FortiAnalyzer VM
Virtual FortiAnalyzer — 1 to 2,000+ GB of logs per day
- GB logs / day
- 1 to 2,000+
- Analytic rate
- Hardware dependent
- Storage
- 500 GB to 100+ TB
FortiAnalyzer VM covers the same logging, reporting and retention role on your own infrastructure, licensed from 1 GB/day up to 2,000+ GB/day with storage from 500 GB to over 100 TB.
1 to 2,000+ GB/day with 500 GB to over 100 TB of storage, licensed by daily volume rather than by chassis. The flexibility is the point — you can start small and grow the licence — but the same caveat as FortiManager VM applies: performance follows the resources you give it, and log ingest is I/O-bound, so storage backing matters more here than vCPU count.
Highlights
- 1 to 2,000+ GB of logs per day
- Hardware-dependent in analytic mode
- 500 GB to 100+ TB of onboard storage
- Reporting and retention for PCI DSS, HIPAA and state breach law
Typical deployments
- Organisations already running everything virtually
- Cloud-hosted log retention for a distributed estate
- Deployments that need to scale ingest without replacing hardware
What this includes
Fortinet publishes no throughput table for this product — it is licensed per user, endpoint, workload or account. What follows is capability and sizing, not benchmarks.
Capacity
Analytic mode indexes for investigation and reporting; collector mode ingests faster but does not index. Large estates commonly run collectors at the edge feeding one analytic unit at the centre.
| GB logs/day | 1 to 2,000+ |
|---|---|
| Analytic sustained rate (logs/sec) | — |
| Collector sustained rate (logs/sec) | — |
Hardware
| Total interfaces | 1–4 vNIC |
|---|---|
| Storage capacity | 500 GB to 100+ TB |
Sources
- Fortinet Product Matrix (July 2026) — retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order — we will.