Fortianalyzer: Single-Pane Orchestration, Automation & Response For
Fortianalyzer: Single-Pane Orchestration, Automation & Response For
Fortianalyzer: Single-Pane Orchestration, Automation & Response For
FortiAnalyzer
Security-Driven Analytics & Log Management
Key Features
Advanced Threat Detection & Correlation Security Fabric Analytics
allows Security & Network teams to § Event correlation across all logs and real-time anomaly
immediately identify and respond to network detection, with Indicator of Compromise (IOC) service and threat
Automated Workflows & Compliance § Correlates with logs from FortiClient, FortiSandbox, FortiWeb,
and FortiMail for deeper visibility and critical network insights
Reporting provides customizable
Enterprise-grade high availability
dashboards, reports and advanced workflow
§ Automatically back-up FortiAnalyzer DB’s (up to 4 node cluster)
handlers for both Security & Network teams
that can be geographically dispersed for disaster recovery
to accelerate workflows & assist with
Security automation
regulation and compliance audits.
§ Reduce complexity and leverage automation via REST API,
scripts, connectors, and automation stitches to expedite
Scalable Log Management collects logs security response
from FortiGate, FortiClient, FortiManager, Multi-tenancy and administrative domains (ADOMs)
FortiSandbox, FortiMail, FortiWeb,
§ Separate customer data and manage domains leveraging
FortiAuthenticator, Generic syslog and others. ADOMs to be compliant and operationally effective
Deploy as an individual unit or optimized for a Flexible deployment options & archival storage
specific operation and scale storage based § Supports deployment of appliance, VM, hosted or cloud. Use
on retention requirements. AWS, Azure or Google to archive logs as a secondary storage
DATA SHEET | FortiAnalyzer
Feature Highlights
Security Operations Center (SOC) Indicators of Compromise
FortiAnalyzer’s SOC (Security Operations Center) helps security The Indicators of Compromise (IOC) service identifies suspicious
teams protect networks with real-time log and threat data in the usage and artifacts observed on a network or in an operations
form of actionable views, notifications and reports. Analysts can system, determined with high confidence to be a computer
protect network, web sites, applications, databases, data centers, intrusion. FortiGuard’s IOC subscription provides intelligence
and other technologies, through centralized monitoring, awareness information to help security analysts identify risky devices and users
of threats, events and network activity. The predefined and custom based on these artifacts. The IOC package consisting of around
dashboards provide a single-pane-of-glass for easy integration 500K IOCs daily and delivers it via our Fortinet Developers Network
into your Security Fabric. The new FortiSOC service subscription, (FNDN) to our FortiSIEM, FortiAnalyzer, and FortiCloud products.
provides built-in Incident management workflows with playbooks Analysts can also re-scan historical logs for threat hunting and
and connectors to simplify the Security Analysts role with enhanced identify threats based on new intelligence, as well as review users’
security automation and orchestration. aggregated threat scores by IP addresses, hostname, group, OS,
overall threat rating, a location Map View, and a number of threats.
Incident Detection & Response
FortiAnalyzer’s Automated Incident Response capability enables
security teams to manage incident life cycle from a single view.
Analysts can focus on event management and identification
of compromised endpoints through default and customized
event handlers with quick detection, automated correlation and
connected remediation of Fortinet devices and syslog servers
with incident management and playbooks for quick assignment
of incidents for analysis. Track timelines and artifacts, with audit
history and incident reports, as well as streamlined integration
with ITSM platforms helps bridge gaps in your Security Operations
Center and reinforces your Security Posture.
Asset & Identity
Security Fabric assets and identity monitoring and vulnerability
tracking provides full SOC visibility and analytics of the attack
surface. Assets & Identity visibility and assets classification based
on telemetry from NAC. Built-in SIEM module for automated log
collection, normalization & correlation. Integrated with FortiSOAR
for further incident investigation and threat eradication. Support
export of incident data to FortiSOAR through the FortiAnalyzer
Connector and API Admin.
Reports
FortiAnalyzer Playbooks FortiAnalyzer provides 39+ built-in templates that are ready to use,
FortiAnalyzer Playbooks boost security teams abilities to simplify with sample reports to help identify the right report for you. You
efforts and focus on critical tasks. Out of the box playbook can generate custom data reports from logs by using the Reports
templates enable SOC analysts to quickly customize and automate feature. Run reports on-demand or on a schedule with automated
their investigation use cases to respond to compromised hosts, email notifications, uploads and an easy to manage calendar view.
critical intrusions, blocking C&C IPs, and more. Flexible playbook Create custom reports with the 700+ built-in charts and datasets
editor for hosts under investigation. FortiAnalyzer also allows ready for creating your custom reports, with flexible report formats
analysts to drill down to a playbook to review task execution details include PDF, HTML, CSV, and XML.
and edit playbooks to define custom processes and tasks, and
also includes built-in Connectors for playbooks to interact with
other Security Fabric devices like FortiOS and EMS.
