As part of the Fortinet Security Fabric, FortiAnalyzer provides security fabric analytics and automation to provide better detection and response against cyber risks.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Network Engineer in Information Technology at Boulanger (1001-5000 employees employees)
Use Cases and Deployment Scope
We're addressing logging analytics, real time logs for trafic events, but for webfiltering too or any or security profile. We also configured alerting on specific log and made some reports to be sent by email to keep historical view of specific needs. Globaly it allows to centralized our 200 clusters logs
Pros
Automated reports on specific perimeters
Logs analytics
Global retention (security need of storage)
Global overview log on specific device
Cons
UI is sometimes complicated to custom
global configuration for SSL negociation (forward log could have an impact)
Storage management could be easier
Return on Investment
As we choose Cloud platform, we're using what we need, I mean the storage is specifically the storage that we need
As soon as we had some issues we can analyze it or forward log to siem and they can analyze it
As we forward log to SIEM we had a best security management on firewall
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Verified User
Manager in Information Technology (201-500 employees employees)
Use Cases and Deployment Scope
We use FortiAnalyzer mainly in a security operations center capacity helping us gain a clear perspective of internet/network activity from our end users and identifying cyber threats. FortiAnalyzer helps us collect system logs and produce clear reporting. Triggering alerts to our service desk when certain events happen has also helped us stay on top.
Pros
Reporting
Alerts
Graphical User Interface
Cons
Sections and tab system - can be confusing
Automatic/scheduled updates - would be a great feature
SSL binding can be buggy - accessing the FAZ site sometimes gives certificate warnings.
Return on Investment
Alert Automation - less time spent trawling endless logs
Great accuracy with granular reporting.
Team accessible - custom reporting portal available to delegated teams
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Verified User
Manager in Information Technology (201-500 employees employees)
Use Cases and Deployment Scope
We primarily leverage FortiAnalyzer for comprehensive monitoring of both inbound and outbound internet and intranet traffic through our perimeter firewall. This product provides us with a customized dashboard tailored to our specific use cases. Additionally, it plays a crucial role in generating monthly executive summary reports for management, offering insights into internet usage across the organization and individual users.
Pros
Custom dashboard
VPN traffic monitoring
Internet traffic monitoring
Users behavior analysis
Integrate well with the FortiGate firewall
Log analysis
Cons
In-depth user behavior analysis
Better UI/UX dashboard
Better integration with other product than FortiGate
Return on Investment
We are able to report to the management the real-time attacks on the network
User behavior analysis has become easy
Achieving a favorable return on investment (ROI) is easily attainable, given that the product cost is relatively moderate. Without the product, the amount of human work time required is significantly higher, further emphasizing the cost-effectiveness of its implementation.
Alternatives Considered
IBM Security QRadar SIEM, SolarWinds NetFlow Traffic Analyzer (NTA) and ManageEngine NetFlow Analyzer