Reduce response times with advanced AI-driven threat hunting
Boost ROI through automated Security Fabric integration
Minimise analyst fatigue via high-volume workflow automation
Build audit-ready compliance reports with custom data visualization
Convert raw log data into actionable business intelligence
Strengthen cyber resilience with proactive outbreak alert monitoring
What you'll gain from our training
Upcoming sessions
SOC roles, objectives, and responsibilities
Fortinet Security Fabric overview and integration with FortiAnalyzer
FortiAnalyzer operating modes and deployment options
How centralized logging supports SOC efficiency
Explore a FortiAnalyzer deployment within a Security Fabric
Validate operating modes and integration points
Logging architecture in Fortinet environments
Parsing and normalization of logs
Navigating the log view: filters, search, and dashboards
Creating saved filters, custom dashboards, and FortiView widgets
Hands-on with log parsing validation
Build custom filters and dashboards for monitoring
Understanding events and indicators of compromise (IoCs)
Configuring and managing event handlers
Event correlation and automation stitch integration
Creating and managing incidents
Configuring incident settings and workflows
Best practices for incident analysis in SOC operations
Configure an event handler with automation stitch
Create an incident from event triggers
Perform incident analysis using FortiAnalyzer tools
FortiAI operations and SOC use cases
Threat hunting methodology with FortiAnalyzer
Using log count charts and SIEM analytics tables
Outbreak alert generation and analysis
Troubleshooting incidents and log anomalies
Conduct a guided threat hunt using FortiAI
Use outbreak reports to investigate a simulated attack
Building datasets, macros, and custom charts
Configuring external storage for reports
Importing/exporting reports and attaching to incidents
Troubleshooting reporting issues
Run a predefined report
Create a custom report with charts and macros
Attach reports to a live incident
Automation playbook concepts and benefits
Building playbooks with tasks and variables
Monitoring playbook execution
Exporting/importing playbooks for reuse
Integrating playbooks with incidents and event handlers
Design and implement a custom playbook for automated response
Monitor playbook performance and fine-tune execution
Successful completion will help you to
1
Define enterprise log requirements and map sources across network zones
2
Configure FortiAnalyzer initial settings and validate secure administrative access
3
Draft data retention policies and document evidence-handling procedures for investigations
4
Onboard FortiGate units and verify reliable event forwarding and parsing
5
Evaluate storage resilience options and monitor disk health indicators proactively
6
Implement high-availability plans and test failover to maintain service continuity
To enrol, the following prerequisite must be met:
Overall ratings by our students
The FortiAnalyzer Analyst Course focuses on establishing reliable security logging and reporting routines for organisations using Fortinet environments. It helps teams standardise how security events are collected, stored, reviewed, and presented as defensible records. For many organisations, this supports incident investigations, management reporting, and audit evidence requests without relying on informal processes or individual workarounds. It also aligns day-to-day monitoring with repeatable review and handover practices across teams and locations.
Common challenges include inconsistent log forwarding from sites, unclear ownership between the SOC and network teams, and delays in building incident timelines when leadership requests evidence. Many organisations also face storage pressure, unexpected log gaps, and reporting that varies by analyst or shift. This training aligns teams on operating routines, ensuring that log availability, evidence retrieval, and reporting outputs follow a defined internal baseline. It is particularly relevant where audits, customer requirements, or regulated operations demand traceable records.
Organisations usually nominate a mix of security operations, network/security administration, and IT operations stakeholders who touch monitoring, escalation, and reporting. In multi-site environments, including a representative from central operations helps standardise naming, grouping, and review cadence across locations. Where audits or governance requirements are strict, a compliance or risk stakeholder may join to align retention expectations and evidence handling. The goal is cross-functional alignment on how log data is maintained and referenced.
The program can be aligned to your current FortiGate and log-source landscape by mapping sources, defining grouping conventions, and agreeing on review routines that work across sites. For multi-site operations, the focus is usually on consistent onboarding steps, standard naming, and comparable reporting outputs so different locations can be reviewed using the same structure. This reduces site-by-site variability and makes escalations easier to interpret. Teams leave with a practical operating baseline they can implement internally.
Some of the key benefits of enrolling employees in this employee training program are as follows:
The FortiAnalyzer Analyst course covers event correlation, IoC detection, and automation stitches for rapid triage and incident handling. We provide hands-on labs that simulate real-time analysis. This enables teams to reduce mean time to respond (MTTR) in scenarios like ransomware attacks. For industries such as finance or manufacturing, this training minimizes operational downtime, enhances response efficiency, and integrates seamlessly with existing Fortinet tools for immediate threat mitigation.
Learn now, pay later
Dive into your course now and pay in installments

