Fortinet FortiSIEM vs Wazuh comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jul 20, 2023
 

Categories and Ranking

Fortinet FortiSIEM
Ranking in Security Information and Event Management (SIEM)
10th
Average Rating
7.6
Number of Reviews
65
Ranking in other categories
No ranking in other categories
Wazuh
Ranking in Security Information and Event Management (SIEM)
3rd
Average Rating
7.4
Number of Reviews
39
Ranking in other categories
Log Management (2nd), Extended Detection and Response (XDR) (3rd)
 

Mindshare comparison

As of July 2024, in the Security Information and Event Management (SIEM) category, the mindshare of Fortinet FortiSIEM is 3.5%, up from 3.2% compared to the previous year. The mindshare of Wazuh is 15.3%, up from 10.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM)
Unique Categories:
No other categories found
Log Management
18.6%
Extended Detection and Response (XDR)
15.6%
 

Featured Reviews

MC
Jun 16, 2022
Integrates logs from different sources so that there is a common place to see and create dashboards
I work in our presales department. We have three of our clients using Fortinet FortiSIEM. The solution is useful to integrate logs from different sources so that there is a common place to see and create dashboards and the AI associated with event checking. We have a common service desk for our…
MB
Jun 15, 2023
Good for file integrity monitoring
There is room for improvement in Wazuh, but it's possible they are already working on it. The only challenge we faced with Wazuh was the lack of direct support. They charge for support, whether it's five days a week or seven days a week. We don't expect it to be free because revenue is generated through the support they provide. In future releases, I would like to see a feature. There is one feature we observed in a premium tool in the industry called Dynatrace. It provides automatic relations between different devices and components. For instance, if you receive a web login request, Dynatrace can trace and show you the path it takes from the firewall to the switch, then to the Apache server, the actual job application, and finally back to the client. It intelligently correlates all the components involved in a single event. If Wazuh could include this feature, where all the components are integrated, it would automatically relate them for any activity in your environment.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"AccelOps can handle a lot of data and it's just so important to true monitoring. Also, I can create a lot of rules to detect anything I like."
"Analytics is the most valuable feature. The business service summaries in the dashboards and the correlations for the SIEM are also valuable features."
"The product's initial setup phase was easy."
"The most valuable features for us are the built-in reports and alerts, along with the extreme flexibility in reporting and rule generation."
"The most valuable feature of Fortinet FortiSIEM is the user and entity behave as analytics(UEBA). This feature mixes your data and provides useful information based on the behavior of the targeted."
"FortiSIEM provides a single PIN to monitor SOC and NOC. It's a nice tool for integration and monitoring. It provides multiple categories for monitoring based on security designations like low, medium, and high."
"It gives us the opportunity to generate notifications based upon rules that get triggered, and the rules could be specific to PCI, HIPAA, GIBA, NIST, and so forth."
"The event correlation is pretty robust. The GUI is pretty good."
"Some of the strengths of Wazuh that stand out for us include its scalability when deployed on Azure, its open-source nature, which allows for customization based on our needs, and its compatibility with various security solutions like threat intelligence platforms."
"The most valuable feature of Wazuh is the ELK for doing an investigation."
"Integrates with various open-source and paid products, allowing for flexibility in customization based on use cases."
"I find the PCI DSS feature the most valuable, along with the feature that monitors the compliance of Windows and the CIS benchmarks on other devices like Unix or Linux systems."
"The product is easy to customize."
"It's very easy to integrate Wazuh with other environments, cloud applications, and on-prem applications. So, the advantage is that it's easy to implement and integrate with other solutions."
"The MITRE ATT&CK correlation is most valuable."
"Wazuh is free and easy to use. It is also adjustable, and we can use it on the cloud and on-premises."
 

