FortiAnalyzer Logging and Analytics
Where the logs live, the reports come from and retention is satisfied
Compare all 8 models
Figures are Fortinet’s own — sortable, cited on every product page| Model | logs/sec | logs/sec | Actions | ||
|---|---|---|---|---|---|
| FortiAnalyzer 150GFAZ-150G | 25 | 500 | 750 | 2x 2 TB | Details |
| FortiAnalyzer 300GFAZ-300G | 100 | 2,000 | 3,000 | 2x 4 TB | Details |
| FortiAnalyzer 810GFAZ-810G | 200 | 4,000 | 6,000 | 4x 4 TB | Details |
| FortiAnalyzer 1000GFAZ-1000G | 660 | 20,000 | 30,000 | 8x 4 TB | Details |
| FortiAnalyzer 3100GFAZ-3100G | 3,000 | 42,000 | 60,000 | 16x 4 TB HDD + 2x 1.92 TB SSD | Details |
| FortiAnalyzer 3510GFAZ-3510G | 5,000 | 60,000 | 90,000 | 24x 4 TB HDD + 2x 3.84 TB SSD | Details |
| FortiAnalyzer 3750GFAZ-3750G | 8,300 | 100,000 | 150,000 | 24x 16 TB HDD + 4x 15 TB SSD | Details |
| FortiAnalyzer VMFAZ-VM | 1 to 2,000+ | — | — | 500 GB to 100+ TB | Details |
How to read these numbers
FortiAnalyzer collects, indexes and reports on logs from across the Fabric. It is what turns a firewall's traffic log into an investigation, a compliance report and a retention posture.
More on choosing within this range
Sizing has two distinct numbers and both matter. GB of logs per day drives storage and licensing — 25 on the FAZ-150G up to 8,300 on the FAZ-3750G. Sustained log rate drives whether it keeps up under load, and it is quoted separately for analytic mode (500 to 100,000 logs/sec) and collector mode (750 to 150,000).
Under-sizing shows up as dropped logs during exactly the incident you needed the logs for. It is the most consequential sizing mistake in the Fabric.
Before you order
How many GB of logs per day?
Measure it rather than estimating. A FortiGate with full UTM logging and SSL inspection produces dramatically more than the same box doing plain firewalling, and the multiplier surprises people.
How long must logs be kept?
Retention times storage per day gives the capacity requirement. PCI, HIPAA and state breach law all have opinions here and they are not optional.
Analytic or collector mode?
Collector mode ingests far faster but does not index for analysis. Large estates commonly run collectors at the edge feeding an analytic FortiAnalyzer at the centre.
Do you need it for SOC work?
FortiAnalyzer covers reporting and investigation well. Once you need cross-vendor correlation and UEBA, that is FortiSIEM's job — we will tell you which line you are on.
All FortiAnalyzer Logging and Analytics
FortiAnalyzer 150G
25 GB of logs per day, 500 logs/sec in analytic mode
FortiAnalyzer 300G
100 GB of logs per day, 2,000 logs/sec in analytic mode
FortiAnalyzer 810G
200 GB of logs per day, 4,000 logs/sec in analytic mode
FortiAnalyzer 1000G
660 GB of logs per day, 20,000 logs/sec in analytic mode
FortiAnalyzer 3100G
3,000 GB of logs per day, 42,000 logs/sec in analytic mode
FortiAnalyzer 3510G
5,000 GB of logs per day, 60,000 logs/sec in analytic mode
FortiAnalyzer 3750G
8,300 GB of logs per day, 100,000 logs/sec in analytic mode
FortiAnalyzer VM
Virtual FortiAnalyzer — 1 to 2,000+ GB of logs per day