Try our new research platform with insights from 80,000+ expert users
IT Infrastructure at 4 Seniors Brasil
Real User
Top 5
Aggregates all your logs in one place and provides a unified view to monitor
Pros and Cons
  • "It allows you to aggregate all your logs in one place and provides a unified view to monitor your security environment."
  • "Wazuh doesn't have native support for some enterprise solutions."

What is our primary use case?

My company specializes in providing SIEM as a service. We leverage Wazoo for that. Since Wazoo is open-source, I hosted it on Azure.

We provide Wazuh as a service to our customers. Currently, we have three clients whose environments are integrated with our Wazuh server on our CRM system. We handle the typical CRM use cases, including security alerts and advisories, and monitor their environments through our Wazuh server.

How has it helped my organization?

It allows you to aggregate all your logs in one place and provides a unified view to monitor your security environment. Unlike other solutions, Wazuh is open-source, so you don't need to invest in significant capital expenses. You can easily set up a server on Azure or your infrastructure. While you will need specialized personnel to operate it, this is true for any SIEM solution.

What is most valuable?

One of Wazuh's most significant advantages, aside from being open source, is its flexible dashboards. Integrated with Elasticsearch, Wazuh allows you to create customized dashboards if you have an in-house developer. This level of customization isn’t available with Fortinet, which offers only pre-made dashboards. Wazuh lets you design any dashboard you need.

What needs improvement?

Wazuh doesn't have native support for some enterprise solutions. It requires an agent installed on the server, whether Windows Server or Linux, to collect logs. While you can gather information via SNMP or Splunk logs, this isn't natively supported. Some decoders are available, but they are community-built rather than officially supported. It relies on its community to create these decoders as an open-source platform, so they may not be fully integrated.

Buyer's Guide
Wazuh
November 2024
Learn what your peers think about Wazuh. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
824,053 professionals have used our research since 2012.

What do I think about the stability of the solution?

It's pretty stable. If it's not properly implemented, you don't have stability problems if you follow the documentation and do it as detailed documentation.

What do I think about the scalability of the solution?

Wazuh is highly scalable. You can install it on-premises, in Azure, or using Docker. The architecture allows you to separate the dashboard, index, and node servers.

How are customer service and support?

Wazuh offers technical support, but you need to pay for it. If you are using the open-source solution, you'll need to rely on the extensive documentation and the community itself.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is complicated. You need a specialist in the technology to make good use of it. You can do it on-premises. You can do it on Azure. You can do it on the hybrid cloud as a docker. So it's very flexible.

We use Azure, which we currently use as a single server. We will migrate it to our partner using Azure.

It takes two months to deploy completely.

What was our ROI?

You save on licensing, and you need to invest in people.

What other advice do I have?

When Wazuh is properly implemented, it runs smoothly without causing many problems. However, if it's not set up correctly, you might encounter issues that require weekly maintenance. These can include database and disk issues because, as a VM solution, Wazuh collects a large amount of logging data. Proper implementation prevents these problems, but they can arise if you're unsure how to do it.

Overall, I rate the solution an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Flag as inappropriate
PeerSpot user
Dr. Sushan Banerjee - PeerSpot reviewer
GISO - Global Information Security Officer at Beyon Connect
Real User
A free and open source security monitoring solution with useful cloud-native infrastructure, but it would be better if they had an app with an alerting mechanism
Pros and Cons
  • "I like the cloud-native infrastructure and that it's free. We didn't have to pay anything, and it has the capabilities of many premium solutions in the market. We could integrate all of our services and infrastructure in the cloud with Wazuh. From an integration point of view, Wazuh is pretty good. I had a good experience with this platform."
  • "It would be better if they had a vulnerability assessment plug-in like the one AlienVault has. In the next release, I would like to have an app with an alerting mechanism."

What is our primary use case?

We integrated all of our services and infrastructure in the cloud with Wazuh.

What is most valuable?

I like the cloud-native infrastructure and that it's free. We didn't have to pay anything, and it has the capabilities of many premium solutions in the market. We could integrate all of our services and infrastructure in the cloud with Wazuh. From an integration point of view, Wazuh is pretty good. I had a good experience with this platform.

What needs improvement?

It would be better if they had a vulnerability assessment plug-in like the one AlienVault has. In the next release, I would like to have an app with an alerting mechanism.

For how long have I used the solution?

I have been working with Wazuh for two and a half years.

What do I think about the stability of the solution?

Wazuh is a stable solution.

What do I think about the scalability of the solution?

