No more typing reviews! Try our Samantha, our new voice AI agent.

CrowdStrike Falcon Next-Gen SIEM vs Wazuh comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.6
CrowdStrike Falcon's impact varied, showing clear ROI for some but unclear results for others, enhancing team cohesion and response speed.
Sentiment score
3.3
Wazuh offers rapid threat response and cost-effective security, benefiting small businesses with significant savings and no proprietary costs.
The impact of this consolidation has resulted in greater team cohesion, greater team efficacy, and greater speed of response.
Security Operations at a financial services firm with 5,001-10,000 employees
I have definitely seen a return on my investment with this solution.
IAM Senior Software Engineer at MGM Resorts International
I have seen value in security cost savings with Wazuh, as using proprietary EDR versions could save us substantial money.
Security Consultant at ebenezer.okoh@agorasecurity.it
 

Customer Service

Sentiment score
8.3
CrowdStrike Falcon Next-Gen SIEM support is praised for rapid, skilled, empathetic service and effective issue resolution.
Sentiment score
3.0
Wazuh offers valuable community forums and support, with a preference for cloud services despite occasional response time delays.
What makes the customer service great is that support is both technically sound and empathetic in their understanding of different situations.
Security Operations at a financial services firm with 5,001-10,000 employees
We have never had an issue, and if we ask, somebody answers quickly, either our account rep or if we submit a ticket, they are very quick about getting back to us.
System Administrator at W. O. Grubb Steel Erection, Inc.
They responded quickly, which was crucial as I was on a time constraint.
Cyber Security Software Engineer at a tech services company with 11-50 employees
We use the open-source version of Wazuh, which does not provide paid support.
Tech Lead at a tech vendor with 201-500 employees
The documentation is good and provides clear instructions, though it's targeted at those with technical backgrounds.
Student at Dakota State University
 

Scalability Issues

Sentiment score
8.2
CrowdStrike Falcon Next-Gen SIEM is highly scalable, user-friendly, and prepared for future growth beyond current organizational needs.
Sentiment score
6.4
Wazuh is seen as scalable, fitting small to medium businesses, with potential challenges in larger data and sectors.
CrowdStrike Falcon Next-Gen SIEM scales effectively with the growing needs of my organization.
Security Operations at a financial services firm with 5,001-10,000 employees
I would say that CrowdStrike Falcon Next-Gen SIEM scales with the growing needs of my organization.
Avp Cyber Pen Test Master
CrowdStrike Falcon Next-Gen SIEM scales with the growing needs of my organization.
System Administrator at W. O. Grubb Steel Erection, Inc.
It can accommodate thousands of endpoints on one instance, and multiple instances can run for different clients.
Security Operations Center Analyst at mailbox.org
Currently, I don't see any limitations in terms of scalability as Wazuh can still connect many endpoints.
Security Consultant at ebenezer.okoh@agorasecurity.it
This is because of the backend work the agent is collecting and processing, causing the laptop to slow down and the bandwidth to decrease.
Security Consultant at Payatu
 

Stability Issues

Sentiment score
8.2
CrowdStrike Falcon Next-Gen SIEM is reliable, with seamless integration, solid performance, minimal downtime, and excellent user ratings.
Sentiment score
6.3
Wazuh is reliable for small to mid-level businesses, despite occasional bugs and maintenance challenges affecting stability.
I have experienced very minimal downtime, crashes, or performance issues with CrowdStrike Falcon Next-Gen SIEM.
Security Operations at a financial services firm with 5,001-10,000 employees
I would describe the stability and reliability of CrowdStrike Falcon Next-Gen SIEM as really good, as it is stable and reliable, triggering everything and figuring out everything, so it saves a lot of time.
Avp Cyber Pen Test Master
I assess the stability and reliability of CrowdStrike Falcon Next-Gen SIEM as 10 out of 10.
System Administrator at W. O. Grubb Steel Erection, Inc.
The stability of Wazuh is strong, with no issues stemming from the solution itself.
Tech Lead at a tech vendor with 201-500 employees
The stability of Wazuh is largely dependent on maintenance.
Security Operations Center Analyst at mailbox.org
The indexer frequently times out, requiring system restarts.
Cyber Security Software Engineer at a tech services company with 11-50 employees
 

Room For Improvement

CrowdStrike Falcon SIEM needs better dashboards, automation, storage, licensing flexibility, and more cat-themed threat actor integrations.
Wazuh faces scalability and integration issues, needing enhanced security, AI features, and better support for large enterprises.
I would suggest including data normalization, specifically a way to easily normalize data from different sources, as currently you can do it, but it is a little bit more labor-intensive.
System Administrator at W. O. Grubb Steel Erection, Inc.
If we can get alerts based upon the CPU utilizations and the metrics over there, probably that would make this one tool used for everything.
IAM Senior Software Engineer at MGM Resorts International
I believe CrowdStrike Falcon Next-Gen SIEM can be improved by continuing on the path it is on.
Security Operations at a financial services firm with 5,001-10,000 employees
Machine learning is needed along with understanding user behavior and behavioral patterns.
Engineer Information Security at N-Able (Pvt) Ltd
If we had a correlation of logs where I could just search one unique ID and then the unique ID pulls every system in a time-wise manner, that would be a great improvement I would suggest.
Security Consultant at Payatu
The integration modules are insufficiently developed, necessitating the creation of custom integration solutions using tools like Logstash and PubSub.
Tech Lead at a tech vendor with 201-500 employees
 

