Fortinet FortiAnalyzer

FORTINET EXPERT PARTNER · SAME-DAY SHIPPING

FortiAnalyzer. Centralized log management for the Security Fabric.

FortiAnalyzer collects, stores, and analyzes log data from every Fortinet device in your environment. Firewalls, access points, switches, proxies, and endpoints all feed into one dashboard for threat correlation, forensic investigation, and compliance reporting. Firewalls.com is a Fortinet Expert Partner with certified engineers ready to help you size, configure, and manage your FortiAnalyzer deployment.

FortiAnalyzer appliance family
Expert Pre-Sales Advice Certified reps reply in 1 hour.
Config & Managed Services Skip the setup. We'll do it.
POs · Tax-Exempt · Net 30 Welcomed for Corp, Edu, & Gov.
Same-Day Shipping Order by 3pm EST, ships today.
Fortinet FortiAnalyzer Series

Shop by Series

FortiAnalyzer 150G appliance
SMB & Branch

FortiAnalyzer 150G

Up to 50 Devices · 5 TB Storage

Compact 1U appliance for small businesses, retail locations, and branch offices running a handful of FortiGate firewalls. Five terabytes of on-board storage and up to 50 GB/day log ingestion give small security teams months of searchable event history without requiring external archiving or a larger platform.

Shop FortiAnalyzer 150G →
FortiAnalyzer 300G appliance
SMB & Branch

FortiAnalyzer 300G

Up to 100 Devices · 8 TB Storage

A step up from the 150G for growing SMBs that have outgrown entry-level storage or need to manage more than a few FortiGate units. The 300G doubles storage capacity and raises the daily ingestion ceiling, keeping pace with organizations that are adding sites or expanding their Fortinet Security Fabric footprint.

Shop FortiAnalyzer 300G →
FortiAnalyzer 800F appliance
Mid-Market

FortiAnalyzer 800F

Up to 150 Devices · 32 TB Storage

Previous-generation mid-market appliance that remains fully supported and a solid choice for budget-conscious organizations managing tens of Fortinet devices. Thirty-two terabytes of storage supports extended log retention across multiple FortiGate firewalls, FortiAP deployments, and FortiSwitch stacks without requiring an upgrade to the current G-series hardware.

Shop FortiAnalyzer 800F →
FortiAnalyzer 800G appliance
Mid-Market

FortiAnalyzer 800G

Up to 300 Devices · 40 TB Storage

Current-generation mid-market appliance with 40 terabytes of storage and higher daily ingestion throughput than its F-series predecessor. AI-assisted event correlation helps security teams surface anomalies and generate audit-ready compliance reports without manual analysis work. The right choice for mid-size organizations starting a fresh FortiAnalyzer deployment.

Shop FortiAnalyzer 800G →
FortiAnalyzer 1000F appliance
Mid-Enterprise

FortiAnalyzer 1000F

Up to 500 Devices · 72 TB Storage

Bridges the gap between mid-market and full enterprise for organizations that have outgrown the 800 series but do not yet need the 3000-class hardware. Seventy-two terabytes of storage supports long retention cycles that compliance frameworks like PCI-DSS, HIPAA, and CMMC typically require, without the cost and footprint of a top-tier appliance.

Shop FortiAnalyzer 1000F →
FortiAnalyzer 3000F appliance
Enterprise

FortiAnalyzer 3000F

Up to 1,000 Devices · High-Capacity

Previous-generation enterprise appliance that handles large multi-site Fortinet deployments with high daily log volumes and deep retention requirements. The 3000F continues to see production use in enterprise environments and is a cost-effective option for organizations that need serious capacity without moving to current G-series hardware.

Shop FortiAnalyzer 3000F →
FortiAnalyzer 3000G appliance
Enterprise

FortiAnalyzer 3000G

2,000+ Devices · 100+ TB Storage

Current-generation enterprise workhorse for large organizations managing thousands of Fortinet devices across distributed networks. Updated hardware delivers higher ingestion throughput and more storage than the 3000F, with multi-VDOM support and granular administrative roles for complex, multi-team security operations.

Shop FortiAnalyzer 3000G →
FortiAnalyzer 3500G appliance
Enterprise

FortiAnalyzer 3500G

2,000+ Devices · 200+ TB Storage

Higher-capacity variant of the 3000G for enterprises with demanding log volumes or strict long-term retention requirements. The 3500G delivers significantly more on-board storage in the same 2U footprint, making it the right choice when the 3000G storage ceiling starts to create retention pressure in a growing Security Fabric environment.

Shop FortiAnalyzer 3500G →
FortiAnalyzer 3700G appliance
Enterprise

FortiAnalyzer 3700G

4,000+ Devices · Highest G-Series Capacity

Top of the standard G-series enterprise line, delivering the highest throughput and storage capacity in a rack-mount form factor before stepping into the BigData-4500F class. Designed for very large enterprises operating at the edge of what a single high-performance appliance can handle, with the full G-series feature set and current FortiOS support.

Shop FortiAnalyzer 3700G →
FortiAnalyzer BigData-4500F appliance
Large Enterprise

FortiAnalyzer BigData-4500F

10,000+ Devices · Petabyte-Scale

Purpose-built for MSSPs, government agencies, and very large enterprises that collect and retain petabytes of security telemetry. Administrative domains (ADOMs) let managed service providers isolate customer log data and delegate reporting access without mixing tenant environments, all from a single management plane.

