
This is first video introduction to FortiAnalyzer , also kindly download Step by step workbook for this course attached under this video Resources also the require Lab EVE-NG Images and topology .
Learn how to upload switch images to eve-ng using WinSCP over sftp, extract them, place them in the eve-ng image directory, apply permissions, and configure l2 and l3 switches.
Upload ready-made lab images for EVE-NG, including FortiGate firewall, FortiAnalyzer, 40 Manager, Linux Lake, Linux Tiny Core, and Pfsense, to build and test a complete Fortinet lab topology.
Construct a FortiAnalyzer lab in EVE-NG with a detailed topology, management subnet IP schema, and multiple FortiGate firewalls to practice Fortinet NSE5 FortiAnalyzer v7.2 training.
Export the lab topology in eve-ng, import it into the community edition, adjust the management cloud and ip schema, upload required images, wipe and start the FortiGate topology.
Perform the initial configuration of three firewalls (HQ, DC, branch), setting hostnames, management interfaces, DNS, and WAN/LAN interfaces, then automate with a script and verify access via management IPs.
Configure SD-WAN across HQ, DC, and branch firewalls with two-member and single-member setups, add static routes, adjust load balancing, enable health checks, and define firewall policies for monitoring via FortiAnalyzer.
Configure six lab clients across HQ, DC, and branch subnets with static IPs, gateways, and DNS, then verify connectivity using ifconfig and ping to gateway and internet.
Configure Windows Server 2012 in the lab with Active Directory, DNS, and two interfaces named lane and management, then disable the firewall to enable remote desktop.
Explore the FortiAnalyzer GUI, including device manager, logs, and reports. Learn to add devices, create groups, view logs, and monitor dashboards and system settings.
Take and verify backups for HQ, DC, and branch firewalls via graphical and CLI methods, preserving configurations, revisions, and 40 analyzer backups to enable quick restoration or factory resets.
Examine administrator accounts on FortiAnalyzer, including local and remote authentication (ldap, radius, tacacs, pki), admin profiles (superuser, standard, restricted, no-permission), and trusted host login restrictions.
Configure DNS in the lab by setting up forward and reverse lookup zones and host records for HQ, DC, branch firewalls, and FortiAnalyzer; verify with nslookup.
Create an organization unit named fg in Active Directory, then create test groups (sales, hr, it, support, admin) and test users, and assign members to these groups for later use.
Create and assign administrator profiles, including restricted and super user, to local or remote admins, and test access restrictions, cloning, deleting, and login lockout settings.
Learn how administrative domains (adoms) organize FortiAnalyzer devices into separate logical environments, enable them, and manage with normal or advanced mode while allocating per-adom logs and storage.
Register Fortinet devices to FortiAnalyzer using device wizard with serial number or pre-shared key. Authorize devices via fabric connector or remote logging, and consider clustering for multiple FortiGate units.
Register a FortiGate HQ firewall with FortiAnalyzer 40 analyzer using the serial number in a lab topology, configure security fabric and real-time log forwarding via fabric connector.
Learn how to add FortiGate firewall through Security Fabric, register devices with FortiAnalyzer, and complete the authorization process via Fabric Connector and root Adams workflow.
Register a FortiGate firewall with FortiAnalyzer through log settings by enabling logs, entering the FortiAnalyzer IP address, and authorizing the device under the root Adams, then proceed.
Learn how to register a HQ firewall with FortiAnalyzer using a pre-shared key, covering device manager steps, port analyzer registration, log settings activation, and the CLI set pre-shared key command.
Upgrade FortiAnalyzer firmware by downloading the correct image from the Fortinet support portal, backing up configurations, uploading the image, and rebooting to verify the new version.
Perform and verify FortiAnalyzer backups and restores using both GUI and CLI. Learn to create encrypted or unencrypted backups, download them, and restore configurations to a previous state.
Learn how FortiAnalyzer collects and analyzes logs from FortiGate devices, separating traffic, security, and event logs, then decompresses, indexes, and archives them for real-time and historical insights.
Learn to use FortiAnalyzer device manager to add, authorize, and group Fortinet devices (including FortiGate firewalls), and monitor real-time log collection, while organizing devices into groups for streamlined management.
Generate and monitor traffic across HQ to DC and remote sites to produce firewall, security, and traffic logs sent to FortiAnalyzer, while enabling VPNs and security profiles.
Navigate FortiView’s two-part interface, FortiView and monitor, to analyze traffic and security logs with real-time and historical data. Filter by user, IP, and time, and view top sources and threats.
Analyze top threats, DNS logs, and traffic with FortiView and FortiView Monitor in FortiAnalyzer, tracking VPN activity, cloud applications, and top sources and destinations, with export to PDF.
