Short answer
No. FortiAnalyzer is the Fortinet-native analytics and reporting layer, sitting closer to your FortiGates and providing out-of-the-box compliance reports. If you already use Splunk or Sentinel, keep it; FirstNet can scope log forwarding to your SIEM separately.
In detail
How the work divides:
- FortiAnalyzer as a Service: centralised log analytics, threat correlation, incident investigation and compliance reporting across your Fortinet devices
- Your SIEM: correlation across all your security and IT sources, not only Fortinet
- FortiManager, if FirstNet runs it too: policy revisions are cross-referenced in FortiAnalyzer reports, giving a change-and-evidence trail for audits
Neither FortiAnalyzer nor FortiManager is a SOC. For 24/7 analyst-led detection, FirstNet offers Sophos MDR with its own Incident Response team, and Sophos NG-SIEM is an option if you want to replace a legacy SIEM as part of a planned transformation.
If you do not have a SIEM, FortiAnalyzer as a Service may cover your Fortinet logging and reporting needs on its own, provided the storage bundle is sized for your log volume and retention period.
Source: FirstNet Hosted Firewall & Network Security service page →
Didn’t answer your question?
