Skip to main content
Authorized Fortinet reseller · DynaScale Technologies888-907-0723 · 24/7[email protected]
FortiAnalyzer (FAZ-150G through 3750G / VM)

FortiAnalyzer Logging and Analytics

Where the logs live, the reports come from and retention is satisfied

Compare all 8 models

Figures are Fortinet’s own, sortable, cited on every product page
FortiAnalyzer Logging and Analytics model comparison
Modellogs/seclogs/secActions
FortiAnalyzer 150GFAZ-150G255007502x 2 TBDetails
FortiAnalyzer 300GFAZ-300G1002,0003,0002x 4 TBDetails
FortiAnalyzer 810GFAZ-810G2004,0006,0004x 4 TBDetails
FortiAnalyzer 1000GFAZ-1000G66020,00030,0008x 4 TBDetails
FortiAnalyzer 3100GFAZ-3100G3,00042,00060,00016x 4 TB HDD + 2x 1.92 TB SSDDetails
FortiAnalyzer 3510GFAZ-3510G5,00060,00090,00024x 4 TB HDD + 2x 3.84 TB SSDDetails
FortiAnalyzer 3750GFAZ-3750G8,300100,000150,00024x 16 TB HDD + 4x 15 TB SSDDetails
FortiAnalyzer VMFAZ-VM1 to 2,000+, , 500 GB to 100+ TBDetails

How to read these numbers

FortiAnalyzer collects, indexes and reports on logs from across the Fabric. It is what turns a firewall's traffic log into an investigation, a compliance report and a retention posture.

More on choosing within this range

Sizing has two distinct numbers and both matter. GB of logs per day drives storage and licensing, 25 on the FAZ-150G up to 8,300 on the FAZ-3750G. Sustained log rate drives whether it keeps up under load, and it is quoted separately for analytic mode (500 to 100,000 logs/sec) and collector mode (750 to 150,000).

Under-sizing shows up as dropped logs during exactly the incident you needed the logs for. It is the most consequential sizing mistake in the Fabric.

Before you order

How many GB of logs per day?

Measure it rather than estimating. A FortiGate with full UTM logging and SSL inspection produces dramatically more than the same box doing plain firewalling, and the multiplier surprises people.

How long must logs be kept?

Retention times storage per day gives the capacity requirement. PCI, HIPAA and state breach law all have opinions here and they are not optional.

Analytic or collector mode?

Collector mode ingests far faster but does not index for analysis. Large estates commonly run collectors at the edge feeding an analytic FortiAnalyzer at the centre.

Do you need it for SOC work?

FortiAnalyzer covers reporting and investigation well. Once you need cross-vendor correlation and UEBA, that is FortiSIEM's job; we will tell you which line you are on.

All FortiAnalyzer Logging and Analytics