Try our new research platform with insights from 80,000+ expert users

LogRhythm UEBA [EOL] vs Wazuh comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Aug 25, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

LogRhythm UEBA [EOL]
Average Rating
7.2
Reviews Sentiment
6.5
Number of Reviews
12
Ranking in other categories
No ranking in other categories
Wazuh
Average Rating
7.4
Reviews Sentiment
6.1
Number of Reviews
50
Ranking in other categories
Log Management (1st), Security Information and Event Management (SIEM) (2nd), Extended Detection and Response (XDR) (5th)
 

Featured Reviews

HS
Senior Cyber Cons at MDS
Improves threat investigation speed and reduces cyber risks but requires a more comprehensive use case library
In general, if something needs to be improved in the algorithm, it would be the dashboards. The dashboards with solutions such as Splunk are very neat and clean. I would also like to improve the use cases LogRhythm has. It does not have a very large use case library, so the content engineer needs to develop use cases rapidly alongside emerging threats.
RS
Engineer Information Security at N-Able (Pvt) Ltd
Has faced limitations in AI capabilities and pricing flexibility
Pricing-wise, Wazuh stands out, along with deployment flexibility and its documentation which is extremely good in comparison to Forti. The community support is also incredible. They have helped quite a bit because previously, we had a separate tool and management dashboard to do our compliance. With Wazuh, we receive that information without having to do anything extra. We just set up the SIEM and all of that information was automatically populated. The dashboards are very easy to understand and very quick with no lag or delay. I have experienced delays on Forti's dashboards, but not with Wazuh. Wazuh is quite good. In comparison to Forti, they are quite similar. They are very good at detection.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"LogRhythm UEBA [EOL] has positively impacted our organization by improving our ability to detect insider threats and compromised accounts earlier, resulting in better security visibility, reduced false positives, and faster investigations and response times, which helped the team operate more effectively with greater confidence."
"It is easy to monitor users and that is how the solution is adding value to our firm."
"The tool's most valuable feature is server threat hunting."
"It has a lot of features. It has file integration monitoring."
"The solution's most valuable features are the graphical user interface and the reporting."
"LogRhythm UEBA’s best feature is the dashboard. It provides several graphs, charts, and event logs."
"Good capability pinpointing specific cyber incidents."
"What I like most about LogRhythm UEBA is that it allows you to identify and analyze end-user behaviors and suspicious activities within the systems."
"Wazuh offers numerous features, such as the ability to define custom rules for detecting malicious activities and remembering behaviors."
"It is a stable solution."
"Good for monitoring, active response, and for vulnerabilities."
"The solution is easy to maintain."
"The most valuable features are the modules and metrics."
"Wazuh has very flexible and robust features."
"We found the MITRE framework mapping and the agent enrollment service to be the most valuable features of Wazuh."
"Wazuh's most valuable features include file monitoring and compliance reporting, which do not require excessive costs."
 

Cons

"The cloud version is lacking and not up to par."
"The product should improve its dashboards. Splunk has neat dashboards. Additionally, we would like to enhance the use cases provided by LogRhythm as its use case library is not as extensive as other tools. Its machine-learning capabilities need to improve when compared to other solutions. It lacks risk quantification in a single, transparent view for individuals such as CSOs."
"It should have better mitigation with other solutions and be tightly integrated with other solutions. It has to be improved."
"LogRhythm UEBA [EOL] could be improved with more flexible tuning options and clearer model transparency to better understand why certain behaviors are flagged; enhanced integrations with additional data sources and more intuitive dashboards would also help improve usability and investigation efficiency."
"The product could be user-friendly for someone who doesn’t have any prior experience working with it."
"In general, if something needs to be improved in the algorithm, it would be the dashboards."
"It would be helpful if there were more guidance provided for integrating with unsupported devices."
"The search feature needs to be improved."
"Wazuh is missing many things that a typical SIEM should have."
"They need to go towards integrating with more cloud applications and not just OS like Windows and Linux."
"We would like to see more improvements on the cloud."
"I have yet to find the same capability in Wazuh to get logs from different sources into the system"
"When I face a challenge, I prefer not to spend too much time on it and may move to another solution that will give us the results."
"Wazuh doesn't have native support for some enterprise solutions."
"The computing resources are consuming and do not make sense."
"Since it's an open-source tool, scalability is the main issue."
 

Pricing and Cost Advice

"The pricing is nice when compared to other products in the industry."
"LogRhythm UEBA's pricing is affordable for small and medium businesses."
"Licensing is on a yearly basis. It's not expensive compared to its competitors."
"As LogRhythm UEBA is pretty expensive, I'd give its pricing a seven out of ten."
"I rate the product's pricing a three out of ten. However, the cloud version is expensive. You need to hire professional services for deployment and migrations, which can be expensive."
"It is quite a budget-friendly product."
"The current pricing is open source."
"It is a free-of-cost solution."
"Wazuh is totally free and open source. There are no licensing costs, only support costs if you need them."
"The solution's cost is above the average."
"Wazuh is an open-source tool."
"The product is cheaper compared to other tools."
"Wazuh is a good tool, but the open-source version has scalability limitations."
"It is a cost-effective solution."
report
Use our free recommendation engine to learn which Extended Detection and Response (XDR) solutions are best for your needs.
881,455 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Retailer
10%
Financial Services Firm
10%
Manufacturing Company
7%
Computer Software Company
12%
Comms Service Provider
11%
University
8%
Manufacturing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise4
Large Enterprise4
By reviewers
Company SizeCount
Small Business27
Midsize Enterprise15
Large Enterprise8
 

Questions from the Community

What do you like most about LogRhythm UserXDR?
The solution is useful for privilege accounts and super admin accounts. It is beneficial from a security perspective. The tool uses machine learning rather than threshold-based alerts. For instance...
What is your experience regarding pricing and costs for LogRhythm UserXDR?
I rate the product's pricing a three out of ten. However, the cloud version is expensive. You need to hire professional services for deployment and migrations, which can be expensive.
What needs improvement with LogRhythm UserXDR?
In general, if something needs to be improved in the algorithm, it would be the dashboards. The dashboards with solutions such as Splunk are very neat and clean. I would also like to improve the us...
What do you like most about Wazuh?
Wazuh is its flexibility and open-source nature, which allows us to tailor threat detection and response across diverse client environments. Its integration capabilities with SOAR, cloud platforms,...
What needs improvement with Wazuh?
Regarding compliance, I find it not stable. I do not recommend it for that purpose. It can comply with Wazuh NCA, which we have here in Saudi Arabia. Wazuh NCA has many frameworks starting with ECC...
What is your primary use case for Wazuh?
I have been working with Wazuh for two years, and I can explain how I use Wazuh. I did not use Wazuh as a SIEM solution. I use Wazuh as a tool for services we provide. This service is called compro...
 

Also Known As

LogRhythm UserXDR, LogRhythm Enterprise UEBA
Wazuh All-In-One Deployment
 

Overview

Find out what your peers are saying about CrowdStrike, TrendAI, SentinelOne and others in Extended Detection and Response (XDR). Updated: January 2026.
881,455 professionals have used our research since 2012.