FortiAnalyzer 3100G
3,000 GB of logs per day, 42,000 logs/sec in analytic mode
- GB logs / day
- 3,000
- Analytic rate
- 42,000 logs/sec
- Storage
- 16x 4 TB HDD + 2x 1.92 TB SSD
The FortiAnalyzer 3100G ingests 3,000 GB of logs per day, sustaining 42,000 logs/sec in analytic mode and 60,000 logs/sec in collector mode, with 16x 4 TB HDD + 2x 1.92 TB SSD of storage.
3,000 GB/day with a hybrid 16x 4 TB HDD plus 2x 1.92 TB SSD layout, the SSD tier is what keeps search responsive at this volume, and it is the reason this is not simply a bigger 1000G. At three terabytes a day, retention arithmetic dominates the purchase: multiply your regulatory requirement by daily volume before comparing models.
How to work out whether it fits
The arithmetic a datasheet leaves out. If any of it does not match your situation, that is worth a call rather than a guess.
The hybrid HDD-plus-SSD layout is the reason this is not simply a bigger 1000G, the SSD tier keeps search responsive at three terabytes a day, and search performance is what determines whether anyone actually uses the system during an incident. Size on retention times daily volume, then check that the resulting index is still searchable at the speed your responders need.
What to order alongside the FortiAnalyzer 3100G
The published threat protection figure for this model is measured with IPS, application control and malware protection all running. Those arrive as a FortiGuard subscription, so the bundle you choose decides whether the hardware can reach the number you sized it on. Every bundle already includes FortiCare Premium 24x7 support.
| Bundle | What it adds | 1 yearlist price | 3 yearslist price | 5 yearslist price |
|---|---|---|---|---|
| Enterprise ProtectionENT | The broadest bundle. Everything in UTP, plus the services that cover data, SaaS posture and attack-surface visibility, plus inline zero-day malware prevention. | on quote | on quote | on quote |
| Unified Threat ProtectionUTP | The traditional mid-tier: perimeter defence covering network, file, web and email threats. Everything most sites actually switch on. | on quote | on quote | on quote |
| Advanced Threat ProtectionATP | The narrow bundle: IPS and the full malware stack including cloud sandboxing, without the web and email filtering layers. | on quote | on quote | on quote |
These are Fortinet list prices. You will not pay them.
Every quote we write is discounted from list, and how far below depends on quantity, term and whether we register the deal with Fortinet. Longer terms also price better per year, which is why three and five year bundles are usually the better buy on a device you intend to keep through a refresh cycle. Part numbers follow Fortinet’s standard bundled convention; not every model carries every combination, so we confirm the exact orderable SKU before anything is placed.
FortiAnalyzer 3100G is number 5 of 7 in this family
Ranked on gb logs/day, the figure that separates these models. All values are Fortinet’s own and cited on each product page.
FortiAnalyzer 1000G
660 GB/day
355% less than the FortiAnalyzer 3100G. Worth it only if your measured requirement genuinely fits inside it.
FortiAnalyzer 3100G
3K GB/day
7 models in this family span 25 GB/day to 8K GB/day.
FortiAnalyzer 3510G
5K GB/day
67% more headroom. Worth costing if you expect growth inside the refresh cycle, replacing early is dearer than buying up once.
Highlights
- 3,000 GB of logs per day
- 42,000 logs/sec in analytic mode
- 16x 4 TB HDD + 2x 1.92 TB SSD of onboard storage
- Reporting and retention for PCI DSS, HIPAA and state breach law
Typical deployments
- Very large enterprises with estate-wide inspection logging
- Long retention obligations under PCI DSS or HIPAA
- Central analytic tier behind multiple edge collectors
What this includes
Fortinet publishes no throughput table for this product; it is licensed per user, endpoint, workload or account. What follows is capability and sizing, not benchmarks.
Capacity
Analytic mode indexes for investigation and reporting; collector mode ingests faster but does not index. Large estates commonly run collectors at the edge feeding one analytic unit at the centre.
| GB logs/day | 3,000 |
|---|---|
| Analytic sustained rate (logs/sec) | 42,000 |
| Collector sustained rate (logs/sec) | 60,000 |
Hardware
| Total interfaces | 2x GE RJ45, 2x 25GE SFP28 |
|---|---|
| Storage capacity | 16x 4 TB HDD + 2x 1.92 TB SSD |
Sources
- Fortinet Product Matrix (July 2026), retrieved 2026-09-01
- Fortinet Partner Portal price list, retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order; we will.