2
DATA SHEET | FortiAnalyzer
Feature Highlights
Virtual Machines
FortiAnalyzer-VM-S
The new FortiAnalyzer Subscription license model consolidates the VM product SKU and the FortiCare Support SKU, as well as IOC and
FortiAnalyzer SOC (SOAR/SIEM) services into one single SKU, to simplify the product purchase, upgrade and renewal.
The FortiAnalyzer S-Series SKUs come in stackable 5, 50 and 500 GB/Day logs licenses, so that multiple units of this SKU can be
purchased at a time to increase the number of GB/Day logs. This SKU can also be purchased together with other FAZ VM-S SKUs to
expand the total number of GB/Day logs.
FortiAnalyzer-VM
FortiAnalyzer-VM integrates network logging, analysis, and reporting into a single system, delivering increased knowledge of security
events throughout a network. Utilizing virtualization technology, FortiAnalyzer-VM is a software-based version of the FortiAnalyzer hardware
appliance and is designed to run on many virtualization platforms. It offers all the features of the FortiAnalyzer hardware appliance.
FortiAnalyzer-VM provides organizations with centralized security event analysis, forensic research, reporting, content archiving, data
mining, malicious file quarantining and vulnerability assessment. Centralized collection, correlation and analysis of geographically and
chronologically diverse security data from Fortinet and third-party devices deliver a simplified, consolidated view of your security posture.
3
DATA SHEET | FortiAnalyzer
Specifications
FORTIANALYZER VIRTUAL APPLIANCES FAZ-VM-BASE FAZ-VM-GB1 FAZ-VM-GB5 FAZ-VM-GB25 FAZ-VM-GB100 FAZ-VM-GB500 FAZ-VM-GB2000
Capacity and Performance
GB/Day of Logs 1 incl.* +1 +5 +25 +100 +500 +2,000
Storage Capacity 500 GB +500 GB +3 TB +10 TB +24 TB +48 TB +100 TB
Devices/VDOMs (Maximum) 10,000 10,000 10,000 10,000 10,000 10,000 10,000
FortiGuard Indicator of Compromise (IOC)
Hypervisor Requirements
Hypervisor Support VMware ESX/ESXi 5.0/5.1/5.5/6.0/6.5/6.7, Microsoft Hyper-V 2008 R2/2012/2012 R2/2016, Citrix XenServer 6.0+ and Open Source Xen 4.1+,
KVM on Redhat 6.5+ and Ubuntu 17.04, Nutanix AHV (AOS 5.10.5), Amazon Web Services (AWS), Microsoft Azure, Google Cloud (GCP), Oracle Cloud
Infrastructure (OCI), Alibaba Cloud (AliCloud)
Network Interface Support (Minimum / Maximum) 1/4
vCPUs (Minimum / Maximum) 2 / Unlimited
Memory Support (Minimum / Maximum) 4 GB / Unlimited
* Sustained Rate - maximum constant log message rate that the FAZ platform can maintain for minimum 48 hours without SQL database and system performance degradation.
**is the max number of days if receiving logs continuously at the sustained analytics log rate. This number can increase if the average log rate is lower.
4
DATA SHEET | FortiAnalyzer
Specifications
* Sustained Rate - maximum constant log message rate that the FAZ platform can maintain for minimum 48 hours without SQL database and system performance degradation.
**is the max number of days if receiving logs continuously at the sustained analytics log rate. This number can increase if the average log rate is lower.
5
DATA SHEET | FortiAnalyzer
Specifications
* Sustained Rate - maximum constant log message rate that the FAZ platform can maintain for minimum 48 hours without SQL database and system performance degradation.
** is the max number of days if receiving logs continuously at the sustained analytics log rate. This number can increase if the average log rate is lower.
*** 3700F must connect to a 200V - 240V power source.
6
DATA SHEET | FortiAnalyzer
Order Information
Product SKU Description
FortiAnalyzer 200F FAZ-200F Centralized log and analysis appliance — 2 x RJ45 GE, 4 TB storage, up to 100 GB/day of logs.
FortiAnalyzer 300F FAZ-300F Centralized log and analysis appliance — 2 x RJ45 GE, 8 TB storage, up to 150 GB/day of logs.
FortiAnalyzer 400E FAZ-400E Centralized log and analysis appliance — 4 x GE RJ45, 12 TB storage, up to 200 GB/day of logs.
FortiAnalyzer 800F FAZ-800F Centralized log and analysis appliance — 4 x GE, 2 x SFP, 16 TB storage, up to 300 GB/day of logs.
