FortiAnalyzer enhances security operations by integrating threat intelligence, AI-driven assistance, and security automation into a unified framework for IT and OT systems. Its lightweight deployment enables organizations to transform raw data into actionable insights, streamlining operations and improving both historical and real-time analysis capabilities. By centralizing Security Fabric configurations, events, and alerts, FortiAnalyzer simplifies operations while providing advanced threat visualization through intuitive dashboards and detailed threat topologies.
With its seamless integration of FortiAI, FortiAnalyzer leverages generative AI to deliver context-aware threat management, offering AI-recommended practices and preconfigured automation packs, including playbooks and premium reports. These tools help SecOps teams prioritize strategic tasks and accelerate threat response.
The FortiAnalyzer Attack Surface Security Rating Service continuously evaluates an organizations security posture in real-time, monitoring unpatched vulnerabilities and critical settings while providing actionable insights. This service empowers decision-making by offering security posture scores, Fabric coverage analysis, and optimization recommendations, ensuring a comprehensive approach to enhancing security architecture. FortiAnalyzer ultimately improves operational efficiency and strengthens an organizations overall security strategy.
This product supports the flexibility of scaling the underlying instance up or down to achieve the desired feature capacity to match your requirements. The following information is an example of how to size your cloud instance to support a logging rate of 2GB/DAY with a recommended disk space to store 6 months of logs and then increase from 2GB/DAY to 100GB/Day.
Select an instance size with 8vCPU to support a 2GB/DAY logging rate and is configured with 360GB of storage space.
To increase the logging rate to 100GB/Day, shut down the existing instance, select and apply an instance size with 16vCPU, and add storage space to equal 18 TB.
Streamlined Operations: FortiAnalyzer centralizes Security Fabric configurations, events, and alerts, providing advanced threat visualization and actionable insights for efficient SecOps management.
AI-Driven Automation: Integrated with FortiAI, it leverages generative AI for context-aware threat management, offering ready-to-deploy playbooks, automation packs, and continuous updates to accelerate security responses.
Continuous Security Posture Assessment: The Attack Surface Security Rating Service provides real-time evaluations of vulnerabilities and security settings, offering actionable scores to enhance security architecture and decision-making.
Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Try this product free for 30 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You pay by the hour based on the AWS EC2 instance type you run FortiAnalyzer on. This is usage-based pricing, so you are billed only for the hours each instance runs. The dimensions are not feature tiers. Each option maps to a different EC2 instance size across several families, including general-purpose, compute-optimized, and memory-optimized types. Smaller instances (xlarge) suit lighter logging loads, while larger ones (up to 16xlarge) handle heavier processing. All options deliver the same centralized logging and reporting software. You scale cost by choosing a larger or smaller instance to match your workload.
Top-of-mind questions for buyers
Am I charged when the FortiAnalyzer instance is stopped or paused?
Software charges meter running instance-hours only. A fully stopped instance does not accrue hourly software fees. Stopped instances may still incur underlying AWS storage costs for attached volumes, but the FortiAnalyzer software licence bills for hours the instance actually runs.
What does one billing unit map to, and how do I pick an instance?
One unit is one hour of a chosen AWS EC2 instance type running FortiAnalyzer. You select from general-purpose, compute-optimized, or memory-optimized families. Memory-optimized types suit heavier log analysis. Match the instance size to your log ingestion and reporting volume.
How does hourly usage-based billing differ from committing to a fixed term?
The hourly option meters actual instance-hours with no upfront commitment. You pay only for hours each instance runs, and you can start or stop as needed. This suits variable or short-term logging workloads where continuous around-the-clock operation is not required.
www.fortinet.com+1
Helpful?
Vendor refund policy
You may terminate the instance at anytime to stop incurring charges.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
This product supports the flexibility of scaling the underlying instance up or down to achieve the desired feature capacity to match your requirements. The following information is an example of how to size your cloud instance to support a logging rate of 2GB/DAY with a recommended disk space to store 6 months of logs and then increase from 2GB/DAY to 100GB/Day.
Select an instance size with 8vCPU to support a 2GB/DAY logging rate and is configured with 360GB of storage space.
To increase the logging rate to 100GB/Day, shut down the existing instance, select and apply an instance size with 16vCPU, and add storage space to equal 18 TB.
Choose an instance with 8vCPU to support a logging rate of 2GB/Day and configured with 360GB of storage
Choose an instance with 16vCPU to support a logging rate of 100GB/Day and configured with 18TB of storage
Choose an instance with 32vCPU to support a logging rate of 500GB/Day and configured with 90TB of storage
Choose an instance with 64vCPU to support a logging rate of 1500GB/Day and configured with 270TB of storage
Please ensure the connectivity to FortiCare (https://directregistration.fortinet.com:443) by checking all related setup on security groups, ACLs, IGW, route tables, public IP address...etc.
