Short answer: for some jobs yes, for the jobs FortiAnalyzer exists for, no. This page is the honest version, because sending you down the wrong path wastes your afternoon and our reputation.
Vigil is a free, open-source, self-hosted dashboard for FortiGate syslog. It runs as one Docker container, reads the logs your firewall already sends, and answers the daily questions: who is hitting us from the internet, what got through, which rule allowed it, and what changed on the firewall. Nothing leaves the machine.
| What you need | FortiAnalyzer | Vigil |
|---|---|---|
| Long-term log archival and retention policies | Yes — built for it | 30 days of detail by default, summaries longer |
| Compliance reporting (PCI, ISO, audit packs) | Yes | No |
| Multi-device, multi-tenant, ADOMs | Yes | Single firewall per instance |
| High availability, clustering | Yes | No — one container |
| Vendor support and warranty | Yes | Community, GitHub issues |
| FortiView, SOC automation, playbooks | Yes | No |
| Cost | Licensed appliance or VM | Free, Apache-2.0 |
| Time to first screen | Deploy and licence | docker compose up -d, about a minute |
| Runs next to an existing syslog server | — | Yes, reads its file read-only |
| Live traffic view | Dashboards | 3D view where each particle is one real log line you can click |
| Rule risk grading from your config | Reports | Upload a backup; graded, then kept current from the change log |
| Plain-English “why was this blocked?” | Log search | Investigation tracker with the hop-by-hop path |
Use FortiAnalyzer when you must keep logs for a year, produce audit reports, or manage many firewalls under one roof. Nothing here replaces that.
Use Vigil when there is no FortiAnalyzer — the site is too small, the budget went elsewhere, or the logs land on a syslog VM nobody reads — and you still want to see what the internet is doing to you today.
Plenty of people run both: FortiAnalyzer for retention and reporting, Vigil on the syslog box for the live view.
The usual free answer is Elasticsearch + Logstash + Kibana with FortiGate parsers.
| ELK stack | Vigil | |
|---|---|---|
| Moving parts | Elasticsearch, Logstash, Kibana, parser configs | One container, SQLite |
| Memory | Several GB, JVM tuning | Fits a 1–2 GB VM |
| Time to a useful screen | Days of dashboard building | Minutes, dashboards included |
| FortiGate knowledge built in | You write the parsers and panels | Field semantics, rule grading and detections included |
| Flexible for any log source | Yes — that is the point | FortiGate only |
If you already run ELK and enjoy it, keep it. If you want FortiGate answers today without becoming an Elasticsearch operator, that is the gap Vigil fills.
key=value, with the field semantics that trip up home-grown
parsers (event time in nanoseconds, FTNTFGTapp versus app=, security-profile blocks that never say deny).ENC value.logid 0100044547) with the old and new value.git clone https://github.com/vigiltech01/vigil.git && cd vigil && ./install.sh
Or without a firewall to hand, explore the demo data:
VIGIL_DEMO=1 docker compose up -d
Then open http://<host>:8080. Install guide · FortiGate setup ·
Source on GitHub