FortiAnalyzer 1000F FAZ-1000F Centralized log and analysis appliance — 2 x 10GE RJ45, 2 x 10GbE SFP+, 32 TB storage, dual power supplies, up to
660 GB/day of logs.
FortiAnalyzer 2000E FAZ-2000E Centralized log and analysis appliance — 4 x GE RJ45, 2 x SFP+, 36 TB storage, dual power supplies, up to 1,000 GB/
day of logs.
FortiAnalyzer 3000F FAZ-3000F Centralized log and analysis appliance — 4 x GE RJ45, 2 x SFP+, 48 TB storage, dual power supplies, up to 3,000 GB/
day of logs.
FortiAnalyzer 3500G FAZ-3500G Centralized log and analysis appliance — 2 x GbE RJ45, 2 x SFP28, 96 TB storage, dual power supplies, up to
5,000 GB/day of logs.
FortiAnalyzer 3700F FAZ-3700F Centralized log and analysis appliance — 2 x SFP+, 2 x 1GE slots, 240 TB storage, up to 8,300 GB/day of logs.
FortiAnalyzer-VM FAZ-VM-BASE Base license for stackable FortiAnalyzer-VM; 1 GB/Day of Logs and 500 GB storage capacity. Unlimited GB/Day when
used in collector mode only. Designed for all supported platforms.
FAZ-VM-GB1 Upgrade license for adding 1 GB/Day of Logs and 500 GB storage capacity.
FAZ-VM-GB5 Upgrade license for adding 5 GB/day of logs and 3 TB storage capacity.
FAZ-VM-GB25 Upgrade license for adding 25 GB/day of logs and 10 TB storage capacity.
FAZ-VM-GB100 Upgrade license for adding 100 GB/day of logs and 24 TB storage capacity.
FAZ-VM-GB500 Upgrade license for adding 500 GB/day of logs and 48 TB storage capacity.
FAZ-VM-GB2000 Upgrade license for adding 2 TB/Day of Logs and 100 TB storage capacity.
FortiAnalyzer-VM Subscription License with Support FC1-10-AZVMS-431-01-DD Central Logging & Analytics subscription for 5 GB/Day logs. Include 24x7 FortiCare support, IOC, SOAR/SIEM services.
FC2-10-AZVMS-431-01-DD Central Logging & Analytics subscription for 50 GB/Day logs. Include 24x7 FortiCare support, IOC, SOAR/SIEM services.
FC3-10-AZVMS-431-01-DD Central Logging & Analytics subscription for 500 GB/Day logs. Include 24x7 FortiCare support, IOC, SOAR/SIEM services.
FortiAnalyzer - Backup to Cloud Service FC-10-FAZ00-286-02-DD 1 year subscription to FortiAnalyzer storage connector service for 10TB data transfer to public cloud.
FortiGuard Indicator of Compromise (IOC) Subscription FC-10-[Model code] -149-02-DD 1 Year Subscription license for the FortiGuard Indicator of Compromise (IOC).
Enterprise Protection Bundle FC-10-[Model code]-432-02-DD Enterprise Protection (24x7 FortiCare plus Indicators of Compromise Service and SOC Subscription license)
FortiAnalyzer SOC Subscription FC-10-[Model code]-335-02-DD Subscription license for the FortiAnalyzer SOC component
www.fortinet.com
Copyright © 2020 Fortinet, Inc. All rights reserved. Fortinet®, FortiGate®, FortiCare® and FortiGuard®, and certain other marks are registered trademarks of Fortinet, Inc., and other Fortinet names herein may also be registered and/or common law
trademarks of Fortinet. All other product or company names may be trademarks of their respective owners. Performance and other metrics contained herein were attained in internal lab tests under ideal conditions, and actual performance and other results
may vary. Network variables, different network environments and other conditions may affect performance results. Nothing herein represents any binding commitment by Fortinet, and Fortinet disclaims all warranties, whether express or implied, except to
the extent Fortinet enters a binding written contract, signed by Fortinet’s General Counsel, with a purchaser that expressly warrants that the identified product will perform according to certain expressly-identified performance metrics and, in such event,
only the specific performance metrics expressly identified in such binding written contract shall be binding on Fortinet. For absolute clarity, any such warranty will be limited to performance in the same ideal conditions as in Fortinet’s internal lab tests.
Fortinet disclaims in full any covenants, representations, and guarantees pursuant hereto, whether express or implied. Fortinet reserves the right to change, modify, transfer, or otherwise revise this publication without notice, and the most current version
of the publication shall be applicable. Fortinet disclaims in full any covenants, representations, and guarantees pursuant hereto, whether express or implied. Fortinet reserves the right to change, modify, transfer, or otherwise revise this publication without
notice, and the most current version of the publication shall be applicable.
FST-PROD-DS-FAZ FAZ-DAT-R55-202006