Fortinet FortiAnalyzer Cloud
Enhance Visibility with Cloud-based Network Analytics
Click here to jump to more pricing!
Overview:
The challenges of increasingly complex and naturally fragmented infrastructures continue to enable a rise in cyber events and network outages. Too many point products deployed by most enterprises almost always operate in isolated silos with their own consoles are narrow and only relevant for that one product. Subsequently, network operations teams rarely have clear and consistent insight into what across the infrastructure.
Real-time and comprehensive network visibility is not easy—especially as enterprises add on an increasing number of point products to already complex infrastructures. As network teams consolidate point products and leverage FortiOS for intrusion prevention (IPS), NGFW, SD-WAN, SD-Branch, and other functions, they can easily share telemetry data between all deployments and enable real-time visibility of network anomalies.
FortiAnalyzer Cloud offers customers a SaaS based delivery option for automation-driven, single pane analytics, providing log management, analytics and reporting for Fortinet NGFW and SD-WAN with an easily accessible cloud-based solution.
FortiAnalyzer Cloud delivers reliable real-time insights into network activity with extensive reporting and monitoring for clear, consistent visibility of an organizations security posture.
With the FortiCloud Premium subscription customers can easily enable the FortiAnalyzer Cloud service with the 360 Protection bundle or by purchasing it a-la-carte, producing analytics for Fortinet Security Fabric devices and users.
Customers and Partners can easily access their FortiAnalyzer Cloud from their FortiCloud Single-Sign-On Portal.
FortiAnalyzer Cloud provides the following key benefits:
- Single Sign-on Portal for logging and reporting for Fortinet NGFW and SD-WAN
- Cloud-based logging and alerting for network analytics and response
- Extensive Reporting templates for streamlined reporting
FortiAnalyzer
FortiAnalyzer is a powerful log management, analytics and reporting platform, providing organizations with Single-Pane Orchestration, Automation, and Response for simplified security operations, proactive identification and remediation of risks, and complete visibility of the entire attack surface.
FortiAnalyzer, integrated with Fortinet’s Security Fabric, provides advanced threat detection capabilities, centralized security analytics, and complete end-to-end security posture awareness and control, helping security teams identify and eliminate threats before a breach can occur.
Orchestrate security tools, people and process for streamlined execution of tasks and workflows, incident analysis and response, and rapidly expedite threat detection, case creation & investigation, and mitigation and response.
Automate workflows and trigger actions with fabric connectors, playbooks and event handlers to accelerate your network security team’s ability to respond to critical alerts and events, as well as SLA’s for regulation and compliance.
Respond in real-time to network security attacks, vulnerabilities and warnings of potential compromises, with threat intelligence, event correlation, monitoring, alerts and reporting for immediate tactical response and remediation.
Key Features
- Security Fabric Analytics with event correlation and real-time detection across all logs, with Indicators of Compromise (IOC) service and detection of advanced threats
- Fortinet Security Fabric integration with FortiGates, FortiClient, FortiSandbox, FortiWeb, FortiMail, and others for deeper visibility and critical network insights
- Enterprise-grade High Availability to automatically back-up FortiAnalyzer databases (up to four node cluster), which can be geographically dispersed for disaster recovery
- Security Automation to reduce complexity, leveraging REST API, scripts, connectors, and automation stitches to expedite security response and reduce time-to-detect
- Multi-Tenancy solution with quota management, leveraging (ADOMs) to separate customer data and manage domains for operational effectiveness and compliance
- Flexible deployment options as appliance, VM, hosted, or public cloud. Use AWS, Azure, or Google for cloud secondary archival storage
Feature Highlights:
Incident Detection and Response
Centralized NOC/SOC Visibility for the Attack Surface
The FortiSOC view helps teams in the security operations center (SOC) and network operations center (NOC) protect networks with access to real-time log and threat data in the form of actionable views with deep drill-down capabilities, notifications & reports, and predefined or customized dashboards for single-pane visibility and awareness. Analysts can utilize FortiAnalyzer’s workflow automation for simplified orchestration of security operations, management of threats and vulnerabilities, and responding to security incidents, or investigate proactively by looking for anomalies and threats in SIEM normalized logs in the Threat Hunting view.
Event Management
FortiAnalyzer’s Event Manager enables security teams to monitor and manage alerts and events from logs. Events are processed and correlated in an easily readable format that analysts can understand for immediate response. Analysts can use the Event Monitor for investigative searches into alerts, and use the predefined or custom event handlers for NOC and SOC, with customizable filters to generate realtime notifications for around-the-clock monitoring, including handlers for SD-WAN, VPN SSL, wireless, network operations, FortiClient, and more.
Incident Management
The Incidents component in FortiSOC enables security operations teams to manage incident handling and life cycle with incidents created from events to show affected assets, endpoints and users. Analysts can assign incidents, view and drill down on event details, incident timelines, add analysis comments, attach reports and artifacts, and review playbook execution details for complete audit history.
Integrate with FortiSOAR for further incident investigation and threat eradication including support to export incident data to FortiSOAR through the FortiAnalyzer fabric connector (enabled on FortiSOAR with API Admin setup).
