Try our new research platform with insights from 80,000+ expert users

Logstash vs Wazuh comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Logstash
Ranking in Log Management
25th
Average Rating
9.0
Reviews Sentiment
5.6
Number of Reviews
5
Ranking in other categories
No ranking in other categories
Wazuh
Ranking in Log Management
1st
Average Rating
7.4
Reviews Sentiment
6.7
Number of Reviews
48
Ranking in other categories
Security Information and Event Management (SIEM) (2nd), Extended Detection and Response (XDR) (5th)
 

Mindshare comparison

As of July 2025, in the Log Management category, the mindshare of Logstash is 0.6%, up from 0.4% compared to the previous year. The mindshare of Wazuh is 13.7%, down from 15.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management
 

Featured Reviews

PRANIL CHANDARKAR - PeerSpot reviewer
Open-source accessibility and ease of implementation empower adaptable log management
As both a customer and an integrator, I think the best features in Logstash are that people prefer it because it is open to all, as it is an open-source version. The functionality of Logstash is quite easy to implement. I can say that the plugin ecosystem of Logstash is great. I have used some plugins for shell script monitoring and for SQL monitoring, and these are all working well with Logstash. The real-time processing capabilities of Logstash are also pretty fine with the tool. When I use the community edition, I have to do many things manually. If I am using enterprise Elastic, then that is taken care of by the Elastic native machine learning.
Sandip_Patel - PeerSpot reviewer
Evaluating robust file monitoring with insights for community support improvements
Wazuh's most valuable features include file monitoring and compliance reporting, which do not require excessive costs. These aspects are vital as they provide alerts for changes and facilitate the monitoring of compliance. The platform is also relatively easy to set up and operate. Reports are straightforward to extract and prove useful for compliance requirements.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I can collect logs from various data sources, including hardware."
"Everything aligns well with improving our organization."
"The transformation means we ship the logs in the way that we want them to be presented in Kibana, which is the main function we use Logstash for."
"Logstash has numerous plugins for inputs and outputs, allowing it to work well in environments that do not contain other Elastic components."
"We have three or four Logstash servers for high availability."
"I recommend Wazuh to everyone and believe more platforms, not just SIEM and XDR capability platforms, should be open source, allowing people to leverage these tools for the greater good."
"Wazuh's logging features integrate seamlessly with AWS cloud-native services. There are also Wazuh agent configurations for different use cases, like vulnerability scanning, host-based intrusion detection, and file integrity monitoring."
"I find the PCI DSS feature the most valuable, along with the feature that monitors the compliance of Windows and the CIS benchmarks on other devices like Unix or Linux systems."
"The product is easy to customize."
"We found the MITRE framework mapping and the agent enrollment service to be the most valuable features of Wazuh."
"It offers built-in modules for file integrity and vulnerability management."
"The tool is stable."
"I like the cloud-native infrastructure and that it's free. We didn't have to pay anything, and it has the capabilities of many premium solutions in the market. We could integrate all of our services and infrastructure in the cloud with Wazuh. From an integration point of view, Wazuh is pretty good. I had a good experience with this platform."
 

Cons

"An enhancement we could implement is the ability to cluster Logstash to exist in more than one node."
"We still have a problem with importing the log system."
"Almost all the research can be very bad. We still have a problem with importing the log system."
"Elastic does not provide proper support for Logstash worldwide, and I rate their technical support as one out of ten."
"There can be a UI to implement with Logstash. Currently, I have to work with config files and everything."
"The product needs to improve its compatibility."
"Its user interface for sure can be improved. It is not so comfortable to use if you're looking for specific logs."
"The implementation is very complex."
"The only challenge we faced with Wazuh was the lack of direct support."
"They could include flexibility and customization capabilities by modifying for customers based on partner agreements."
"It would be great if there could be customization for the decoder portion."
"The support channel is not optimal, and extensive research is required on our part to implement Wazuh effectively."
"Some features, like alerting, are complex with Wazuh."
"The tool does not provide CTI to monitor darknet."
 

Pricing and Cost Advice

Information not available
"Wazuh is free and open source."
"The solution's cost is above the average."
"It is a cost-effective solution."
"Wazuh is a cheaply priced product."
"The product is cheaper compared to other tools."
"Wazuh has a community edition, and I was using that. It's free and open source."
"Wazuh is an open-source tool, which means it is freely available for use."
"Wazuh is open-source, but you must consider the total cost of ownership. It may be free to acquire, but you spend a lot of time and effort supporting the product and getting it to a point where it's useful."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
864,053 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
17%
Computer Software Company
12%
Government
9%
Educational Organization
6%
Computer Software Company
15%
Comms Service Provider
9%
University
7%
Manufacturing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What do you like most about Logstash?
I can collect logs from various data sources, including hardware.
What needs improvement with Logstash?
An enhancement we could implement is the ability to cluster Logstash to exist in more than one node.
What is your primary use case for Logstash?
A use case for using Logstash that we have involves integration servers that log in files in a non-transformed way. We have more than four servers that log in files, and when we have an issue, we c...
What do you like most about Wazuh?
Wazuh is its flexibility and open-source nature, which allows us to tailor threat detection and response across diverse client environments. Its integration capabilities with SOAR, cloud platforms,...
What needs improvement with Wazuh?
That would require me to discuss with the Wazuh team regarding areas that could be improved, as I have numerous ideas. From a developer's perspective, this is a Linux system with an active communit...
What is your primary use case for Wazuh?
Wazuh is a SIEM platform with various applications in today's environment. Compliance checks have helped with regulatory requirements. I pulled in PCI DSS to check for file integrity monitoring. I ...
 

Comparisons

 

Overview

Find out what your peers are saying about Logstash vs. Wazuh and other solutions. Updated: July 2025.
864,053 professionals have used our research since 2012.