Wazuh is a scalable solution. We had 18 employees using this solution.

Which solution did I use previously and why did I switch?

We had an AlienVault setup, but it does not support the cloud servers and infrastructure. Wazuh is known for cloud security event management.

How was the initial setup?

It took less than ten days for the integration and to get the complete setup up and running.

What about the implementation team?

Wazuh was implemented by one of my team members, who is a Wazuh expert. This employee did the complete installation and everything else.

What's my experience with pricing, setup cost, and licensing?

Wazuh has a community edition, and I was using that. It's free and open source.

What other advice do I have?

I would tell potential users to review the technical implementation documentation before setting up Wazuh. This is because setting up Wazuh is a little bit tricky for a newbie because they won't be able to understand the technicalities of the solution. Just go through the technical documentation and implementation documentation once before installing Wazuh.

On a scale from one to ten, I would give Wazuh a seven.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Wazuh
November 2024
Learn what your peers think about Wazuh. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
824,053 professionals have used our research since 2012.
Chetan_Sharma - PeerSpot reviewer
Linux System Administrator at Amity Software Systems Limited
Reseller
Top 5
Has good scalability but requires an efficient hardware monitoring tool
Pros and Cons
  • "It has efficient SCA capabilities."
  • "There could be a hardware monitoring tool for the solution."

What is our primary use case?

We use the solution for vulnerability metrics, auditing, and detecting SQL injection attacks.

What is most valuable?

The solution's most valuable feature is its SCA capabilities.

What needs improvement?

There could be a hardware monitoring tool for the solution. It helps reduce the cost of utilizing external resources for the same.

For how long have I used the solution?

We have been using the solution for five to six months.

What do I think about the scalability of the solution?

I rate the solution's scalability a ten out of ten. We have enterprise business clients.

How are customer service and support?

We are currently evaluating the cost of the solution's support services.

How was the initial setup?

We have multiple teams using the solution in the virtual environment. It was easy to deploy for a few teams while challenging for others.

What's my experience with pricing, setup cost, and licensing?

I rate the solution's pricing a seven out of ten.

What other advice do I have?

I rate the solution a seven out of ten. There needs to be monitoring for the hardware similar to Zabbix and Nagios solutions.

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer:
PeerSpot user
Youssef EL AZZOUZI - PeerSpot reviewer
Intern Master in Cybersecurity and Cybercrime at Université Abdelmalek Essaâdi
Real User
Top 5Leaderboard
Provides a range of features, but its configuration process needs to be faster
Pros and Cons
  • "It is a stable solution."
  • "Its configuration process is time-consuming."

What is our primary use case?

We use the solution for endpoint detection and response. It helps us detect malicious files.

What is most valuable?

The solution is easy to integrate with other SOC tools. Also, it has a lot of capabilities like active response, cloud security, etc.

What needs improvement?

The solution's configuration could be faster.

For how long have I used the solution?

We have been using the solution for two months.

What do I think about the stability of the solution?

The solution is easy to install. However, it takes a long time to configure.

What do I think about the scalability of the solution?

It is a stable solution.

What's my experience with pricing, setup cost, and licensing?

It is an open-source solution.

What other advice do I have?

I recommend the solution to others and rate it a seven. It has many features and integrates with other substitutes like QRadar, Hive, etc.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Vice President Information Technology and Security at a comms service provider with 201-500 employees
Real User
It's open source and useful for compliance, but it isn't user friendly and lacks out-of-the-box functionality
Pros and Cons
  • "My company implemented Wazuh because it was relatively inexpensive. They could quickly get their hands on it to check a box for some audit and compliance."
  • "There's not much I like about Wazuh. Other products I've used were a lot more functional and user friendly. They came with reports and use cases out of the box. We need to configure Wazuh's alerts and monitoring capabilities manually. It'd be nice if we could select from templates and presets for use cases already built and coded."

What is our primary use case?

Wazuh is used for event information and management. We have several events that are of interest, and Wazuh lets our folks know if any of them trigger.

How has it helped my organization?

My company implemented Wazuh because it was relatively inexpensive. They could quickly get their hands on it to check a box for some audit and compliance.

What needs improvement?

There's not much I like about Wazuh. Other products I've used were a lot more functional and user friendly. They came with reports and use cases out of the box. We need to configure Wazuh's alerts and monitoring capabilities manually. It'd be nice if we could select from templates and presets for use cases already built and coded. 

For how long have I used the solution?

I've only been with the company since November, but I believe they've been using Wazuh for maybe five years.