Cons

"Our team tried configuring MS SQL database logs with Fortinet FortiSIEM, but it did not work for some time."
"Network detection and response is a separate product."
"Its training can be improved. Its price also needs to be improved."
"Fortinet FortiSIEM could improve by having better integration and extensions. This would benefit by allowing us to give more rules."
"It would be good if the solution offered even more configuration options, especially in relation to the VPN so that it continues to be a very flexible option."
"Customer support service could be better."
"The solution's interface could be modernized and improved."
"Does not have load-sharing or high-availability, and these are important things to implement. I can do the same things in another way, but not naturally having these features makes it complicated."
"One area where Wazuh could use some improvement is in its reporting mechanism, especially for high-level management like CSOs and CEOs."
"Adding the flexibility to integrate various plug-ins or modules into its core system would enhance functionality."
"Log data analysis could be improved. My IT team has been looking for an alternative because they want better log data for malware detection. We are also doing more container implementation also, so we need better container security, log data analysis, auditing and compliance, malware detection, etc."
"Since it's an open-source tool, scalability is the main issue."
"Wazuh currently fails to provide its users with AI and ML."
"A lack of certain features creates limitations."
"Wazuh is missing many things that a typical SIEM should have."
"They could include flexibility and customization capabilities by modifying for customers based on partner agreements."
 

Pricing and Cost Advice

"There are additional features that cost more than the standard licensing fees."
"The price of Fortinet FortiSIEM is a lot less when compared to other solutions."
"The price is competitive."
"Fortinet FortiSIEM is very cost-efficient compared to other SIEM solutions."
"The price of the solution is expensive. The license is scalable. If there are 10 devices it is simple to license."
"Pricing is determined based on the customer's budget."
"The price of Fortinet FortiSIEM was reasonable compared to other solutions."
"Please be cheaper and more simplified."
"Wazuh is an open-source tool, which means it is freely available for use."
"The current pricing is open source."
"Wazuh is open-source, so I think it's an option for a small organization that cannot go for enterprise-grade solutions like Splunk."
"My client uses the open-source version of Wazuh."
"We use the free version of Wazuh."
"There is not a license required for Wazuh."
"Wazuh is a good tool, but the open-source version has scalability limitations."
"Wazuh is open-source, but you must consider the total cost of ownership. It may be free to acquire, but you spend a lot of time and effort supporting the product and getting it to a point where it's useful."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
793,295 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
17%
Government
10%
Financial Services Firm
7%
Manufacturing Company
6%
Computer Software Company
17%
Government
7%
Manufacturing Company
7%
Financial Services Firm
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Fortinet FortiSIEM?
Fortinet FortiSIEM needs to provide better API integrations to users.
What is your experience regarding pricing and costs for Fortinet FortiSIEM?
I don't have the price list of any of the competitors of Fortinet FortiSIEM. I work with the technical part of the tool. There is a need to make yearly payments towards the licensing charges attach...
What needs improvement with Fortinet FortiSIEM?
Fortinet FortiSIEM is a better solution than other products. As a SIEM solution, it can meet all the requirements of customers. The product already offers good integration capabilities with multipl...
What do you like most about Wazuh?
Integrates with various open-source and paid products, allowing for flexibility in customization based on use cases.
What needs improvement with Wazuh?
I have built some rules that produce duplicate alerts two or three times. Therefore, these rules should be consolidated. Alerts should be specific rather than repeatedly triggered by integrating mu...
What is your primary use case for Wazuh?
We use Wazuh for the onboarding of both Windows and Linux machines, as well as for firewall and SIM configuration. The IP address is automatically blocked if a server has multiple wrong passwords.
 

Also Known As

FortiSIEM, AccelOps
No data available
 

Learn More

 

Overview

 

Sample Customers

FortiSIEM has hundreds of customers worldwide in markets including managed services, technology, financial services, healthcare, and government. Customers include Aruba Networks, Compushare, Port of San Diego, Cleveland Indians, Infoblox, Healthways, and Referentia.
Information Not Available
Find out what your peers are saying about Fortinet FortiSIEM vs. Wazuh and other solutions. Updated: July 2024.
793,295 professionals have used our research since 2012.