We use Wazuh to deliver security features in a venture capital company project focused on building a mobile application.
Security Analyst at a tech services company with 501-1,000 employees
Has efficient integration features, but they could provide enhanced customization capabilities
Pros and Cons
- "One of the most beneficial features of Wazuh, particularly in the context of security needs, is the machine learning data handling capability."
- "They could include flexibility and customization capabilities by modifying for customers based on partner agreements."
What is our primary use case?
What needs improvement?
They could include flexibility and customization capabilities by modifying for customers based on partner agreements. They could enhance governance-related tools for audit reports.
We conducted a cost-benefit evaluation and compared Wazuh with Sentinel and FortiCM. The decision to choose Wazuh was influenced by its compatibility with other systems and the strong open-source community.
In comparison, Microsoft has a huge community, but it needs to be easy to use. Additionally, FortiCM needs better community support.
For how long have I used the solution?
We are the latest version of Wazuh.
What do I think about the stability of the solution?
We have not encountered any performance issues for the application up until now. I rate the stability an eight out of ten.
Buyer's Guide
Wazuh
March 2025

Learn what your peers think about Wazuh. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
842,388 professionals have used our research since 2012.
What do I think about the scalability of the solution?
The product is easily scalable. We have around 20 executives using it daily. Our work on the use cases is still in progress.
How are customer service and support?
We contact a third-party supplier for technical support. They provide seamless services and resolve issues by the next day most of the time.
Which solution did I use previously and why did I switch?
I was a part of a service team using Splunk. I have experience working with Symantec Endpoint.
How was the initial setup?
I rate the initial setup process a seven out of ten.
What about the implementation team?
The implementation of Wazuh is done through a local third-party supplier, but the management and overall engagement with the company are handled in-house. The third-party supplier provides hardware provision, field engineers, and devices, with the day-to-day management and operations handled remotely.
There were some slight problems related to the images being used. However, these issues were attributed to infrastructure considerations rather than specific to Wazuh. Once the correct image was selected, the installation process for the first server during the proof of concept, which involved comparing Sentinel and other solutions, was completed relatively quickly—approximately one day.
It might require a team for regular patch management and vulnerability scanning. We have yet to start with the maintenance.
What's my experience with pricing, setup cost, and licensing?
For both personal and service use, the perceived cost is relatively low. They have a good pricing strategy for market expansion.
I rate the product's pricing a three out of ten.
Which other solutions did I evaluate?
We evaluated Sentinel.
What other advice do I have?
We are currently running a proof of concept and simulating usage with a select group of users as required by local bank licensing. It is utilized for vulnerability management. Up to this point, there have been minor incidents with no risks higher than moderate. Despite not needing immediate reaction, we have automation in place within your SOC and development team to respond in case of any recognized incidents.
One of the most beneficial features of Wazuh, particularly in the context of security needs, is the machine learning data handling capability. Although it has yet to be fully implemented into production and is currently in a test environment, the decision to choose Wazuh was influenced significantly by this feature. It helps us streamline and automate the assessment of security incidents. We can organize response plans proactively, even before certain incidents occur. It is the most critical aspect for us.
There were initial challenges with the real-time alerting team due to the many systems-generated alerts. It took about three months to fine-tune the system configuration, focusing on capturing only the alarms relevant from a security perspective. Despite the initial difficulties, Wazuh worked seamlessly, and there were no notable issues with configurations, handling, or investigations. The challenges primarily occurred from system-related aspects rather than issues with Wazuh.
I do not have direct experience with scalability requirements, but the implementation has been seamless. No challenges are scaling up, especially regarding adding more machines to handle the same load. The challenge is delivering logs so that Wazuh can collect, read, and analyze them effectively. We were able to overcome major issues without the need for extensive support.
Wazuh has been integrated with an intrusion prevention system (IPS) solution, Suricata, also an open-source tool. This integration adds a layer for security monitoring. The integration process is quite straightforward, especially due to the community's availability of shared use cases.
I rate the product a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Information Technology Security Consultant at a computer software company with 1,001-5,000 employees
Is easy to use both on the cloud and on-premises
Pros and Cons
- "Wazuh is free and easy to use. It is also adjustable, and we can use it on the cloud and on-premises."
- "The technical support can be improved. Wazuh has some bugs that need to be fixed. It would be good if we can have automation with respect to incidence responses."
What is most valuable?
Wazuh is free and easy to use. It is also adjustable, and we can use it on the cloud and on-premises.
What needs improvement?
The technical support can be improved. Wazuh has some bugs that need to be fixed.
It would be good if we can have automation with respect to incidence responses.
For how long have I used the solution?
I've been working with this solution for almost a year.
It's deployed both on the cloud and on-premises.
How are customer service and support?
I rate technical support at eight out of ten. It could be improved.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is easy.
Which other solutions did I evaluate?
We looked at AlienVault and EventLog Analyzer.
What other advice do I have?
If you have a small company or if you are new to SIEM and want to create your own tools, I highly recommend Wazuh.
I would rate Wazuh at eight on a scale from one to ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
Wazuh
March 2025

