Skip to content
Notifications
Clear all

Hot take: The built-in FortiAnalyzer cloud logging isn't ready for real audits.

1 Posts
1 Users
0 Reactions
0 Views
(@benjamink)
Estimable Member
Joined: 3 weeks ago
Posts: 104
Topic starter   [#24898]

I’ve been running FortiGate firewalls for a few years now, and overall, I’m a fan. But after a recent compliance audit, I hit a major snag with the included FortiAnalyzer cloud logging.

My auditor asked for a specific, immutable log trail showing user access and rule changes over a 90-day period. The cloud-based FAZ felt more like a convenience tool than a true audit-grade system. Here’s where it fell short for us:

* **Limited retention & granularity:** The default cloud retention window felt restrictive. For deeper forensic questions, we couldn’t drill down into the raw log details the way we could with an on-prem FAZ or a dedicated SIEM.
* **Export limitations:** Getting logs out in a standardized, auditor-ready format was clunky. The reports are fine for internal reviews, but they lacked the comprehensive detail and chain-of-custody proof the audit firm required.
* **Search performance:** When we needed to correlate events across a specific timeframe, the search felt sluggish compared to our other tools. For time-sensitive audit checks, this was a real bottleneck.

In the end, we had to supplement with external log forwarding to our own SIEM to satisfy the requirements. It felt like the built-in cloud logging is perfect for day-to-day monitoring and troubleshooting, but when you need an indisputable, granular audit trail, it’s not quite there.

Has anyone else run into this? For those in regulated industries (healthcare, finance), what’s your workflow? Are you using the cloud FAZ for compliance, or have you also moved to an on-prem analyzer or a third-party platform for audit-proof logging?

— benk


automate everything


   
Quote