<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="32692" language="en" source="https://portal.flane.ch/swisscom/en/xml-course/fortinet-faz-ans" lastchanged="2026-04-02T00:29:09+02:00" parent="https://portal.flane.ch/swisscom/en/xml-courses"><title>FortiAnalyzer Analyst</title><productcode>FAZ-ANS</productcode><vendorcode>FO</vendorcode><vendorname>Fortinet</vendorname><fullproductcode>FO-FAZ-ANS</fullproductcode><version>7.6</version><objective>&lt;p&gt;After completing this course, you should be able to:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe SOC objectives, responsibilities, and roles&lt;/li&gt;&lt;li&gt;Describe the role of FortiAnalyzer in a SOC&lt;/li&gt;&lt;li&gt;Describe FortiAnalyzer Security Fabric integration&lt;/li&gt;&lt;li&gt;Describe how logging works in a Security Fabric&lt;/li&gt;&lt;li&gt;Describe FortiAnalyzer Fabric deployments&lt;/li&gt;&lt;li&gt;Describe FortiAnalyzer operating modes&lt;/li&gt;&lt;li&gt;Describe how FortiAnalyzer parses and normalizes logs&lt;/li&gt;&lt;li&gt;Validate log parsers&lt;/li&gt;&lt;li&gt;Search logs using normalized fields&lt;/li&gt;&lt;li&gt;View and search for logs in the log view&lt;/li&gt;&lt;li&gt;Create saved filters and dashboards&lt;/li&gt;&lt;li&gt;View summary data in FortiView&lt;/li&gt;&lt;li&gt;View dashboards and widget features&lt;/li&gt;&lt;li&gt;Configure event handlers&lt;/li&gt;&lt;li&gt;Manage events&lt;/li&gt;&lt;li&gt;Configure indicators&lt;/li&gt;&lt;li&gt;Create incidents&lt;/li&gt;&lt;li&gt;Analyze incidents&lt;/li&gt;&lt;li&gt;Configure incident settings&lt;/li&gt;&lt;li&gt;Describe FortiAI operations and use cases&lt;/li&gt;&lt;li&gt;Describe threat hunting&lt;/li&gt;&lt;li&gt;Use the log count chart&lt;/li&gt;&lt;li&gt;Use the SIEM log analytics table&lt;/li&gt;&lt;li&gt;Describe outbreak alerts&lt;/li&gt;&lt;li&gt;Collect log volume statistics&lt;/li&gt;&lt;li&gt;Configure an automation stitch&lt;/li&gt;&lt;li&gt;Configure an event handler with an automation stitch enabled&lt;/li&gt;&lt;li&gt;Run and fine-tune predefined reports&lt;/li&gt;&lt;li&gt;Customize reports with macros, custom charts, and datasets&lt;/li&gt;&lt;li&gt;Configure external storage for reports&lt;/li&gt;&lt;li&gt;Group reports&lt;/li&gt;&lt;li&gt;Import and export reports and charts&lt;/li&gt;&lt;li&gt;Attach reports to incidents&lt;/li&gt;&lt;li&gt;Manage and troubleshoot reports&lt;/li&gt;&lt;li&gt;Create new playbooks&lt;/li&gt;&lt;li&gt;Use variables in tasks&lt;/li&gt;&lt;li&gt;Monitor playbooks&lt;/li&gt;&lt;li&gt;Export and import playbooks&lt;/li&gt;&lt;/ul&gt;</objective><essentials>&lt;p&gt;You must have an understanding of the topics covered in the following courses, or have equivalent experience:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;FortiGate Operator&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/fortinet-anlzr-admn&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;FortiAnalyzer Administrator &lt;span class=&quot;fl-prod-pcode&quot;&gt;(ANLZR-ADMN)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;It is also recommended that you have knowledge of the following topic:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;SQL SELECT statement syntax&lt;/li&gt;&lt;/ul&gt;</essentials><audience>&lt;p&gt;Security professionals responsible for Fortinet Security Fabric analytics and automating tasks to detect and respond to cyberattacks using FortiAnalyzer should attend this course.&lt;/p&gt;</audience><outline>&lt;ul&gt;
&lt;li&gt;SOC Concepts and Security Fabric&lt;/li&gt;&lt;li&gt;Log Data Flow and Navigation&lt;/li&gt;&lt;li&gt;Events, Indicators, and Incidents&lt;/li&gt;&lt;li&gt;FortiAI, Threat Hunting, and Troubleshooting&lt;/li&gt;&lt;li&gt;Reports&lt;/li&gt;&lt;li&gt;Playbooks&lt;/li&gt;&lt;/ul&gt;</outline><objective_plain>After completing this course, you should be able to:



- Describe SOC objectives, responsibilities, and roles
- Describe the role of FortiAnalyzer in a SOC
- Describe FortiAnalyzer Security Fabric integration
- Describe how logging works in a Security Fabric
- Describe FortiAnalyzer Fabric deployments
- Describe FortiAnalyzer operating modes
- Describe how FortiAnalyzer parses and normalizes logs
- Validate log parsers
- Search logs using normalized fields
- View and search for logs in the log view
- Create saved filters and dashboards
- View summary data in FortiView
- View dashboards and widget features
- Configure event handlers
- Manage events
- Configure indicators
- Create incidents
- Analyze incidents
- Configure incident settings
- Describe FortiAI operations and use cases
- Describe threat hunting
- Use the log count chart
- Use the SIEM log analytics table
- Describe outbreak alerts
- Collect log volume statistics
- Configure an automation stitch
- Configure an event handler with an automation stitch enabled
- Run and fine-tune predefined reports
- Customize reports with macros, custom charts, and datasets
- Configure external storage for reports
- Group reports
- Import and export reports and charts
- Attach reports to incidents
- Manage and troubleshoot reports
- Create new playbooks
- Use variables in tasks
- Monitor playbooks
- Export and import playbooks</objective_plain><essentials_plain>You must have an understanding of the topics covered in the following courses, or have equivalent experience:



- FortiGate Operator
- FortiAnalyzer Administrator (ANLZR-ADMN)
It is also recommended that you have knowledge of the following topic:



- SQL SELECT statement syntax</essentials_plain><audience_plain>Security professionals responsible for Fortinet Security Fabric analytics and automating tasks to detect and respond to cyberattacks using FortiAnalyzer should attend this course.</audience_plain><outline_plain>- SOC Concepts and Security Fabric
- Log Data Flow and Navigation
- Events, Indicators, and Incidents
- FortiAI, Threat Hunting, and Troubleshooting
- Reports
- Playbooks</outline_plain><duration unit="d" days="1">1 day</duration><pricelist><price country="US" currency="USD">950.00</price><price country="AT" currency="EUR">950.00</price><price country="DE" currency="EUR">950.00</price><price country="IT" currency="EUR">950.00</price><price country="PL" currency="EUR">950.00</price><price country="FR" currency="EUR">1490.00</price><price country="NL" currency="EUR">950.00</price><price country="CH" currency="CHF">1000.00</price></pricelist><miles/></course>