What do I think about the stability of the solution?

I haven't had issues with stability.

What do I think about the scalability of the solution?

Wazuh can scale up, but it doesn't scale easily. It's extensively used. We have about 30 people in our company using it. 

How are customer service and support?

Wazuh is an open-source solution, so there isn't any support. We look for answers in the knowledge base and on user forums.  

How was the initial setup?

I wasn't with the company during the initial installation, but Wazuh does require some maintenance. We don't have the resources to take care of it, so it tends to get out of date and require updates. We have an administrator, but maintaining Wazuh is only one of his responsibilities. 

What's my experience with pricing, setup cost, and licensing?

Wazuh is open-source, but you must consider the total cost of ownership. It may be free to acquire, but you spend a lot of time and effort supporting the product and getting it to a point where it's useful. 

Which other solutions did I evaluate?

There are more advanced and robust offerings out there like QRadar that we should try instead of upgrading to a new version of Wazuh.

What other advice do I have?

I rate Wazuh four out of 10. It can do the job, but you need to invest a lot of time configuring it for your use case.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Usman Arif - PeerSpot reviewer
Cyber Security Engineer at Ebryx (Pvt.) Ltd
Real User
Top 10
Transforming security features with notable vulnerability reduction and comprehensive compliance
Pros and Cons
  • "It offers built-in modules for file integrity and vulnerability management."
  • "A more structured approach, perhaps with modular UI components, to facilitate easier integration and navigation within the Wazuh platform for custom integrations would be beneficial."

What is our primary use case?

It is used primarily for event management in our organization, which falls into the category of an edge Intrusion Detection System (IDS) or host Internet protection system. Our company is not very large, with around twenty to thirty servers and approximately one hundred fifty to two hundred endpoints. Wazuh serves as a centralized platform for collecting security events and managing vulnerabilities across your systems. Its main purpose is to analyze and improve the overall security posture of our organization.

How has it helped my organization?

Before the deployment of Wazuh, we faced challenges related to vulnerability management and version change history. Vulnerabilities often went unreported, and there was no organized system for managing vulnerabilities. Since we implemented it, there has been a notable improvement. Vulnerabilities have significantly decreased, with nearly fifty percent of servers now reporting zero vulnerabilities. This positive change is attributed to regular reporting, remediation efforts, and frequent system updates.

What is most valuable?

It offers built-in modules for file integrity and vulnerability management. This provides the convenience of having these features integrated into one platform rather than using separate dedicated tools. Wazuh's comprehensive compliance with various modules aligns well with our organization's needs, making it a highly suitable and efficient solution.

What needs improvement?

It is an open-source tool with a strong community. We had positive experiences with community support, having received solutions for most of your inquiries in the past. However, it would be beneficial if Wazuh could provide clearer guidance or tutorials on how to add components to the user interface (UI), especially when integrating tools that aren't inherently supported by Wazuh. A more structured approach, perhaps with modular UI components, to facilitate easier integration and navigation within the Wazuh platform for such custom integrations would be beneficial.

For how long have I used the solution?

I have been working with it for the last three years.

What do I think about the stability of the solution?

The stability capabilities are almost perfect. I would rate it nine out of ten.

What do I think about the scalability of the solution?

It offers excellent scalability features. I would rate it nine out of ten.

How are customer service and support?

Their customer support services are excellent. I would rate it nine out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We use other tools like SpamTitan and Fortis for specific purposes. SpamTitan is employed for email spam filtering and Fortis for client-related tasks. These tools complement our overall cybersecurity and client management efforts.

How was the initial setup?

While generally straightforward, there were some challenges during the initial setup process, particularly when dealing with certificate-related issues. I would rate it seven out of ten.

What about the implementation team?

The deployment took a total of five days, involving three individuals. Once deployed, the solution is efficiently maintained by just one person.

What's my experience with pricing, setup cost, and licensing?

Wazuh is an open-source tool, which means it is freely available for use.

What other advice do I have?

I recommend it for its flexibility and adaptability to specific organizational needs. I would rate it eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer2590542 - PeerSpot reviewer
Tech Lead at a tech vendor with 201-500 employees
Real User
Improved security visibility but needs better support and integration
Pros and Cons
  • "We found the MITRE framework mapping and the agent enrollment service to be the most valuable features of Wazuh."
  • "The support channel is not optimal, and extensive research is required on our part to implement Wazuh effectively."
  • "The support channel is not optimal, and extensive research is required on our part to implement Wazuh effectively."