Learn what your peers think about Wazuh. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
842,388 professionals have used our research since 2012.
Tech Lead Security at a comms service provider with 51-200 employees
Poor detection, lacking features, but simple installation
Pros and Cons
- "The most valuable feature of Wazuh is the ELK for doing an investigation."
- "Wazuh could improve the detection, it is not detecting all of the attacks. Additionally, it is lacking features compared to other solutions."
What is our primary use case?
We are using Wazuh for our SOC environment. We are managing and monitoring our infrastructure using the Wazuh SIEM
What is most valuable?
The most valuable feature of Wazuh is the ELK for doing an investigation.
What needs improvement?
Wazuh could improve the detection, it is not detecting all of the attacks. Additionally, it is lacking features compared to other solutions.
For how long have I used the solution?
I have been using Wazuh for approximately six months.
What do I think about the stability of the solution?
Wazuh is a stable solution.
What do I think about the scalability of the solution?
I have found Wazuh to be scalable.
We have approximately six people using the solution. We plan to increase the usage of the solution.
How are customer service and support?
I have not used the support from Wazuh.
Which solution did I use previously and why did I switch?
I have used Splunk previously.
How was the initial setup?
The installation of Wazuh is simple.
What about the implementation team?
We did the implementation of the solution ourselves.
We have six technicians supporting the solution.
What's my experience with pricing, setup cost, and licensing?
There is not a license required for Wazuh.
What other advice do I have?
My advice to others is Wazuh is a good starter solution but there are other more advanced solutions on the market, such as Splunk which is an industry-level solution.
I rate Wazuh a five out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security engineer at a tech services company with 51-200 employees
A flexible solution that can be used for instant response, security operations, and compliance
Pros and Cons
- "Wazuh's most beneficial features for our security needs are flexibility, built-in rules, integration capabilities, and documentation."
- "Wazuh should come up with more in-built rules and integrations for the cloud."
What is our primary use case?
We use Wazuh for internal testing, instant response, security operations, and compliance.
What is most valuable?
Wazuh's most beneficial features for our security needs are flexibility, built-in rules, integration capabilities, and documentation.
What needs improvement?
At the moment, we haven't tried the cloud version yet. My customers are mostly into the cloud. Wazuh should come up with more in-built rules and integrations for the cloud.
For how long have I used the solution?
I have been using Wazuh for one year.
What do I think about the stability of the solution?
I rate Wazuh seven and a half out of ten for stability.
What do I think about the scalability of the solution?
Around 10 users are using the solution in our organization.
How was the initial setup?
For a technical and experienced person, the solution's initial setup is easy. The setup would be a little hard for a non-technical person with less experience.
What about the implementation team?
The initial implementation and configuration may take a maximum of one week.
What's my experience with pricing, setup cost, and licensing?
Wazuh is not an expensive solution.
What other advice do I have?
If correctly configured, Wazuh can support threat detection and response for SMBs. Wazuh is a good solution if you can implement, integrate, and fine-tune it in the right way.
Overall, I rate Wazuh an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Chief Information Security Officer at a financial services firm with 501-1,000 employees
Stable with good MITRE ATT&CK correlation, but needs a better user interface
Pros and Cons
- "The MITRE ATT&CK correlation is most valuable."
- "Its user interface for sure can be improved. It is not so comfortable to use if you're looking for specific logs."
What is our primary use case?
We collect logs in it, and then we correlate logs against the MITRE ATT&CK framework. We have configured some notifications.
What is most valuable?
The MITRE ATT&CK correlation is most valuable.
What needs improvement?
Its user interface for sure can be improved. It is not so comfortable to use if you're looking for specific logs.
For how long have I used the solution?
I have been using this solution for the last two years.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
I am not sure about scalability. We have a total of seven users. Our department has two people, and there are five people from the IT department. We don't have any plans to increase its usage at this time.
How are customer service and technical support?
I didn't use their technical support.
How was the initial setup?
I was not involved in its installation. I am just using it.
What about the implementation team?
Other colleagues from the IT department handle its installation.
What other advice do I have?
For our usage, I would rate Wazuh a six out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
CBO at a security firm with 11-50 employees
Offers good log monitoring and analysis tools
Pros and Cons
- "The log monitoring and analysis tools are great in addition to SIEM file activity monitoring."
- "I think that the next release should be more suitable for large enterprises, because currently they are not because large companies do not rely on open source solutions."
What is most valuable?
The log monitoring and analysis tools are great in addition to SIEM file activity monitoring.
What needs improvement?
I think that the next release should be more suitable for large enterprises, because currently they are not because large companies do not rely on open source solutions.
For how long have I used the solution?
I have been working with this solution for about four months.
What do I think about the stability of the solution?
For mid-level customer, stability is okay.
What do I think about the scalability of the solution?
This is a scalable solution.
How are customer service and support?
Support needs to be purchased on an annual basis but the support required is excellent.
How was the initial setup?
The initial setup is rather complex and takes a few days to perform.
What's my experience with pricing, setup cost, and licensing?
This is a very price sensitive product.
What other advice do I have?
No hardware is required for this solution but be prepared to purchase implementation support. I would rate this solution a six or seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller

Buyer's Guide
Download our free Wazuh Report and get advice and tips from experienced pros
sharing their opinions.
Updated: March 2025
Product Categories
Log Management Security Information and Event Management (SIEM) Extended Detection and Response (XDR)Popular Comparisons
Dynatrace
Datadog
Splunk Enterprise Security
IBM Security QRadar
Elastic Security
Elastic Observability
Graylog
Grafana Loki
Security Onion
LogRhythm SIEM
Sumo Logic Security
Fortinet FortiAnalyzer
syslog-ng
Elastic Stack
Amazon CloudWatch
Buyer's Guide
Download our free Wazuh Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the difference between SIEM and Next-Gen SIEM solutions?
- When evaluating Log Management tools and software, what aspect do you think is the most important to look for?
- Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
- Which Windows event log monitoring tool do you recommend?
- What is the difference between log management and SIEM?
- Splunk vs. Elastic Stack
- How can Cloudtrail logs be used effectively to improve log monitoring?
- Why hot data and cold data differences in SIEM solutions are not discussed sufficiently?
- When evaluating Log Management solutions, what aspect do you think is the most important to look for?
- When evaluating Log Management solutions, what aspects do you think are the most important to look for?