Try our new research platform with insights from 80,000+ expert users

Elastic Stack vs Wazuh comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 9, 2024
 

Categories and Ranking

Elastic Stack
Ranking in Log Management
14th
Average Rating
7.8
Reviews Sentiment
6.0
Number of Reviews
15
Ranking in other categories
No ranking in other categories
Wazuh
Ranking in Log Management
2nd
Average Rating
7.4
Reviews Sentiment
6.6
Number of Reviews
45
Ranking in other categories
Security Information and Event Management (SIEM) (2nd), Extended Detection and Response (XDR) (3rd)
 

Mindshare comparison

As of December 2024, in the Log Management category, the mindshare of Elastic Stack is 4.0%, up from 0.3% compared to the previous year. The mindshare of Wazuh is 17.0%, up from 13.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management
 

Featured Reviews

Mahesh Ramichetty - PeerSpot reviewer
A stable product that can be fine-tuned easily
Elastic Stack provides all sorts of things, so it provides Elasticsearch for the transformations into a specific format, and pipelines can be defined for distributed applications along with the logs that come in the JSON format, which is clean. It's only the enhancements or the security that the product lacks and needs to be enhanced. I don't think further enhancement of the features needs to be added to the solution because it is already equivalent to a monitoring or alerting system, like Dynatrace and other tools. Some developments in the area of AI, which Elastic Stack is currently working on, should be fine in terms of the enhancements. Whenever some critical issue happens, there should be some kind of a co-pilot that helps resolve the issue. The tool should learn from its own previous issues. If you take Databricks, you see that it provides a co-pilot for Python, so a similar kind of development in Elastic Stack would be a real asset for it. AI would be considered a good way to enable the tool further for more in 2024, and even a beta launch would be helpful. If you take any sort of cloud-native monitoring product, like Azure Monitor or AWS CloudWatch, you see that such products don't provide much of the insights. If you go with Azure Monitor for any sort of ML models to be there, Sentinel needs to be used from Azure, which is very costly. AI-enablement would be a big improvement in Elastic Stack. Everyone in the monitoring space, including Dynatrace and New Relic, has lately been discussing AI, but it doesn't seem to be coming out. If there is room for an ML model in Elastic Stack, then it would be good.
AKASH MAJUMDER - PeerSpot reviewer
Open-source platform with custom alerting
There are three key strengths of Wazuh that stand out to me. Firstly, Wazuh offers an enhanced HDR version that outperforms the Elastic Stack. Wazuh has achieved this by running a config or a sec in the background, which has improved the XBR for endpoint security significantly. Secondly, Wazuh comes with built-in frameworks, such as the NISC and ISO, that make it easy to comply with various industry standards. We didn't need to configure any custom frameworks for this, as Wazuh had it built in. Lastly, Wazuh has the ability to collect terabytes of data within seconds, which is a crucial feature for modern enterprises dealing with large amounts of data.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The biggest strength of Elastic Stack is its brilliant archiving capabilities."
"The detection rules in Elastic Stack are the most valuable feature. The search capabilities are excellent and fast. As we collect logs from workstations and devices, the detection rules run on top of the logs and detect any suspicious activity, raising alerts accordingly. Integration with Elastic Stack depends on the specific integration. Elastic provides some bridging integrations that make it easy, but require custom integration. Most integrations are simple, but customization can be challenging because we need to do some parsing. There's something called Elastic Common Schema, and we need to parse the source logs to match this schema, which can be a bit challenging."
"I think the ecosystem is well supported, and for logs, it was faster compared to our previous previous log management."
"The machine learning capabilities are valuable."
"The solution's technical support is good...Elastic Stack offers good value for value for money based on the product's features and what they offer."
"The tool's most powerful aspect is its search engine capability. It's a highly effective and powerful solution for searching. We use it in professional and student projects at universities, and it delivers promising results."
"The only beneficial aspect of Elastic Stack is that it's open source."
"Elastic Stack has made a positive impact as we can now see our logs."
"Wazuh's most beneficial features for our security needs are flexibility, built-in rules, integration capabilities, and documentation."
"One of the most beneficial features of Wazuh, particularly in the context of security needs, is the machine learning data handling capability."
"Wazuh automatically scans the host for CIS benchmarks for the latest updates and vulnerabilities and gives a host score. It provides a percentage of perceived risk due to of non patches or any missing patches on that work."
"Some of the strengths of Wazuh that stand out for us include its scalability when deployed on Azure, its open-source nature, which allows for customization based on our needs, and its compatibility with various security solutions like threat intelligence platforms."
"If they support a solution, it is easy to do an integration."
"Regarding Wazuh, I find the SCA (Security Configuration Assessment) features most valuable. It's crucial for asset management and inventory, allowing us to monitorendpoints and servers' changes easily. This is particularly important for my customers, who aren't heavily focused on incident response but rely on asset management and inventories. Wazuh's compliance management features are very supportive, especially in regions like the Americas and Europe. However, it's less effective in the ANZ (Australia and New Zealand) region since Wazuh doesn't cater to the specific compliance standards there, such as those required in Australia. I appreciate that Wazuh fully complies with PCI DSS and GDPR standards, allowing us to generate necessary reports."
"It has efficient SCA capabilities."
"It is excellent in terms of visualization and indexing services, making it a powerful tool for malware detection."
 