After deploying the instance, click on Manage in AWS Console to see the running instance and public DNS address to continue the configuration of the FortiAnalyzer. Connect to the secured Web UI via the public DNS address: https://<public DNS address>. For any CLI configuration/settings, SSH is required to log into the CLI. Default login credentials are with a username of admin and the AWS Instance ID value as the password.
Fortinet FortiCare support offerings provide global support for all Fortinet products and services. Please contact Customer Support with the following information:
The serial number of your FortiGate instance (found on the GUI dashboard)
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Fortinet FortiGate allows mitigation of blind spots to improve policy compliance by implementing critical security controls within your AWS environment. FortiGate includes all of the security and networking services common to FortiGate physical appliances.
Fortinet professional design and implementation services for network, application, and cloud-native (CNAPP) security for AWS, hybrid, and multi-cloud environments.
FortiAuthenticator is a centralized user Identity Management solution to transparently identify network users and enforce identity-driven access policy in a Fortinet fabric. It supports FortiToken Two-factor authentication, Certificate and Wireless Guest management and Single Sign On capability.
The Fortinet FortiManager provides easy centralized configuration, policy-based provisioning, update management and end-to-end network monitoring for your Fortinet installed environment.
The FortiWeb web application firewall (WAF) defends web-based applications from known and zero-day threats. Its AI-based machine learning identifies threats with virtually no false positive detections.
Outstanding Centralized Log Management with Full Visibility Across Fortinet Devices
Reviewed on May 04, 2026
Review provided by G2
What do you like best about the product?
The centralized log management is outstanding. Having full visibility across all of our Fortinet devices in one dashboard saves us a lot of time and makes it much easier to stay on top of everything.
What do you dislike about the product?
Storage requirements can grow quickly in large environments, but the performance and insights you get in return more than justify the extra space.
What problems is the product solving and how is that benefiting you?
FortiAnalyzer solved our visibility problem entirely. Having all logs centralized in one platform means we can detect and respond to threats in minutes instead of hours.
Jitendra Kumar P.
Robust Log Collection and Strong Reporting for Incidents and Events
Reviewed on Apr 06, 2026
Review provided by G2
What do you like best about the product?
Robust log collection for incidents and events, backed by strong reporting.
What do you dislike about the product?
The initial integration with FortiManager is fairly complex. For new users, it can be difficult to set up and understand.
What problems is the product solving and how is that benefiting you?
A solid choice for centralized log analysis, with robust reporting to match.
Telecommunications
FortiAnalyzer Delivers Centralized Visibility and Powerful Reporting
Reviewed on Mar 24, 2026
Review provided by G2
What do you like best about the product?
What I really appreciate about FortiAnalyzer is how it pulls everything together into one place. Instead of jumping between different tools or trying to piece logs together manually, it gives me centralized visibility across the entire Fortinet setup. That alone saves a lot of time and reduces the chance of missing something important. Reporting is something which needs to be appreciated. We have multiple reporting templates which really help us in multiple queries . IMPORTANT : Handler and connector features really helps us in Proactive monitoring where we intergrated with Webhook and alerts are triggered in through our teams which is one of the key features
What do you dislike about the product?
When dealing with Larger volume of logs , it takes more times and reporting few columns will be empty at times. Inner joint queries are not working in FAZ report generation . In the past, we had to merge two reports with a common column ,I tried writing a sql query and it dint work . FAZ documentation need to be better. Only who worked with Fortinet can manage FAZ
What problems is the product solving and how is that benefiting you?
Fortinet is now concentrating to make the reporting time less compared to larger time . Also the handler and connector features really helps us in Proactive monitoring which triggers alert and helps our engineers to action the alerts. Eg. VPN down , HA failover , BGP flap etc
Amarnath Jaiswal
Comprehensive log analysis has improved traffic monitoring and streamlined risk mitigation
Reviewed on Feb 17, 2026
Review provided by PeerSpot
What is our primary use case?
I am using Fortinet FortiAnalyzer along with the analyzer for traffic monitoring and event checking. It is effective for analyzing traffic purposes.
I use Fortinet FortiAnalyzer for event monitoring and traffic monitoring to generate different types of reports for internal, external, internet traffic, or local LAN traffic.
I am looking for FortiNAC. I requested it from the local Fortinet manager and Forti sales manager. I contacted and emailed them to provide FortiNAC solution for my organization.
