We are using Wazuh for our SOC environment. We are managing and monitoring our infrastructure using the Wazuh SIEM
Tech Lead Security at a comms service provider with 51-200 employees
Poor detection, lacking features, but simple installation
Pros and Cons
- "The most valuable feature of Wazuh is the ELK for doing an investigation."
- "Wazuh could improve the detection, it is not detecting all of the attacks. Additionally, it is lacking features compared to other solutions."
What is our primary use case?
What is most valuable?
The most valuable feature of Wazuh is the ELK for doing an investigation.
What needs improvement?
Wazuh could improve the detection, it is not detecting all of the attacks. Additionally, it is lacking features compared to other solutions.
For how long have I used the solution?
I have been using Wazuh for approximately six months.
Buyer's Guide
Wazuh
October 2024
Learn what your peers think about Wazuh. Get advice and tips from experienced pros sharing their opinions. Updated: October 2024.
816,406 professionals have used our research since 2012.
What do I think about the stability of the solution?
Wazuh is a stable solution.
What do I think about the scalability of the solution?
I have found Wazuh to be scalable.
We have approximately six people using the solution. We plan to increase the usage of the solution.
How are customer service and support?
I have not used the support from Wazuh.
Which solution did I use previously and why did I switch?
I have used Splunk previously.
How was the initial setup?
The installation of Wazuh is simple.
What about the implementation team?
We did the implementation of the solution ourselves.
We have six technicians supporting the solution.
What's my experience with pricing, setup cost, and licensing?
There is not a license required for Wazuh.
What other advice do I have?
My advice to others is Wazuh is a good starter solution but there are other more advanced solutions on the market, such as Splunk which is an industry-level solution.
I rate Wazuh a five out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security engineer at a tech services company with 51-200 employees
A flexible solution that can be used for instant response, security operations, and compliance
Pros and Cons
- "Wazuh's most beneficial features for our security needs are flexibility, built-in rules, integration capabilities, and documentation."
- "Wazuh should come up with more in-built rules and integrations for the cloud."
What is our primary use case?
We use Wazuh for internal testing, instant response, security operations, and compliance.
What is most valuable?
Wazuh's most beneficial features for our security needs are flexibility, built-in rules, integration capabilities, and documentation.
What needs improvement?
At the moment, we haven't tried the cloud version yet. My customers are mostly into the cloud. Wazuh should come up with more in-built rules and integrations for the cloud.
For how long have I used the solution?
I have been using Wazuh for one year.
What do I think about the stability of the solution?
I rate Wazuh seven and a half out of ten for stability.
What do I think about the scalability of the solution?
Around 10 users are using the solution in our organization.
How was the initial setup?
For a technical and experienced person, the solution's initial setup is easy. The setup would be a little hard for a non-technical person with less experience.
What about the implementation team?
The initial implementation and configuration may take a maximum of one week.
What's my experience with pricing, setup cost, and licensing?
Wazuh is not an expensive solution.
What other advice do I have?
If correctly configured, Wazuh can support threat detection and response for SMBs. Wazuh is a good solution if you can implement, integrate, and fine-tune it in the right way.
Overall, I rate Wazuh an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Wazuh
October 2024
Learn what your peers think about Wazuh. Get advice and tips from experienced pros sharing their opinions. Updated: October 2024.
816,406 professionals have used our research since 2012.
CBO at a security firm with 11-50 employees
Offers good log monitoring and analysis tools
Pros and Cons
- "The log monitoring and analysis tools are great in addition to SIEM file activity monitoring."
- "I think that the next release should be more suitable for large enterprises, because currently they are not because large companies do not rely on open source solutions."
What is most valuable?
The log monitoring and analysis tools are great in addition to SIEM file activity monitoring.
What needs improvement?
I think that the next release should be more suitable for large enterprises, because currently they are not because large companies do not rely on open source solutions.
For how long have I used the solution?
I have been working with this solution for about four months.
What do I think about the stability of the solution?
For mid-level customer, stability is okay.
What do I think about the scalability of the solution?
This is a scalable solution.
How are customer service and support?
Support needs to be purchased on an annual basis but the support required is excellent.
How was the initial setup?
The initial setup is rather complex and takes a few days to perform.
What's my experience with pricing, setup cost, and licensing?
This is a very price sensitive product.
What other advice do I have?
No hardware is required for this solution but be prepared to purchase implementation support. I would rate this solution a six or seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Chief Information Security Officer at a financial services firm with 501-1,000 employees
Stable with good MITRE ATT&CK correlation, but needs a better user interface
Pros and Cons
- "The MITRE ATT&CK correlation is most valuable."
- "Its user interface for sure can be improved. It is not so comfortable to use if you're looking for specific logs."
What is our primary use case?
We collect logs in it, and then we correlate logs against the MITRE ATT&CK framework. We have configured some notifications.
What is most valuable?
The MITRE ATT&CK correlation is most valuable.
What needs improvement?
Its user interface for sure can be improved. It is not so comfortable to use if you're looking for specific logs.
For how long have I used the solution?
I have been using this solution for the last two years.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
I am not sure about scalability. We have a total of seven users. Our department has two people, and there are five people from the IT department. We don't have any plans to increase its usage at this time.
How are customer service and technical support?
I didn't use their technical support.
How was the initial setup?
I was not involved in its installation. I am just using it.
What about the implementation team?
Other colleagues from the IT department handle its installation.
What other advice do I have?
For our usage, I would rate Wazuh a six out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Wazuh Report and get advice and tips from experienced pros
sharing their opinions.
Updated: October 2024
Product Categories
Log Management Security Information and Event Management (SIEM) Extended Detection and Response (XDR)Popular Comparisons
Splunk Enterprise Security
Dynatrace
Datadog
IBM Security QRadar
Elastic Security
Elastic Observability
Graylog
LogRhythm SIEM
Sumo Logic Security
Grafana Loki
Devo
Security Onion
Fortinet FortiAnalyzer
syslog-ng
Amazon CloudWatch
Buyer's Guide
Download our free Wazuh Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the difference between SIEM and Next-Gen SIEM solutions?
- When evaluating Log Management tools and software, what aspect do you think is the most important to look for?
- Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
- Which Windows event log monitoring tool do you recommend?
- What is the difference between log management and SIEM?
- Splunk vs. Elastic Stack
- How can Cloudtrail logs be used effectively to improve log monitoring?
- Why hot data and cold data differences in SIEM solutions are not discussed sufficiently?
- When evaluating Log Management solutions, what aspect do you think is the most important to look for?
- When evaluating Log Management solutions, what aspects do you think are the most important to look for?