FortiAnalyzer 1000G
660 GB of logs per day, 20,000 logs/sec in analytic mode
- GB logs / day
- 660
- Analytic rate
- 20,000 logs/sec
- Storage
- 8x 4 TB
The FortiAnalyzer 1000G ingests 660 GB of logs per day, sustaining 20,000 logs/sec in analytic mode and 30,000 logs/sec in collector mode, with 8x 4 TB of storage.
660 GB/day and 20,000 logs/sec analytic, a five-fold jump in ingest rate over the 810G for triple the daily volume, which tells you where it is aimed: bursty, inspection-heavy estates where the peak matters more than the average. Under-sizing shows up as dropped logs during precisely the incident you needed them for, which is the most expensive mistake available in the Fabric.
How to work out whether it fits
The arithmetic a datasheet leaves out. If any of it does not match your situation, that is worth a call rather than a guess.
The five-fold jump in ingest rate over the 810G for triple the daily volume tells you what this is for: bursty, inspection-heavy estates where the peak matters more than the average. Size on peak. Dropped logs during an incident is the failure mode here, and it is silent; you discover it when you go looking for the events and they are not there.
What to order alongside the FortiAnalyzer 1000G
The published threat protection figure for this model is measured with IPS, application control and malware protection all running. Those arrive as a FortiGuard subscription, so the bundle you choose decides whether the hardware can reach the number you sized it on. Every bundle already includes FortiCare Premium 24x7 support.
| Bundle | What it adds | 1 yearlist price | 3 yearslist price | 5 yearslist price |
|---|---|---|---|---|
| Enterprise ProtectionENT | The broadest bundle. Everything in UTP, plus the services that cover data, SaaS posture and attack-surface visibility, plus inline zero-day malware prevention. | on quote | on quote | on quote |
| Unified Threat ProtectionUTP | The traditional mid-tier: perimeter defence covering network, file, web and email threats. Everything most sites actually switch on. | on quote | on quote | on quote |
| Advanced Threat ProtectionATP | The narrow bundle: IPS and the full malware stack including cloud sandboxing, without the web and email filtering layers. | on quote | on quote | on quote |
These are Fortinet list prices. You will not pay them.
Every quote we write is discounted from list, and how far below depends on quantity, term and whether we register the deal with Fortinet. Longer terms also price better per year, which is why three and five year bundles are usually the better buy on a device you intend to keep through a refresh cycle. Part numbers follow Fortinet’s standard bundled convention; not every model carries every combination, so we confirm the exact orderable SKU before anything is placed.
FortiAnalyzer 1000G is number 4 of 7 in this family
Ranked on gb logs/day, the figure that separates these models. All values are Fortinet’s own and cited on each product page.
FortiAnalyzer 810G
200 GB/day
230% less than the FortiAnalyzer 1000G. Worth it only if your measured requirement genuinely fits inside it.
FortiAnalyzer 1000G
660 GB/day
7 models in this family span 25 GB/day to 8K GB/day.
FortiAnalyzer 3100G
3K GB/day
355% more headroom. Worth costing if you expect growth inside the refresh cycle, replacing early is dearer than buying up once.
Highlights
- 660 GB of logs per day
- 20,000 logs/sec analytic, 30,000 collector
- 8x 4 TB storage for real retention depth
Typical deployments
- Large campus and data-centre estates with full UTM logging
- Environments where peak log rate spikes hard during incidents
- Deployments consolidating several regional collectors
What this includes
Fortinet publishes no throughput table for this product; it is licensed per user, endpoint, workload or account. What follows is capability and sizing, not benchmarks.
Capacity
Analytic mode indexes for investigation and reporting; collector mode ingests faster but does not index. Large estates commonly run collectors at the edge feeding one analytic unit at the centre.
| GB logs/day | 660 |
|---|---|
| Analytic sustained rate (logs/sec) | 20,000 |
| Collector sustained rate (logs/sec) | 30,000 |
Hardware
| Total interfaces | 4x GE RJ45, 2x 25GE SFP28 |
|---|---|
| Storage capacity | 8x 4 TB |
Sources
- Fortinet Product Matrix (July 2026), retrieved 2026-09-01
- Fortinet Partner Portal price list, retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order; we will.