FortiManager & FortiAnalyzer
FortiAnalyzer
Security Operations
Security
Operations
© Fortinet Inc. All Rights Reserved. 2
FortiAnalyzer: Log Management, Analytics, & Reporting
What is it?
Datacenter Log Management, Analytics, and Reporting
SDN
FortiAnalyzer provides organisations with a powerful log management, analytics, and reporting
platform, enabling a single console to centrally view and manage logs from Fortinet devices.
Branch
Log Aggregation and Forwarding
By centralising logs from Fortinet devices, it enables FortiAnalyzer to forward the information
Campus
onto 3rd party systems, such as a SIEM, to integrate with vendor tooling.
Home
Reporting
Colocation
Private
FortiAnalyzer contains a rich reporting engine with many out of the box reports, enabling Cloud
organisations to gain deep insights into the state of their network.
OT
FortiAnalyzer
Compliance Security Incident
FortiView Log View Security
Reporting Automation & Events
© Fortinet Inc. All Rights Reserved. 3
Simplified Operations with FortiAnalyzer
Normalized Data Analytics with ML to detect
incidents across the Fortinet Security Fabric
Fabric Visibility
Fabric Response Automation
TI & Rules Detect Known Attacks
SOCaaS for Staff Augmentation
© Fortinet Inc. All Rights Reserved. 4
Real Time Monitoring
FortiView
Eliminate Blind spots
• FortiAnalyzer simplifies the
complexity of analyzing and
monitoring
• Gain end-to-end visibility,
helping you to identify and
eliminate threats
• Detect top threats, destinations,
and a consolidated timeline of
incidents over time
© Fortinet Inc. All Rights Reserved. 5
Network, Server & Application Monitoring
Fortinet devices
Windows & Linux
NGINX
Apache Server
Import custom parser Correlation Analytics
FortiAnalyzer
Security
Reporting Alerting Operations
© Fortinet Inc. All Rights Reserved. 6
Turnkey Reporting – 1000’s Readily Available
hundreds of pre-built reports & templates which are regulation-specific
Maximize Investments
• Fully customizable out-of-the-
box reporting to highlight areas
of improvement and progress
• Automate Compliance & Mitigate
Misconfigurations
• Monitor Benchmarks & Milestones
• PCI / SAR Reports
© Fortinet Inc. All Rights Reserved. 7
Monitor Application Risk and Control
Log Correlation
Improve Operations
• Monitor web traffic, applications,
users, and threats
• Drill down to user browsing
habits and infected hosts
• 360 Security Report
Brings visibility and insights to
entire attack surface
• Highlight all detected threats for
response
© Fortinet Inc. All Rights Reserved. 8
SD-WAN Reporting & Analytics
Realtime Network Insights
BUSINESS DRIVERS
Measure and Identify Security &
Network Risks in Real-time
KEY FEATURES
• Network Health Visibility
• Realtime SLA Reporting
• Historic SLA Reporting
• SD-WAN Reports
• Application Usage Reports &
Dashboards
• Adaptive Response Handlers
© Fortinet Inc. All Rights Reserved. 9
Advanced Threat Detection
Indicators of compromise & Outbreak Detection subscription services coat protection of the enterprise
IOC service within
IoC Subscription FortiAnalyzer
• Fortinet has over 3 million FortiAnalyzer
sensors deployed around the
world to provide customers with
early warning.
• IOC daily package are delivered
to FortiAnalyzer that can
Send Logs to FortiAnalyzer
complete historic rescans for
constant detection providing an
added layer of defense.
Ransomware Delivery
FsoerrvteiC
© Fortinet Inc. All Rights R e d. lient Ransomware 29
Real Time Threat Hunting
Log Correlation
Proactive Security
Posture
Advanced correlation and
analysis to hunt threats
• 16 critical elements for SOC to gain
insights
• Flexible search options
• Global filter to quickly pick up
IOCs
• Interactive time-based log traffic
graph
© Fortinet Inc. All Rights Reserved. 11
Incident Management
Incident's component enables security
operations team to manage incident life
cycle from a single view:
• View Incident details
• Affected endpoint & user
• Incident timeline & artifacts
• Playbook execution details
• Show/Hide Audit History
• Incident attachments (e.g., events and
reports)
• Post Collaboration comments
• Assign Incident for investigation
• Send notifications
© Fortinet Inc. All Rights Reserved. 12
Integrated and Automated
Playbook Connectors
Built-in Connectors for playbooks to interact
with other Security Fabric devices to enrich
incidents with more data and leverage
FortiOS automation framework for Incident
containment.
Current Support:
• EMS Connector
• FOS Connector
• FML Connector
• FCASB connectors
• FAZ built-in Connectors
• FortiGuard Connector
© Fortinet Inc. All Rights Reserved. 13
Fortinet Security Fabric Automation
FortiGate FortiSwitch
Internet
IP Ban /
Other stitches Protected
Endpoints
Automation
TIDB Logs
Stitch
Updates triggered
(API call)
Infected
Endpoints
FortiAnalyzer
Event
detected
© Fortinet Inc. All Rights Reserved. 14
Real Time Network Analysis & Automated Response
Security Fabric Automation
• Build your own FortiGate
Handlers to trigger Automation.