Setup Cost

Wazuh's open-source solution is cost-effective for enterprises, with cloud costs and scalability as key considerations.
Wazuh is completely free of charge.
Security Consultant at ebenezer.okoh@agorasecurity.it
I would definitely recommend Wazuh, especially considering Fortinet's licensing model which is confusing and overpriced in my opinion.
Engineer Information Security at N-Able (Pvt) Ltd
Totaling around two lakh Indian rupees per month.
Tech Lead at a tech vendor with 201-500 employees
 

Valuable Features

CrowdStrike Falcon Next-Gen SIEM enhances speed, integrates data sources, scales efficiently, and improves detection accuracy, reducing workload.
Wazuh offers open-source security solutions with cloud integration, exceptional logging, scalability, and compatibility with platforms like Azure and AWS.
CrowdStrike Falcon Next-Gen SIEM has had a significant impact on alert volume, false positives, and analyst workload by using lookup tables to improve detection context.
Security Operations at a financial services firm with 5,001-10,000 employees
CrowdStrike Falcon Next-Gen SIEM has changed the speed at which my team searches, investigates, and responds to security events, with things going from days to minutes or hours.
System Administrator at W. O. Grubb Steel Erection, Inc.
CrowdStrike Falcon Next-Gen SIEM has changed the speed at which my team searches, investigates, and responds to security events significantly, as it triggers really fast, allowing us to capture the logs and determine the problem or the alerts.
Avp Cyber Pen Test Master
Wazuh is a SIEM tool that is highly customizable and versatile.
Security Operations Center Analyst at mailbox.org
The system allows us to monitor endpoints effectively and collect security data that can be utilized across other platforms such as SOAR.
Security Consultant at ebenezer.okoh@agorasecurity.it
With this open source tool, organizations can establish their own customized setup.
Cyber Security Software Engineer at a tech services company with 11-50 employees
 

Categories and Ranking

CrowdStrike Falcon Next-Gen...
Ranking in Security Information and Event Management (SIEM)
95th
Average Rating
9.8
Reviews Sentiment
7.6
Number of Reviews
4
Ranking in other categories
No ranking in other categories
Wazuh
Ranking in Security Information and Event Management (SIEM)
4th
Average Rating
7.4
Reviews Sentiment
5.9
Number of Reviews
51
Ranking in other categories
Log Management (2nd), Extended Detection and Response (XDR) (3rd)
 

Featured Reviews

KS
IAM Senior Software Engineer at MGM Resorts International
Centralized log onboarding has transformed root-cause analysis and streamlined alert-driven triage
I do not use automations within CrowdStrike Falcon Next-Gen SIEM at this point, but that is something that we want to do in the future. Maybe I did not experiment or did not investigate, but if we can get alerts based upon the CPU utilizations and the metrics over there, probably that would make this one tool used for everything. Actually, the circumstances that prompted my company to explore new SIEM solutions maybe include a point where the storage space or the license that we have, probably compared to other SIEM products, they have more, or the pricing and sales that go into the picture there. Again, that is above my pay grade to comment on, but it probably could be better if we can provide more storage of the data for the license that has been provided for organizations.
Sudarson Prabhu - PeerSpot reviewer
Security Consultant at Payatu
File integrity monitoring has strengthened our data protection and supports compliance needs
I expected one thing from the dashboard in Wazuh. In ManageEngine, when you use ManageEngine, you can assign a unique ID to all employees. Then with the unique ID, if you search any unique ID in the dashboard itself, you can get the unique ID everywhere, including where the laptop has been logged in, when the logout happened, and what actions have been done for that unique ID. I expected the same in Wazuh, but whenever we want to check any monitoring activities for a specific person, we need to search for the endpoint and then get the endpoint details from our Active Directory or wherever we have the endpoint name stored in our resources, and then search for the endpoint to see the history for that specific endpoint only. This made a simple thing a bit complex. If we had a correlation of logs where I could just search one unique ID and then the unique ID pulls every system in a time-wise manner, that would be a great improvement I would suggest.
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
914,394 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
No data available
Comms Service Provider
13%
University
9%
Computer Software Company
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business27
Midsize Enterprise15
Large Enterprise9
 

Questions from the Community

What is your experience regarding pricing and costs for CrowdStrike Falcon Next-Gen SIEM?
Pricing, setup costs, and licensing of CrowdStrike Falcon Next-Gen SIEM is not my area.
What needs improvement with CrowdStrike Falcon Next-Gen SIEM?
I do not use automations within CrowdStrike Falcon Next-Gen SIEM at this point, but that is something that we want to do in the future. Maybe I did not experiment or did not investigate, but if we ...
What is your primary use case for CrowdStrike Falcon Next-Gen SIEM?
I work on Identity Governance for this solution. We onboard the logs into the SIEM, into CrowdStrike Falcon, and we ensure that we get alerts on time and create dashboards using that data. Our work...
What do you like most about Wazuh?
Wazuh is its flexibility and open-source nature, which allows us to tailor threat detection and response across diverse client environments. Its integration capabilities with SOAR, cloud platforms,...
What needs improvement with Wazuh?
I expected one thing from the dashboard in Wazuh. In ManageEngine, when you use ManageEngine, you can assign a unique ID to all employees. Then with the unique ID, if you search any unique ID in th...
What is your primary use case for Wazuh?
Our organization is focusing on the integrity part for implementing Wazuh. We were checking solutions for File Integrity Monitoring systems that are available online. Wazuh caught my attention as a...
 

Comparisons

No data available
 

Also Known As

No data available
Wazuh All-In-One Deployment
 

Overview

Find out what your peers are saying about CrowdStrike Falcon Next-Gen SIEM vs. Wazuh and other solutions. Updated: September 2026.
914,394 professionals have used our research since 2012.