Knowledge Hub · Security

Does FirstNet's FortiAnalyzer as a Service replace our SIEM?

Hosted Firewall & Network Security · Answered by FirstNet Technology Services

Short answer

No. FortiAnalyzer is the Fortinet-native analytics and reporting layer, sitting closer to your FortiGates and providing out-of-the-box compliance reports. If you already use Splunk or Sentinel, keep it; FirstNet can scope log forwarding to your SIEM separately.

In detail

How the work divides:

  • FortiAnalyzer as a Service: centralised log analytics, threat correlation, incident investigation and compliance reporting across your Fortinet devices
  • Your SIEM: correlation across all your security and IT sources, not only Fortinet
  • FortiManager, if FirstNet runs it too: policy revisions are cross-referenced in FortiAnalyzer reports, giving a change-and-evidence trail for audits

Neither FortiAnalyzer nor FortiManager is a SOC. For 24/7 analyst-led detection, FirstNet offers Sophos MDR with its own Incident Response team, and Sophos NG-SIEM is an option if you want to replace a legacy SIEM as part of a planned transformation.

If you do not have a SIEM, FortiAnalyzer as a Service may cover your Fortinet logging and reporting needs on its own, provided the storage bundle is sized for your log volume and retention period.

Source: FirstNet Hosted Firewall & Network Security service page →

Didn’t answer your question?

Call