What is most valuable?
Fortinet FortiAnalyzer is a very comprehensive analyzer providing detailed analyzing features and customizable reports. I can get customization and custom reports, and there are many functions available. It is very good for any organization.
Log management in Fortinet FortiAnalyzer is excellent, as it stores approximately two years of logs.
Using Fortinet FortiAnalyzer, I analyze vulnerability risks and threats and sort out problems accordingly. I then create policies and mitigate the risk based on my findings.
I have created many customizable reports in Fortinet FortiAnalyzer. I have customized the reports to schedule them and generate reports every day that are sent to my email.
I am not using any SIEMs, but Fortinet FortiAnalyzer is the best and looks like a SIEM. I did not integrate Fortinet FortiAnalyzer with any security information and event management solutions.
With Fortinet FortiAnalyzer, I have streamlined the process to mitigate risks and save time to get event information on any type of threats, risks, and unwanted traffic. Risk and time are saved, and it is valuable for any organization.
What needs improvement?
I think technical support should be better. Sometimes support from Fortinet does not help with creating policies or configuration issues and directly routes to the service integrator. A little more help from Fortinet support service would be appreciated.
Technical support should make some improvements.
What do I think about the stability of the solution?
I rate the stability of Fortinet FortiAnalyzer ten out of ten.
What do I think about the scalability of the solution?
I rate the scalability of Fortinet FortiAnalyzer nine.
Which solution did I use previously and why did I switch?
I did not compare Fortinet FortiAnalyzer with a product from any other vendor, and I did not consider any other options before working with Fortinet FortiAnalyzer.
How was the initial setup?
The initial setup for Fortinet FortiAnalyzer is very simple. I deployed this analyzer within a very short time, in under one hour, with the help of the knowledge base from the Fortinet website and Fortinet documentation. I deployed it myself without any third-party help.
What's my experience with pricing, setup cost, and licensing?
For pricing, I rate it a little high but nine.
What other advice do I have?
Fortinet updates the features and services in Fortinet FortiAnalyzer from time to time. From my point of view, everything is good. I believe I get the best results from the analyzer. I am only working with Fortinet FortiAnalyzer. I recommend it to other organizations to purchase Fortinet and Fortinet products. I also initiated purchasing the product for my OT network. I am providing this review with an overall rating of ten.
Arf Wu
Has provided valuable network insights while being straightforward to implement
Reviewed on Nov 03, 2025
Review provided by PeerSpot
What is our primary use case?
I am using Fortinet and Red Hat myself as a consultant. I am dealing with Fortinet products and can provide information about them. I am working with Fortinet products, including firewalls and other Fortinet products. I am working with Fortinet products such as Fortinet FortiAnalyzer and FortiManager. I use Fortinet FortiAnalyzer.
What is most valuable?
I find it easy to deploy Fortinet products, including the firewall, Fortinet FortiAnalyzer, and many other Fortinet products.
The interface of Fortinet FortiAnalyzer is intuitive enough. Fortinet provides training through many training documents and videos.
It is very important to integrate Fortinet products for my customers because it provides many network information for them.
What needs improvement?
I don't know what the main room for improvement is for Fortinet FortiAnalyzer, but perhaps I don't have much experience, so I cannot answer this question comprehensively.
For how long have I used the solution?
I have been working with Fortinet FortiAnalyzer for two years.
What do I think about the stability of the solution?
Fortinet FortiAnalyzer is very stable.
What do I think about the scalability of the solution?
I do not recommend Fortinet FortiAnalyzer for bigger companies because it is not scalable enough.
How are customer service and support?
I always ask Fortinet support about their technical support, and I think they are good.
I rate their technical support as seven out of ten. Sometimes they can answer the question immediately, but they could be more quick.
Which solution did I use previously and why did I switch?
Palo Alto also provides log management and has this product, but I have never used Palo Alto.
How was the initial setup?
I find it easy to deploy Fortinet products, including the firewall, Fortinet FortiAnalyzer, and many other Fortinet products.
What about the implementation team?
I usually help my customers with the implementation of Fortinet products, and they always use Fortinet products.
What was our ROI?
I think Fortinet FortiAnalyzer has fifty percent market share in my region.
What's my experience with pricing, setup cost, and licensing?
The pricing of Fortinet FortiAnalyzer is okay. For smaller companies, the pricing is acceptable.
Which other solutions did I evaluate?
Palo Alto also provides log management and has this product, but I have never used Palo Alto.
What other advice do I have?
I recommend Fortinet FortiAnalyzer for big companies. I rate this review an eight overall.