Multiple tiers FortiAnalyzer fabric
Description
-
Centralized visibility of managed devices, log view, incidents and events from a FortiAnalyzer supervisor.
-
Single or multiple tiers deployment are supported (for example, Collector-Analyzer).
Limitations
-
No high availability on the supervisor.
-
Scalability and redundancy limited to each FortiAnalyzer deployment.
-
Unable to perform configuration changes or to run automation playbooks from fabric supervisor to members.
Use case
A suitable architecture for multinational customers with subsidiaries worldwide. The key differentiator compared to the to the Multiple tiers high availability architecture is that the regional SOC team can also benefit from a fully functional analyzer and not only have a historical log view available as on a collector. The collectors can be used to build points of presence in the different regions and forward the information to the central analyzer in the company's head office.