Sentinel vs Wazuh comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Sentinel
Ranking in Security Information and Event Management (SIEM)
16th
Average Rating
7.6
Number of Reviews
15
Ranking in other categories
No ranking in other categories
Wazuh
Ranking in Security Information and Event Management (SIEM)
3rd
Average Rating
7.4
Number of Reviews
38
Ranking in other categories
Log Management (2nd), Extended Detection and Response (XDR) (3rd)
 

Market share comparison

As of June 2024, in the Security Information and Event Management (SIEM) category, the market share of Sentinel is 5.7% and it increased by 508.3% compared to the previous year. The market share of Wazuh is 26.3% and it increased by 84.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM)
Unique Categories:
No other categories found
Log Management
20.2%
Extended Detection and Response (XDR)
17.0%
 

Featured Reviews

MS
Oct 20, 2022
Native integrations are hassle free and transactional user data enhances security
Our company uses the solution's management stack which has good integration with Sentinel.  We have not necessarily realized the power of the solution but find integrations with other products to be valuable. We are able to understand how access management applications are being used for…
Usman Arif - PeerSpot reviewer
Sep 21, 2023
Transforming security features with notable vulnerability reduction and comprehensive compliance
It is used primarily for event management in our organization, which falls into the category of an edge Intrusion Detection System (IDS) or host Internet protection system. Our company is not very large, with around twenty to thirty servers and approximately one hundred fifty to two hundred…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution lets us get all the logs properly and regularly monitor customer infrastructure."
"The stability is phenomenal and we never had any issues with downtime or even had to restart."
"The native integration with out-of-the box format is hassle free and allows data to be used advantageously."
"The tool is simple to use."
"It makes everything easier by automating some tasks and growing with our needs."
"Sentinel gave us logs to tell us what's going right and wrong in your environment so we could secure the network."
"One of the most valuable features is the business intelligence engine. It's very important because it keeps track of everything that's happening and alerts us if something is different than expected. The first time I used it, I was shocked at how well it performed. Another valuable feature that I think makes this product worth the price you pay for it is that it connects to basically every system that provides some form of logging, and it's very easy to set up what triggers this."
"The most valuable feature is the flexible log for identifying security threats inside an application. Sentinel is very good at this."
"The tool is stable."
"We use it to find any aberration in our endpoint devices. For example, if someone installs a game on their company laptop, Wazuh will detect it and inform us of the unauthorized software or unintended use of the devices provided by the company."
"I like the cloud-native infrastructure and that it's free. We didn't have to pay anything, and it has the capabilities of many premium solutions in the market. We could integrate all of our services and infrastructure in the cloud with Wazuh. From an integration point of view, Wazuh is pretty good. I had a good experience with this platform."
"Wazuh is free and easy to use. It is also adjustable, and we can use it on the cloud and on-premises."
"One of the most beneficial features of Wazuh, particularly in the context of security needs, is the machine learning data handling capability."
"The log monitoring and analysis tools are great in addition to SIEM file activity monitoring."
"The MITRE ATT&CK correlation is most valuable."
"Some of the strengths of Wazuh that stand out for us include its scalability when deployed on Azure, its open-source nature, which allows for customization based on our needs, and its compatibility with various security solutions like threat intelligence platforms."
 

Cons

"There is a need for more flexibility in customization, especially when working with different vendors and platforms."
"The dashboard and customer view should be improved"
"You need a lot of Unix scripting knowledge in order to manage the tool, which is one of the main issues that we faced."
"I rate Sentinel a six out of ten for scalability."
"There is no integration in the web-side of the tool."
"This product's connection to certain types of cloud systems could be improved. We can do Microsoft, Google, and Amazon, but there are a lot of other things happening in the cloud that we do not connect well enough to. This product could be improved with better connection to cloud-based solutions."
"Creating a drag-and-drop dashboard or workbook in Sentinel is a little more complex compared to other tools like LogRhythm and IBM QRadar."
"I would like to see a better reporting work structure on the dashboard."
"The tool doesn't detect anomalies or new environments."
"While it is scalable, it can suffer from reduced latencies."
"Since it's an open-source tool, scalability is the main issue."
"The support team could be more responsive and provide quicker replies during our working hours in Indonesia, which would be a significant improvement."
"The deployment is a bit complex."
"It would be better if they had a vulnerability assessment plug-in like the one AlienVault has. In the next release, I would like to have an app with an alerting mechanism."
"Wazuh is missing many things that a typical SIEM should have."
"There's not much I like about Wazuh. Other products I've used were a lot more functional and user friendly. They came with reports and use cases out of the box. We need to configure Wazuh's alerts and monitoring capabilities manually. It'd be nice if we could select from templates and presets for use cases already built and coded."
 

Pricing and Cost Advice

"Sentinel's slightly on the expensive side."
"Sentinel is a subscription-based solution."
"We inquired about getting support from the vendor, Micro Focus, but the cost was very high."
"The solution’s pricing is aligned with its competitors."
"Sentinel is moderately priced."
"We receive a pricing discount because of our ongoing partnership with Micro Focus."
"The product is cheaper compared to other tools."
"Wazuh is a good tool, but the open-source version has scalability limitations."
"Wazuh is totally free and open source. There are no licensing costs, only support costs if you need them."
"It is an open-source product."
"Wazuh is free and open source."
"Wazuh is an open-source tool, which means it is freely available for use."
"The solution's cost is above the average."
"It is a free-of-cost solution."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
787,061 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
17%
Government
11%
Financial Services Firm
10%
Manufacturing Company
8%
Computer Software Company
17%
Comms Service Provider
8%
Government
7%
Financial Services Firm
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about NetIQ Sentinel?
The solution lets us get all the logs properly and regularly monitor customer infrastructure.
What needs improvement with NetIQ Sentinel?
While it is great with Microsoft, there is a need for more flexibility in customization, especially when working with different vendors and platforms. Also, it would be helpful if we could easily s...
What do you like most about Wazuh?
Integrates with various open-source and paid products, allowing for flexibility in customization based on use cases.
What needs improvement with Wazuh?
I have built some rules that produce duplicate alerts two or three times. Therefore, these rules should be consolidated. Alerts should be specific rather than repeatedly triggered by integrating mu...
What is your primary use case for Wazuh?
We use Wazuh for the onboarding of both Windows and Linux machines, as well as for firewall and SIM configuration. The IP address is automatically blocked if a server has multiple wrong passwords.
 

Comparisons

 

Also Known As

NetIQ Sentinel, Novell SIEM
No data available
 

Learn More

 

Overview

 

Sample Customers

Faysal Bank, GaVI, Handelsbanken, ISC Mªnster, Lambeth Council, Swisscard, The Municipality of Siena, Tukes, University of Dayton, University of the Sunshine Coast
Information Not Available
Find out what your peers are saying about Sentinel vs. Wazuh and other solutions. Updated: June 2024.
787,061 professionals have used our research since 2012.