Playbook Automation
FortiAnalyzer Playbooks boost an organization’s security team’s abilities to simplify investigation efforts through automated incident response, freeing up resources and allowing analysts to focus on more critical tasks.
Out of the box playbook templates enable SOC analysts to quickly customize their use cases, including playbooks for investigation of compromised hosts, infections and critical incidents, data enrichment for Fabric View Assets & Identity views, blocking of malware, C&C IPs, and more. Security teams can define custom processes, edit playbooks and tasks in the visual playbook editor, utilize the Playbook monitor to review task execution details, import or export playbooks, and use built-in connectors for allowing playbooks to interact with other Security Fabric devices like FortiOS and EMS. The new connector health check provides an indicator for verifying that connectors are always up and working.
Security Services
Include the FortiSOC subscription to enable further automation for incident response with enhanced alert monitoring and escalation, built-in incident management workflows, connectors, and many more FortiSOC playbooks.
The FortiGuard Indicators of Compromise subscription empowers security teams with forensic data from 500,000 IOCs daily, used in combination with FortiAnalyzer analytics to identify suspicious usage and artifacts observed on the network or in an operations system, that have been determined with high confidence to be malicious infections or intrusions, and historical rescan of logs for threat hunting.
The Shadow IT monitoring service provides continuous monitoring usage of unapproved devices and resources, and unsanctioned accounts and unauthorized use of SaaS and IaaS, API integration, third party apps, and rogue users using personal accounts for managing company assets.
The FortiGuard Outbreak alert service provides an automatic download of content packages with resources for detecting the latest malware and threats, including views for summary of outbreaks, kill chain mapping for how the malware works, FortiGate coverage explains what FortiGate components and services will block the threats, and Fabric Coverage for leveraging the full Fabric security protection.
Security Fabric Analytics
Analytics and Reporting
Security teams are empowered with FortiAnalyzer’s automation driven analytics and reports providing full visibility of network devices, systems, and users.
FortiAnalyzer delivers correlated log data with threat intelligence for analysis of real-time and historical events, providing context and meaning to network activity, risks, and vulnerabilities, attack attempts, operational anomalies, and continuous monitoring of sanctioned and unsanctioned user activity and investigation of Shadow IT.
Assets and Identity
FortiAnalyzer’s Fabric View with Asset and Identity monitoring provides full SOC visibility of users and devices, including analytics of the attack surface and enables analysts to view and manage detailed UEBA information collected from logs and fabric devices, with filters and custom views for refining results.
The Assets & Identity views provide security teams with elevated visibility into an organization’s endpoints and users with correlated user and device information, vulnerability detections, and EMS tagging and asset classifications through telemetry with EMS, NAC, and Fortinet Fabric Agent.
FortiView is a comprehensive monitoring solution that provides multilevel views and summaries of real-time critical alerts and information such as top threats and IOCs to your network including Botnet and C&C, top sources/destinations of network traffic, top applications, websites and SaaS, VPN and System information, and other Fabric device intelligence.
Monitors view provides operations teams with customizable NOC and SOC dashboards and widgets designed for display across multiple screens in the Operations Center. Monitor events in real-time through the pre-defined dashboard views for SD-WAN, VPN, WiFi, Incoming/Outgoing Traffic, Applications and Websites, FortiSandbox Detections, Endpoint Vulnerabilities, Software Inventory, Threats, Shadow IT (monitoring service), Fabric State, and many more.
Analysts can expand their investigation in Log View, with easy navigation of managed device logs using search filters, log drill down, formatted or raw logs, log import/export, as well as define custom views and create log groups. With a FortiSOC license, a SIEM database is automatically created to store normalized logs for devices in Fabric ADOMs.
FortiAnlayzer Reports
FortiAnalyzer provides over 60 report templates, 800+ datasets and 750+ charts that are ready-to-use with sample reports, including reports for Secure SDWAN, VPN monitoring, Threat Assessments, 360 Security Reviews, Situational Awareness, Self-harm and Risk Indicators, Bandwidth and Applications, FortiClient, FortiMail, FortiSandbox, FortiDeceptor, compliance, and many others.
Analysts can easily customize, clone and modify Reports to their needs with filters by device, subnets and type to deliver specific business metrics to target stakeholders. Schedule reports to run at non-peak hours or run on demand; define output profiles for notifications and deliver reports in flexible viewing formats including PDF, HTML, CSV, and XML.
Services:
FortiGuard Security Subscription Services
FortiGuard Security Subscription Services deliver dynamic, automated updates for Fortinet products. The Fortinet Global Security Research Team creates these updates to ensure up-to-date protection against sophisticated threats. Subscriptions include antivirus, intrusion prevention, web filtering, antispam, vulnerability and compliance management, application control, and database security services.
FortiCare Support Services
FortiCare Support Services provide global support for all Fortinet products and services. FortiCare support enables your Fortinet products to perform optimally. Support plans start with 8x5 Enhanced Support with "return and replace" hardware replacement or 24x7 Comprehensive Support with advanced replacement. Options include Premium Support, Premium RMA, and Professional Services. All hardware products include a 1-year limited hardware warranty and 90-day limited software warranty.
Documentation:
Download the Fortinet FortiAnalyzer Series Datasheet (PDF).
Pricing Notes:
- Pricing and product availability subject to change without notice.