• For sub-second Detection and
Enforcement on FortiGate(s)
e.g., IPBan, CLI Scripts …
© Fortinet Inc. All Rights Reserved. 15
FortiAnalyzer Fabric Integration
Extensive Integration Across the Security Fabric
FortiGate FortiDeceptor FortiDDoS
FortiSOAR FortiAuthenticator FortiSandbox
FortiInsight FortiClient FortiADC
FortiNAC FortiWLC FortiMail
FortiSIEM
FortiEDR FortiTester
FortiAnalyzer
© Fortinet Inc. All Rights Reserved. 16
Follow The Sun Approach
Global Response Teams
SOC
99.99% 24x7x365 Unlimited FortiGate & Security Fast & Simple
Availability Service Hours Log Capacity Fabric logs Onboarding
Data Center
Ingest Log Data
Disaster Recover
Frankfurt
Burnaby Prague
Ottawa Germany
Canada Czechia
San Jose Canada Singapore
US Toyko
Japan
Critical Escalation Times
P1, Priority 1: 15 minutes P3, Priority 3: 90 minutes
P2, Priority 2: 45 minutes P4, Priority 4: 6 hours
© Fortinet Inc. All Rights Reserved. 17
Fortinet’s Turnkey Staff Augmentation Solution – SOCaaS
Take Back Your Time Act When Needed Maximize Investment
• Supplement FortiGate log and • Escalation of confirmed issues • Fully customizable out-of-the-
alert monitoring and triage with in as little as 15min box reporting to highlight areas
Fortinet security experts of improvement and progress
• Step-by-step instruction on:
• Reduce employee burnout and - What has happened • Quarterly meetings with
recapture critical work cycles - Why Fortinet to discuss events,
- Impact
hardening tips, and overall
- Steps to remediate
• 24 x 7 global coverage with live improvement
human experts • Live support for any questions
© Fortinet Inc. All Rights Reserved. 18
Fortinet’s Turnkey Solution – SOCaaS
Rapidly gain analyst support, alert monitoring and triage to your businesses
Take Back Your Time
• Supplement FortiGate log and
alert monitoring and triage with
Fortinet security experts
• Reduce employee burnout and
recapture critical work cycles
• 24 x 7 global coverage with live
human experts
© Fortinet Inc. All Rights Reserved. 19
Hardware Appliance
BoM FortiAnalyzer HW
FORTIANALYZER (HW model)
+
24x7 FortiCare / Enterprise Protection
+
Security Services / Add ON
+
Extras (ex. SFP/SFP+)
+
Premium RMA
© Fortinet Inc. All Rights Reserved. 21
Ex_1 :1x FAZ-300G + Enterprise + PRMA 30110-001
Qty SKU (DD=12/36/60) Description
Centralized log & analysis appliance - 4x GE RJ45, 8TB
1 FAZ-300G
storage, up to 100GB/Day of logs.
Enterprise Protection (24x7 FortiCare plus Indicators of
1 FC-10-L03HG-466-02-DD Compromise Service, SOC Subscription license, and
FortiGuard Outbreak Detection service)
4-Hour Hardware and Onsite Engineer Premium RMA Service
1 FC-10-L03HG-212-02-DD
(Requires 24x7 or ASE FortiCare)
© Fortinet Inc. All Rights Reserved. 22
Virtual Machine
Trial License
[Link]
© Fortinet Inc. All Rights Reserved. 24
FortiAnalyzer VM-Series
Perpetual Subscription
Upgrade license – stackable License + Services – stackable
1 GB/Day 5 GB/Day
5 GB/Day 50 GB/Day
25 GB/Day 500 GB/Day
100 GB/Day
500 GB/Day
2000 GB/Day
+ Add On Services – Range (Not “Stackable”)
+ 24x7 Forticare – Range (Not “Stackable”)
A restrição de armazenamento de logs via licenciamento foi removido da pricelist de Q3/2022 e nas versões FAZ 7.0.4 e 7.2.1
O uso de storage é ilimitado com o máximo de 15 discos por VM
© Fortinet Inc. All Rights Reserved. 25
BoM FortiAnalyzer VM
Perpetual Subscription
FortiAnalyzer VM Subscriptrion Bundle
FortiAnalyzer VM (GB/Day - Stack)
(GB/Day - Stack)
+ +
24x7 Forticare (Range Gb/Day) ADOM License for FortiAnalyzer
+
Security Services / Add ON (Range Gb/Day)
© Fortinet Inc. All Rights Reserved. 26
Ex. 1: 5GB/Day
Perpetual License
Qty SKU (DD=12/36/60) Description
1 FAZ-VM-GB5 Upgrade license for adding 5 GB/Day of Logs.
1 FC1-10-LV0VM-248-02-DD 24x7 FortiCare Contract (for 1-6 GB/Day of Logs)
© Fortinet Inc. All Rights Reserved. 27