Cons

"When people try to move the data from another source to Elastic Stack for visualization, they face challenges when connecting to Elastic Stack from such different sources."
"Improvements are needed in the solution in areas like SOAR and TIP, where there are certain shortcomings."
"The stability of the solution is rated as three or four out of ten as we frequently encounter issues."
"It should facilitate easier manual integration."
"The tool's pricing can be improved."
"Agent deployment is a little tough in the on-premise version."
"It lacks a clear NDR (Network Detection and Response) feature. If Elastic could enhance this aspect, it would significantly boost its capabilities."
"AI-enablement would be a big improvement in Elastic Stack...If there is room for an ML model in Elastic Stack, then it would be good."
"It would be great if there could be customization for the decoder portion."
"The tool doesn't detect anomalies or new environments."
"Wazuh could improve the detection, it is not detecting all of the attacks. Additionally, it is lacking features compared to other solutions."
"The implementation is very complex."
"The deployment is a bit complex."
"There's not much I like about Wazuh. Other products I've used were a lot more functional and user friendly. They came with reports and use cases out of the box. We need to configure Wazuh's alerts and monitoring capabilities manually. It'd be nice if we could select from templates and presets for use cases already built and coded."
"They could include flexibility and customization capabilities by modifying for customers based on partner agreements."
"Integration with Vyara could be better."
 

Pricing and Cost Advice

"We are using the open-source community version of the product."
"I rate the solution's pricing a six out of ten."
"It depends on the specifics, but generally, Elastic is economical for certain use cases."
"The pricing is reasonable."
"The product is expensive."
"I used the open-source version of Elastic Stack, because of which I did not have to pay anything."
"Ultimately, the pricing depends upon the capacity planning that the enterprise architect does."
"If I compare Elastic Stack to the other products in the market, I would say that the tool is available at a competitive price."
"They have a good pricing strategy for market expansion."
"The solution's cost is above the average."
"The current pricing is open source."
"Wazuh is a cheaply priced product."
"It is a cost-effective solution."
"Wazuh is an open-source tool."
"Wazuh is open-source, so I think it's an option for a small organization that cannot go for enterprise-grade solutions like Splunk."
"When I contacted customer care, they mentioned bundling options, that I found to be overall affordable."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
824,053 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
13%
Financial Services Firm
12%
Comms Service Provider
9%
Government
8%
Computer Software Company
16%
Comms Service Provider
7%
University
7%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Elastic Stack?
The tool is huge, and it performs brilliantly. I tested it for malware, and within two weeks of launching, the product alerted me about a network intrusion. This was a tough test for it, but it per...
What is your experience regarding pricing and costs for Elastic Stack?
We use Elastic Stack's open source version, so it is free for us.
What needs improvement with Elastic Stack?
Elastic Stack needs more features similar to other SIEM tools such as Sentinel or the ability to create automations. Additionally, it should facilitate easier manual integration.
What do you like most about Wazuh?
Integrates with various open-source and paid products, allowing for flexibility in customization based on use cases.
What needs improvement with Wazuh?
I am investigating more about the community support for Wazuh. I can't provide a definitive answer yet. An issue I noticed is with tag values in certain rules not functioning properly. It's unclear...
What is your primary use case for Wazuh?
I am currently evaluating and using Wazuh for file monitoring and compliance reporting. We are in the process of conducting a POC to understand how the rules work. I lead this effort to explore and...
 

Comparisons

 

Learn More

 

Overview

Find out what your peers are saying about Elastic Stack vs. Wazuh and other solutions. Updated: December 2024.
824,053 professionals have used our research since 2012.