Fortinet FortiAnalyzer
FortiAnalyzer. Centralized log management for the Security Fabric.
FortiAnalyzer collects, stores, and analyzes log data from every Fortinet device in your environment. Firewalls, access points, switches, proxies, and endpoints all feed into one dashboard for threat correlation, forensic investigation, and compliance reporting. Firewalls.com is a Fortinet Expert Partner with certified engineers ready to help you size, configure, and manage your FortiAnalyzer deployment.
Shop by Series
FortiAnalyzer 150G
Compact 1U appliance for small businesses, retail locations, and branch offices running a handful of FortiGate firewalls. Five terabytes of on-board storage and up to 50 GB/day log ingestion give small security teams months of searchable event history without requiring external archiving or a larger platform.
Shop FortiAnalyzer 150G →
FortiAnalyzer 300G
A step up from the 150G for growing SMBs that have outgrown entry-level storage or need to manage more than a few FortiGate units. The 300G doubles storage capacity and raises the daily ingestion ceiling, keeping pace with organizations that are adding sites or expanding their Fortinet Security Fabric footprint.
Shop FortiAnalyzer 300G →
FortiAnalyzer 800F
Previous-generation mid-market appliance that remains fully supported and a solid choice for budget-conscious organizations managing tens of Fortinet devices. Thirty-two terabytes of storage supports extended log retention across multiple FortiGate firewalls, FortiAP deployments, and FortiSwitch stacks without requiring an upgrade to the current G-series hardware.
Shop FortiAnalyzer 800F →
FortiAnalyzer 800G
Current-generation mid-market appliance with 40 terabytes of storage and higher daily ingestion throughput than its F-series predecessor. AI-assisted event correlation helps security teams surface anomalies and generate audit-ready compliance reports without manual analysis work. The right choice for mid-size organizations starting a fresh FortiAnalyzer deployment.
Shop FortiAnalyzer 800G →
FortiAnalyzer 1000F
Bridges the gap between mid-market and full enterprise for organizations that have outgrown the 800 series but do not yet need the 3000-class hardware. Seventy-two terabytes of storage supports long retention cycles that compliance frameworks like PCI-DSS, HIPAA, and CMMC typically require, without the cost and footprint of a top-tier appliance.
Shop FortiAnalyzer 1000F →
FortiAnalyzer 3000F
Previous-generation enterprise appliance that handles large multi-site Fortinet deployments with high daily log volumes and deep retention requirements. The 3000F continues to see production use in enterprise environments and is a cost-effective option for organizations that need serious capacity without moving to current G-series hardware.
Shop FortiAnalyzer 3000F →
FortiAnalyzer 3000G
Current-generation enterprise workhorse for large organizations managing thousands of Fortinet devices across distributed networks. Updated hardware delivers higher ingestion throughput and more storage than the 3000F, with multi-VDOM support and granular administrative roles for complex, multi-team security operations.
Shop FortiAnalyzer 3000G →
FortiAnalyzer 3500G
Higher-capacity variant of the 3000G for enterprises with demanding log volumes or strict long-term retention requirements. The 3500G delivers significantly more on-board storage in the same 2U footprint, making it the right choice when the 3000G storage ceiling starts to create retention pressure in a growing Security Fabric environment.
Shop FortiAnalyzer 3500G →
FortiAnalyzer 3700G
Top of the standard G-series enterprise line, delivering the highest throughput and storage capacity in a rack-mount form factor before stepping into the BigData-4500F class. Designed for very large enterprises operating at the edge of what a single high-performance appliance can handle, with the full G-series feature set and current FortiOS support.
Shop FortiAnalyzer 3700G →
FortiAnalyzer BigData-4500F
Purpose-built for MSSPs, government agencies, and very large enterprises that collect and retain petabytes of security telemetry. Administrative domains (ADOMs) let managed service providers isolate customer log data and delegate reporting access without mixing tenant environments, all from a single management plane.
Shop FortiAnalyzer BigData-4500F →
FortiAnalyzer VM
Full FortiAnalyzer feature set delivered as a virtual appliance on VMware ESXi, Microsoft Hyper-V, KVM, or the major public clouds. Capacity is license-based, scaling with managed device count and daily log volume. The VM is a natural fit for cloud-first environments or organizations that want to avoid dedicated hardware while keeping log management on-premises or in a private cloud.
