Try our new research platform with insights from 80,000+ expert users

Elastic Observability vs Wazuh comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Elastic Observability
Ranking in Log Management
12th
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
26
Ranking in other categories
Application Performance Monitoring (APM) and Observability (7th), IT Infrastructure Monitoring (7th), Container Monitoring (4th), Cloud Monitoring Software (7th)
Wazuh
Ranking in Log Management
2nd
Average Rating
7.4
Reviews Sentiment
6.6
Number of Reviews
45
Ranking in other categories
Security Information and Event Management (SIEM) (2nd), Extended Detection and Response (XDR) (3rd)
 

Mindshare comparison

As of January 2025, in the Log Management category, the mindshare of Elastic Observability is 1.9%, down from 2.2% compared to the previous year. The mindshare of Wazuh is 16.8%, up from 13.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management
 

Featured Reviews

Adelina Craciun - PeerSpot reviewer
Customization enables tailored monitoring and alerting across departments
The possibility to customize it has been quite useful. Whatever the other departments want to dream up, we implement. Whatever they want to monitor, the granularity of it, the changes in the threshold, and the anomalies that they want reported all require some development. So far, every single request has been fulfilled.
Sandip_Patel - PeerSpot reviewer
Evaluating robust file monitoring with insights for community support improvements
Wazuh's most valuable features include file monitoring and compliance reporting, which do not require excessive costs. These aspects are vital as they provide alerts for changes and facilitate the monitoring of compliance. The platform is also relatively easy to set up and operate. Reports are straightforward to extract and prove useful for compliance requirements.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The ability to ensure that the data is searchable and maintainable is highly valuable for our purposes."
"It is scalable and supports multitenancy, which is beneficial for MSPs."
"Machine learning is the most valuable feature of this solution."
"I have built a mini business intelligence system based on Elastic Observability."
"The solution is open-source and helps with back-end logging. It is also easy to handle."
"Elastic Observability significantly improves incident response time by providing quick access to logs and data across various sources. For instance, searching for specific keywords in logs spanning over a month from multiple data sources can be completed within seconds."
"We can view and connect different sources to the dashboard using it."
"Its diverse set of features available on the cloud is of significant importance."
"Wazuh is free and easy to use. It is also adjustable, and we can use it on the cloud and on-premises."
"The most valuable feature of Wazuh is the ELK for doing an investigation."
"I like that the solution is on top of the Kubernetes stack."
"The configuration assessment and Pile integrity monitoring features are decent."
"The log monitoring and analysis tools are great in addition to SIEM file activity monitoring."
"Wazuh has very flexible and robust features."
"It offers built-in modules for file integrity and vulnerability management."
"It's very easy to integrate Wazuh with other environments, cloud applications, and on-prem applications. So, the advantage is that it's easy to implement and integrate with other solutions."
 

Cons

"Elastic Observability needs to have better standardization, logging, and schema."
"The solution needs to use more AI. Once the product onboards AI, users would more effectively be able to track endpoints for specific messages."
"The tool's scalability involves a more complex implementation process. It requires careful calculations to determine the number of nodes needed, the specifications of each node, and the configuration of hot, warm, and cold zones for data storage. Additionally, managing log retention policies adds further complexity. The solution's pricing also needs to be cheaper."
"Improving code insight related to infrastructure and network, particularly focusing on aspects such as firewalls, switches, routers, and testing would be beneficial."
"Elastic Observability needs to improve the retrieval of logs and metrics from all the instances."
"One example is the inability to monitor very old databases with the newest version."
"The cost must be made more transparent."
"I am familiar with Azure Monitor, which I find more user-friendly compared to Elastic, which is a very technical tool."
"The support channel is not optimal, and extensive research is required on our part to implement Wazuh effectively."
"There's not much I like about Wazuh. Other products I've used were a lot more functional and user friendly. They came with reports and use cases out of the box. We need to configure Wazuh's alerts and monitoring capabilities manually. It'd be nice if we could select from templates and presets for use cases already built and coded."
"They need to go towards integrating with more cloud applications and not just OS like Windows and Linux."
"Wazuh needs more security and features, particularly visualization features and a health monitor."
"The implementation is very complex."
"Wazuh has a drawback with regard to Unix systems. The solution does not allow us to do real-time monitoring for Unix systems. If usage increases, it would be a heavy fall on the other SIEM solutions or event monitoring solutions."
"The product's configuration part and lack of AI capabilities are some of the major concerns associated with Wazuh."
"The only challenge we faced with Wazuh was the lack of direct support."
 

Pricing and Cost Advice

"The product is not that cheap."
"Elastic Observability is cheaper than other similar solutions, such as Dynatrace. Its license calculation is based on various factors like data volume and physical infrastructure, particularly related to RAM capacity."
"The product’s pricing needs improvement."
"One needs to pay for the licenses, and it is an annual subscription model right now."
"Elastic Observability's pricing could be better for small-scale users."
"The price of Elastic Observability is expensive."
"There are two types: cloud and SaaS. They charge based on data ingestion, ingest rate, hard retention, and warm retention. I believe it costs around $25,000 annually to ingest 30GB of data daily. That is the SaaS version. There is also a self-managed license where the customer manages their own infrastructure on-prem. In such cases, there are three license tiers that respectively cost $5,000 annually per node, $7,000 per node, and $12,500 per node."
"Users have to pay for some features, like the alerts on different channels, because they are unavailable in different source versions."
"Wazuh is an open-source tool."
"It is a cost-effective solution."
"The product is cheaper compared to other tools."
"It is a free-of-cost solution."
"It is an open-source product."
"Wazuh is open-source, but you must consider the total cost of ownership. It may be free to acquire, but you spend a lot of time and effort supporting the product and getting it to a point where it's useful."
"There is not a license required for Wazuh."
"They have a good pricing strategy for market expansion."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
831,158 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
22%
Computer Software Company
15%
Manufacturing Company
8%
Government
6%
Computer Software Company
16%
Comms Service Provider
7%
University
7%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Elastic Observability?
Elastic Observability significantly improves incident response time by providing quick access to logs and data across various sources. For instance, searching for specific keywords in logs spanning...
What is your experience regarding pricing and costs for Elastic Observability?
Elastic Observability is cost-efficient and provides all features in the enterprise license without asset-based licensing. However, sizing and licensing information could be clearer.
What needs improvement with Elastic Observability?
Elastic Observability could improve asset discovery as the current requirement to push the agent is not ideal. Simplifying the parsing of logs and manual efforts would also be beneficial.
What do you like most about Wazuh?
Integrates with various open-source and paid products, allowing for flexibility in customization based on use cases.
What needs improvement with Wazuh?
I am investigating more about the community support for Wazuh. I can't provide a definitive answer yet. An issue I noticed is with tag values in certain rules not functioning properly. It's unclear...
What is your primary use case for Wazuh?
I am currently evaluating and using Wazuh for file monitoring and compliance reporting. We are in the process of conducting a POC to understand how the rules work. I lead this effort to explore and...
 

Comparisons

 

Learn More

 

Overview

 

Sample Customers

PSCU, Entel, VITAS, Mimecast, Barrett Steel, Butterfield Bank
Information Not Available
Find out what your peers are saying about Elastic Observability vs. Wazuh and other solutions. Updated: January 2025.
831,158 professionals have used our research since 2012.