Learn to use log view to display, filter, download, and import logs from multiple devices, create views, and manage log groups and log browse for traffic, security, and event logs.
Summarize log view and log browse in FortiAnalyzer, filter real-time traffic logs, create custom views for ping, dns, ntp, and manage archiving and grouping.
Explore FortiSoC in Fortinet FortiAnalyzer training, covering security orchestration, automation and response, incident management with playbooks, and the use of dashboards and connectors for automated responses.
Create and enable a FortiSoC automation playbook from a critical intrusion template to generate incidents, events, and reports from IPS activity in FortiAnalyzer.
Navigate the FortiSoC event monitor to view and filter all device events by endpoint, thread, or system. Create custom views, apply severity filters, and manage incidents.
Explain how FortiAnalyzer reports summarize large log data into readable, graphical formats using templates, charts, macros, and datasets, including predefined and custom reports.
Learn to generate predefined reports in FortiAnalyzer by editing definitions, adjusting time frames and devices, setting schedules, and exporting HTML or PDF with VPN, admin, and system event data.
Learn how to schedule FortiAnalyzer reports by selecting a report, enabling the schedule, and setting daily, weekly, or monthly timings, then verify automation in the report calendar.
Learn to configure FortiAnalyzer to send reports by email and upload copies via FTP, SFTP, or SCP, using SMTP mail server setup and output profiles, with optional scheduling.
Explore system settings to configure the port analyzer, including dashboard, network (DNS and routing), log forwarding, high availability, SNMP, and task monitoring.
Set up disk utilization for analytics and archive logs, allocate space per Adams, define analytics to archive ratio, set retention days, and enable alerts with automatic deletion.
Learn how FortiAnalyzer log rolling compresses and archives logs when the 200 MB limit or a scheduled time is reached, with delete after upload and FTP/SCP uploads and gzip.
Configure automatic deletion of device log, quarantine, report, and content archive files after a set period, with daily, weekly, or monthly checks via system settings in file management.
Manage and troubleshoot FortiAnalyzer logs using the log receive monitor to track receive rate, NZ rate, and lag time, and verify log flow with port analyzer diagnostic commands.
Master Centralized Logging, Analytics & Reporting Across Fortinet Security Devices
This course teaches you the complete fundamentals and practical skills needed to deploy, manage, and optimize FortiAnalyzer, Fortinet’s powerful centralized logging, analytics, and reporting platform. You will learn how to collect logs from multiple FortiGate devices, analyze security events, generate detailed reports, and segment your environment using ADOMs — all through clear explanations and hands‑on demonstrations.
FortiAnalyzer provides real‑time visibility into your entire security infrastructure. With it, you can monitor threats, track user activity, analyze bandwidth usage, review VPN sessions, audit security events, and generate management‑ready reports. This course shows you how to use FortiAnalyzer effectively in real enterprise environments.
What You Will Learn
Fundamentals of centralized log collection and analysis
Deploying and integrating FortiAnalyzer with FortiGate devices
Understanding FortiAnalyzer architecture, databases, and log flow
Using ADOMs to segment and organize multi‑tenant environments
Creating custom dashboards and visualizations
Running detailed reports: security events, traffic, threats, VPN, bandwidth, user activity
Automating scheduled reports for auditing and compliance
Using FortiAnalyzer for forensic analysis and incident investigation
Managing event handlers, alerts, and notifications
Best practices for FortiAnalyzer administration and optimization
Course Overview
This course prepares you for the Fortinet NSE5 FortiAnalyzer 7.2 exam, the required exam for earning the NSE5 Network Security Analyst certification. You will learn how to centrally manage, analyze, and report on Fortinet security devices using real configurations and practical demonstrations.
This training is ideal for onboarding new security professionals, building team skills, or serving as a reference resource for Fortinet environments.
Why This Course Is Valuable
Hands‑on demonstrations of every major FortiAnalyzer feature
Real enterprise use cases — not just theory
Clear, simple explanations suitable for beginners and professionals
Covers all exam‑relevant topics for FortiAnalyzer 7.2
Perfect for SOC analysts, network engineers, and security administrators
Who Should Enroll
Network & Security Engineers
SOC/NOC Analysts
Fortinet administrators managing multiple FortiGate devices
IT managers overseeing centralized security operations
Professionals preparing for the NSE5 FortiAnalyzer 7.2 exam
Prerequisites
3–5 years of experience with Fortinet firewalls recommended
Basic understanding of networking and security concepts
Familiarity with FortiOS and Fortinet products is helpful
Product Versions Covered
FortiOS 7.x
FortiAnalyzer 7.2.x
Start Mastering FortiAnalyzer Today
Gain the skills to centrally manage logs, analyze threats, and generate powerful reports across your Fortinet security infrastructure.