Shop FortiAnalyzer VM →Fortinet FortiAnalyzer Appliances at a Glance
| Series | Best For | Managed Devices | Form Factor | Key Feature |
|---|---|---|---|---|
| FortiAnalyzer 150G | SMB, retail, branch offices | Up to 50 devices | 1U Rack / Desktop | 5 TB storage, 50 GB/day ingestion |
| FortiAnalyzer 300G | Growing SMBs, multi-site branch | Up to 100 devices | 1U Rack / Desktop | 8 TB storage, higher ingestion ceiling |
| FortiAnalyzer 800F | Budget-conscious mid-market | Up to 150 devices | 2U Rack | 32 TB storage, previous-gen hardware |
| FortiAnalyzer 800G | Mid-size enterprises | Up to 300 devices | 2U Rack | 40 TB storage, AI-driven analytics |
| FortiAnalyzer 1000F | Mid-enterprise, compliance-heavy | Up to 500 devices | 2U Rack | 72 TB storage, extended retention |
| FortiAnalyzer 3000F | Large enterprises, previous-gen | Up to 1,000 devices | 2U Rack | High-capacity, F-series hardware |
| FortiAnalyzer 3000G | Large enterprises, current-gen | 2,000+ devices | 2U Rack | 100+ TB storage, multi-VDOM support |
| FortiAnalyzer 3500G | Large enterprises, high retention | 2,000+ devices | 2U Rack | 200+ TB storage, higher throughput |
| FortiAnalyzer 3700G | Very large enterprises | 4,000+ devices | 2U Rack | Highest G-series appliance capacity |
| FortiAnalyzer BigData-4500F | MSSP, government, large enterprise | 10,000+ devices | 4U Rack | Petabyte-scale, multi-tenant ADOMs |
| FortiAnalyzer VM | Cloud-first and hybrid deployments | Flexible, license-based | Virtual (VMware, KVM, AWS, Azure) | Elastic scale, no hardware required |
FortiAnalyzer FAQ
FortiAnalyzer is Fortinet's centralized log management and security analytics platform. It collects logs from FortiGate firewalls, FortiAP access points, FortiSwitch, and other Fortinet Security Fabric devices, then correlates events, generates compliance reports, and surfaces threat intelligence in a single dashboard. Security teams use it to investigate incidents faster, satisfy audit requirements, and track network behavior across the entire Fortinet environment.
FortiAnalyzer collects and analyzes logs from FortiGate (all models and generations), FortiProxy, FortiAP, FortiSwitch, FortiMail, FortiWeb, FortiClient, FortiAuthenticator, and other Fortinet Security Fabric components. It is designed specifically to work within the Fortinet ecosystem and integrates natively with FortiManager, FortiSIEM, and FortiSOAR.
FortiGate logs events locally and offers its own dashboard, but local storage is limited and historical analysis across multiple firewalls is difficult without a dedicated log management tool. FortiAnalyzer gives you centralized, long-term storage, cross-device correlation, forensic search, and compliance-ready reports that FortiGate alone cannot produce. If you run more than one FortiGate, or if you need to retain logs for compliance, FortiAnalyzer is worth the investment.
The G series (150G, 300G, 800G, 3000G, 3500G, 3700G) is the current hardware generation, built for higher throughput, larger storage capacities, and support for the latest FortiOS versions. The F series (800F, 1000F, 3000F, BigData-4500F) is the previous hardware generation and remains fully supported and available. Most new deployments should start with the G series unless budget or an existing F-series environment drives the decision otherwise.
Yes. FortiAnalyzer VM runs on VMware ESXi, Microsoft Hyper-V, KVM, and AWS or Azure environments. It provides the same log collection, analytics, and reporting features as a physical appliance. VM capacity is license-based and scales with the number of managed devices and daily log ingestion volume. Our engineers can help you determine the correct license tier before you order.
The two key variables are the number of managed Fortinet devices and the average gigabytes of logs your environment generates per day. A small office with two or three FortiGates fits comfortably on a 150G. Mid-size companies managing 50 to 150 devices typically need an 800G. Large enterprises and MSSPs managing hundreds or thousands of devices should look at the 3000 series or BigData-4500F. Tell our team your device count and we will recommend the right model.
Yes. FortiAnalyzer supports administrative domains (ADOMs), which let MSSPs or large enterprises segment log data and reports by customer or business unit. Each ADOM can have its own administrators, report schedules, and data retention policies. The BigData-4500F and the high-end 3000 series appliances are built specifically for MSSP-scale multi-tenant deployments.
FortiAnalyzer integrates directly with both. FortiSIEM can pull event data from FortiAnalyzer for broader correlation across non-Fortinet sources. FortiSOAR can consume FortiAnalyzer alerts to trigger automated playbooks for incident response. These integrations are native to the Fortinet Security Fabric and require no third-party connectors or custom development.
Not sure which FortiAnalyzer is right for you?
Tell us how many FortiGate firewalls and other Fortinet devices you are managing, your average daily log volume if you know it, and whether you have any compliance frameworks to satisfy. A certified Fortinet engineer will reply within one business hour with a model recommendation and a quote.
Get a Sizing Recommendation
Login and Registration Form
Existing User