Shop FortiAnalyzer BigData-4500F →
FortiAnalyzer VM virtual appliance
Virtual

FortiAnalyzer VM

Flexible Scale · VMware, KVM, AWS, Azure

Full FortiAnalyzer feature set delivered as a virtual appliance on VMware ESXi, Microsoft Hyper-V, KVM, or the major public clouds. Capacity is license-based, scaling with managed device count and daily log volume. The VM is a natural fit for cloud-first environments or organizations that want to avoid dedicated hardware while keeping log management on-premises or in a private cloud.

Shop FortiAnalyzer VM →
Compare

Fortinet FortiAnalyzer Appliances at a Glance

Series Best For Managed Devices Form Factor Key Feature
FortiAnalyzer 150G SMB, retail, branch offices Up to 50 devices 1U Rack / Desktop 5 TB storage, 50 GB/day ingestion
FortiAnalyzer 300G Growing SMBs, multi-site branch Up to 100 devices 1U Rack / Desktop 8 TB storage, higher ingestion ceiling
FortiAnalyzer 800F Budget-conscious mid-market Up to 150 devices 2U Rack 32 TB storage, previous-gen hardware
FortiAnalyzer 800G Mid-size enterprises Up to 300 devices 2U Rack 40 TB storage, AI-driven analytics
FortiAnalyzer 1000F Mid-enterprise, compliance-heavy Up to 500 devices 2U Rack 72 TB storage, extended retention
FortiAnalyzer 3000F Large enterprises, previous-gen Up to 1,000 devices 2U Rack High-capacity, F-series hardware
FortiAnalyzer 3000G Large enterprises, current-gen 2,000+ devices 2U Rack 100+ TB storage, multi-VDOM support
FortiAnalyzer 3500G Large enterprises, high retention 2,000+ devices 2U Rack 200+ TB storage, higher throughput
FortiAnalyzer 3700G Very large enterprises 4,000+ devices 2U Rack Highest G-series appliance capacity
FortiAnalyzer BigData-4500F MSSP, government, large enterprise 10,000+ devices 4U Rack Petabyte-scale, multi-tenant ADOMs
FortiAnalyzer VM Cloud-first and hybrid deployments Flexible, license-based Virtual (VMware, KVM, AWS, Azure) Elastic scale, no hardware required

FortiAnalyzer FAQ

FortiAnalyzer is Fortinet's centralized log management and security analytics platform. It collects logs from FortiGate firewalls, FortiAP access points, FortiSwitch, and other Fortinet Security Fabric devices, then correlates events, generates compliance reports, and surfaces threat intelligence in a single dashboard. Security teams use it to investigate incidents faster, satisfy audit requirements, and track network behavior across the entire Fortinet environment.

FortiAnalyzer collects and analyzes logs from FortiGate (all models and generations), FortiProxy, FortiAP, FortiSwitch, FortiMail, FortiWeb, FortiClient, FortiAuthenticator, and other Fortinet Security Fabric components. It is designed specifically to work within the Fortinet ecosystem and integrates natively with FortiManager, FortiSIEM, and FortiSOAR.

FortiGate logs events locally and offers its own dashboard, but local storage is limited and historical analysis across multiple firewalls is difficult without a dedicated log management tool. FortiAnalyzer gives you centralized, long-term storage, cross-device correlation, forensic search, and compliance-ready reports that FortiGate alone cannot produce. If you run more than one FortiGate, or if you need to retain logs for compliance, FortiAnalyzer is worth the investment.

The G series (150G, 300G, 800G, 3000G, 3500G, 3700G) is the current hardware generation, built for higher throughput, larger storage capacities, and support for the latest FortiOS versions. The F series (800F, 1000F, 3000F, BigData-4500F) is the previous hardware generation and remains fully supported and available. Most new deployments should start with the G series unless budget or an existing F-series environment drives the decision otherwise.

Yes. FortiAnalyzer VM runs on VMware ESXi, Microsoft Hyper-V, KVM, and AWS or Azure environments. It provides the same log collection, analytics, and reporting features as a physical appliance. VM capacity is license-based and scales with the number of managed devices and daily log ingestion volume. Our engineers can help you determine the correct license tier before you order.

The two key variables are the number of managed Fortinet devices and the average gigabytes of logs your environment generates per day. A small office with two or three FortiGates fits comfortably on a 150G. Mid-size companies managing 50 to 150 devices typically need an 800G. Large enterprises and MSSPs managing hundreds or thousands of devices should look at the 3000 series or BigData-4500F. Tell our team your device count and we will recommend the right model.

Yes. FortiAnalyzer supports administrative domains (ADOMs), which let MSSPs or large enterprises segment log data and reports by customer or business unit. Each ADOM can have its own administrators, report schedules, and data retention policies. The BigData-4500F and the high-end 3000 series appliances are built specifically for MSSP-scale multi-tenant deployments.

FortiAnalyzer integrates directly with both. FortiSIEM can pull event data from FortiAnalyzer for broader correlation across non-Fortinet sources. FortiSOAR can consume FortiAnalyzer alerts to trigger automated playbooks for incident response. These integrations are native to the Fortinet Security Fabric and require no third-party connectors or custom development.

Not sure which FortiAnalyzer is right for you?

Tell us how many FortiGate firewalls and other Fortinet devices you are managing, your average daily log volume if you know it, and whether you have any compliance frameworks to satisfy. A certified Fortinet engineer will reply within one business hour with a model recommendation and a quote.

Get a Sizing Recommendation

You'll always get our best prices when you're signed in!