FortiAnalyzer 1000G
660 GB of logs per day, 20,000 logs/sec in analytic mode
- GB logs / day
- 660
- Analytic rate
- 20,000 logs/sec
- Storage
- 8x 4 TB
The FortiAnalyzer 1000G ingests 660 GB of logs per day, sustaining 20,000 logs/sec in analytic mode and 30,000 logs/sec in collector mode, with 8x 4 TB of storage.
660 GB/day and 20,000 logs/sec analytic — a five-fold jump in ingest rate over the 810G for triple the daily volume, which tells you where it is aimed: bursty, inspection-heavy estates where the peak matters more than the average. Under-sizing shows up as dropped logs during precisely the incident you needed them for, which is the most expensive mistake available in the Fabric.
Highlights
- 660 GB of logs per day
- 20,000 logs/sec analytic, 30,000 collector
- 8x 4 TB storage for real retention depth
Typical deployments
- Large campus and data-centre estates with full UTM logging
- Environments where peak log rate spikes hard during incidents
- Deployments consolidating several regional collectors
What this includes
Fortinet publishes no throughput table for this product — it is licensed per user, endpoint, workload or account. What follows is capability and sizing, not benchmarks.
Capacity
Analytic mode indexes for investigation and reporting; collector mode ingests faster but does not index. Large estates commonly run collectors at the edge feeding one analytic unit at the centre.
| GB logs/day | 660 |
|---|---|
| Analytic sustained rate (logs/sec) | 20,000 |
| Collector sustained rate (logs/sec) | 30,000 |
Hardware
| Total interfaces | 4x GE RJ45, 2x 25GE SFP28 |
|---|---|
| Storage capacity | 8x 4 TB |
Sources
- Fortinet Product Matrix (July 2026) — retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order — we will.