are good.
I rate their technical support as seven out of ten. Sometimes they can answer the question immediately, but they could be more quick.
Which solution did I use previously and why did I switch?
Palo Alto also provides log management and has this product, but I have never used Palo Alto.
How was the initial setup?
I find it easy to deploy Fortinet products, including the firewall, Fortinet FortiAnalyzer, and many other Fortinet products.
What about the implementation team?
I usually help my customers with the implementation of Fortinet products, and they always use Fortinet products.
What was our ROI?
I think Fortinet FortiAnalyzer has fifty percent market share in my region.
What's my experience with pricing, setup cost, and licensing?
The pricing of Fortinet FortiAnalyzer is okay. For smaller companies, the pricing is acceptable.
Which other solutions did I evaluate?
Palo Alto also provides log management and has this product, but I have never used Palo Alto.
What other advice do I have?
I recommend Fortinet FortiAnalyzer for big companies. I rate this review an eight overall.