Likelihood to Recommend
FortiAnalyzer is a must have when you administer multiple FortiGate firewalls in a defense in depth enterprise environment. Total visibility can be achieved across multiple physical and virtual firewalls. Complete analysis of your threat landscape is possible along with real time detection, compliance reporting, and wholistic firewall rule analysis and reporting. Eliminating shadow rules, tuning unnecessarily permissive rules, automation and other analysis are built in to this easy to deploy software.
Read full review
Splunk User Behavior Analytics application is necessary when any company wants to capture the threat based on user behavior instead of just counting the number of occurrences of particular event. With Splunk UBA, we can analyse number of anomalies captured and which in turn creating threats which are nearly true positive.
Read full review Pros Event correlation Real-time detection Compliance Reporting Security Tools orchestration Security workflow automation Integration with ServiceNOW Centralized NOC/SOC visibility Read full review Monitor and troubleshoot for any system errors. Get the insights on application data sets and do some predictive analysis. Read full review Cons Administrative Domains and Software Versions are difficult to maintain managing different FortiOS versions gets complicated quite easily Administrative Domains must be well architected from the beginning Read full review Performance-wise, it can be improved. Queries take a long time. Dataset exploration - More data visualization charts can be added. Read full review Usability
FortiAnalyzer is easy to deploy are ready to use right out of the box. The user interface is intuitive and the reporting engine is very customizable however most of the 'canned' reports are usable right away. It is easy to add firewalls under management and event correlation happens immediately. FortiAnalyzer is a great log aggregator for all of your firewalls and then upload meaningful data to a SEIM.
Read full review Alternatives Considered
FortiAnalyzer is significantly cheaper and a better value for the money especially if you have FortiGate firewalls in the datacenter or in the cloud. FortiAnalyzer manages physical, virtual, and cloud firewalls in a single pane of glass providing a wholistic enterprise view of your security landscape. Compliance reporting comes built-in with the most popular reports ready at a click of a button. FortiAnalyzer is a great aggregation point before uploading logs to a SEIM / SOC tool.
Read full review
Easier we were using
on heavy forwarder on which all the add-on were installed and were using
with respect to search head and indexers stack. And with
Security premium app, we were relying on correlation rules which were throwing more number of false positive but after implementing Splunk UBA, we are now getting real-time true positive threat or incidents.
Read full review Return on Investment we were able to retire 3 legacy security tools in favor of FortiAnalyzer Automate 155 security tasks and reporting one click compliance reporting for PCI-DSS Enterprise security governance Visualize the security landscape Eliminate and or prune unnecessary rules Tune overly permissive rules for tighter security Read full review Fewer team members to work on real threats. Less time required to deal with real incidents. Easy to implement across the network. Read full review