What is our primary use case?

Our primary use case was around data collection and anomaly detection. We integrated Wazuh with Google Cloud and other cloud providers to receive alerts and insights if there is any unauthorized data access in the production environment. 

We also monitor virtual machines for any malicious command execution and get notifications for any privilege access attempts. Additionally, we detect anomalies in traffic patterns related to specific client accounts.

How has it helped my organization?

Wazuh has provided us with excellent clarity on data access, allowing us to significantly reduce instances of unnecessary production environment access and improve processes. 

We now have real-time visibility into the production environment on both cloud and critical virtual machines, which was not possible with our previous manual audits.

What is most valuable?

We found the MITRE framework mapping and the agent enrollment service to be the most valuable features of Wazuh. These components are essential for our security needs.

What needs improvement?

The support channel is not optimal, and extensive research is required on our part to implement Wazuh effectively. The integration modules are insufficiently developed, necessitating the creation of custom integration solutions using tools like Logstash and PubSub. Although they offer data fetching from Cloud Bucket as a more economical option, it was not functioning properly.

For how long have I used the solution?

I've used the solution for four months, during which it was effectively deployed in our production environment for approximately 45 days.

What do I think about the stability of the solution?

The stability of Wazuh is strong, with no issues stemming from the solution itself. Any downtime we experienced was due to human error in configuration.

What do I think about the scalability of the solution?

Scalability depends on the configuration and the infrastructure resources like compute and memory we allocate. We found scalability to be decent, as we could easily adjust our infrastructure to handle increased traffic.

How are customer service and support?

We use the open-source version of Wazuh, which does not provide paid support. Although the community is active, it is not highly responsive. Conversion from issue to resolution is average.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

Before Wazuh, we relied on periodic audits, which were time-consuming and did not provide automated detection of security anomalies.

How was the initial setup?

Initial setup was incredibly simple, requiring only the running of one script for a single node setup. Complexities arose during integration with Kubernetes-based workloads due to insufficient documentation.

What about the implementation team?

We required only two people for both the deployment and ongoing maintenance of Wazuh.

What was our ROI?

The return on investment is visible in reduced mean time to detect from potentially three months to about an hour and mean time to respond from up to thirty days to two days.

What's my experience with pricing, setup cost, and licensing?

We did not incur costs for Wazuh itself, only for the underlying infrastructure such as PubSub, storage, and compute instances, totaling around two lakh Indian rupees per month.

Which other solutions did I evaluate?

We evaluated Google Chronicle and Elastic-based SIEM (ELK SIEM), but Wazuh was the most cost-effective solution, being open-source with necessary compute infrastructure.

What other advice do I have?

Wazuh is well-suited for small to medium-sized organizations seeking better data and security visibility for a reasonable investment. There is a learning curve due to less comprehensive documentation, but it is a beautifully designed solution.

I'd rate the solution seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Haad Fida - PeerSpot reviewer
Software Engineer at 7Vals
Real User
Top 5
An affordable and stable solution that can be used for event monitoring
Pros and Cons
  • "The tool is stable."
  • "The tool doesn't detect anomalies or new environments."

What is our primary use case?

We use the solution for event monitoring.

What is most valuable?

The tool is stable.

What needs improvement?

The rules are hard coded. The tool doesn't detect anomalies or new environments. The product lacks AI features. We have to do a lot of manual searching.

For how long have I used the solution?

I have been using the solution for about eight months.

What do I think about the scalability of the solution?

The tool is scalable for our use cases. Five to ten people use the solution in our organization. We need one administrator to monitor and improve our solution.

How are customer service and support?

We did not contact support. Our company’s security personnel set everything and documented it.

Which solution did I use previously and why did I switch?

We use Elastic Stack for logs.

How was the initial setup?

The deployment was straightforward. It took two to three months. We needed two people for deployment.

What about the implementation team?

We did the deployment in-house with the help of our security personnel and someone from the DevOps team.

What's my experience with pricing, setup cost, and licensing?

The product is cheaper compared to other tools. Depending on the logs, the product costs $200 to $400. We currently have five servers.

Which other solutions did I evaluate?

We evaluated Google Cloud.

What other advice do I have?

When Google contacted us, we were looking into an AI solution. Our implementation is rather basic. Overall, I rate the solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Wazuh Report and get advice and tips from experienced pros sharing their opinions.
Updated: November 2024
Buyer's Guide
Download our free Wazuh Report and get advice and tips from experienced pros sharing their opinions.