No more typing reviews! Try our Samantha, our new voice AI agent.

NetWitness Platform vs Wazuh comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 3, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

NetWitness Platform
Ranking in Log Management
36th
Ranking in Security Information and Event Management (SIEM)
34th
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
36
Ranking in other categories
No ranking in other categories
Wazuh
Ranking in Log Management
2nd
Ranking in Security Information and Event Management (SIEM)
4th
Average Rating
7.4
Reviews Sentiment
5.9
Number of Reviews
51
Ranking in other categories
Extended Detection and Response (XDR) (3rd)
 

Mindshare comparison

As of September 2026, in the Security Information and Event Management (SIEM) category, the mindshare of NetWitness Platform is 1.1%, up from 0.7% compared to the previous year. The mindshare of Wazuh is 4.0%, down from 11.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
Wazuh4.0%
NetWitness Platform1.1%
Other94.9%
Security Information and Event Management (SIEM)
 

Featured Reviews

reviewer2256927 - PeerSpot reviewer
Head of Information Security, Cyber Defense and IT Risk Management at HCT. at a transportation company with 201-500 employees
A solid SIEM solution that should improve technical support and online resources to be easier to use
A big problem with the product is that we don't have much professional experience in Israel installing, implementing, and integrating this product. There is not enough of a knowledge base. There is no support for this product in this country, so problems have to be resolved through global technical teams. We like to work locally because of the language, and when the product is only supported outside the country, it's a little difficult to implement and use this product. Moreover, AI is something that must be added immediately. Artificial intelligence is a part of the competitors' products, and it's not been implemented for us.
Sudarson Prabhu - PeerSpot reviewer
Security Consultant at Payatu
File integrity monitoring has strengthened our data protection and supports compliance needs
I expected one thing from the dashboard in Wazuh. In ManageEngine, when you use ManageEngine, you can assign a unique ID to all employees. Then with the unique ID, if you search any unique ID in the dashboard itself, you can get the unique ID everywhere, including where the laptop has been logged in, when the logout happened, and what actions have been done for that unique ID. I expected the same in Wazuh, but whenever we want to check any monitoring activities for a specific person, we need to search for the endpoint and then get the endpoint details from our Active Directory or wherever we have the endpoint name stored in our resources, and then search for the endpoint to see the history for that specific endpoint only. This made a simple thing a bit complex. If we had a correlation of logs where I could just search one unique ID and then the unique ID pulls every system in a time-wise manner, that would be a great improvement I would suggest.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The development of use cases on the SSA console is quite user friendly, which means that the security analyst or the researcher does not have to learn another language."
"The product's initial setup phase was not at all difficult."
"The most valuable features are its ingestion of logs and raising of alerts based on those logs."
"It's quite economical compared to other solutions in the market."
"The most valuable feature is that we can create our own connectors for any application, and NetWitness provides the training and tools to do it."
"Packet Solution: Allows analyst proactive hunting and alerting on daily sophisticated APTs."
"Incident management is its most valuable feature."
"Once it is deployed and you are used to it, you can do whatever you want."
"Regarding Wazuh, I find the SCA (Security Configuration Assessment) features most valuable. It's crucial for asset management and inventory, allowing us to monitorendpoints and servers' changes easily. This is particularly important for my customers, who aren't heavily focused on incident response but rely on asset management and inventories. Wazuh's compliance management features are very supportive, especially in regions like the Americas and Europe. However, it's less effective in the ANZ (Australia and New Zealand) region since Wazuh doesn't cater to the specific compliance standards there, such as those required in Australia. I appreciate that Wazuh fully complies with PCI DSS and GDPR standards, allowing us to generate necessary reports."
"Overall, I rate Wazuh a nine out of ten."
"Wazuh is a powerful tool, and you can do lots of things with it."
"The reporting and attractive dashboard are the most valuable features."
"Wazuh's logging features integrate seamlessly with AWS cloud-native services. There are also Wazuh agent configurations for different use cases, like vulnerability scanning, host-based intrusion detection, and file integrity monitoring."
"Some of the strengths of Wazuh that stand out for us include its scalability when deployed on Azure, its open-source nature, which allows for customization based on our needs, and its compatibility with various security solutions like threat intelligence platforms."
"Wazuh offers numerous features, such as the ability to define custom rules for detecting malicious activities and remembering behaviors."
"My company implemented Wazuh because it was relatively inexpensive. They could quickly get their hands on it to check a box for some audit and compliance."
 

Cons

"Technical support could be improved."
"The tool's integration capability isn't so great."
"An area for improvement would be better automation and more inbuilt use cases."
"The solution is pretty complex to set up. Comparatively, I have worked on IBM QRadar and Splunk; they are much easier to set up."
"The system architecture is complex and sometimes it’s hard to troubleshoot potential problems."
"Security needs improvement. We would still like to know how the traffic is entering the organization."
"It is overly complicated. It has taken years to implement and the return on investment just isn't there."
"They should implement algorithms to digest that data and produce additional, more advanced reporting, alerting and support of internal security teams."
"It would be better if they had a vulnerability assessment plug-in like the one AlienVault has. In the next release, I would like to have an app with an alerting mechanism."
"The only challenge we faced with Wazuh was the lack of direct support."
"Since it's an open-source tool, scalability is the main issue."
"Wazuh has a drawback with regard to Unix systems. The solution does not allow us to do real-time monitoring for Unix systems. If usage increases, it would be a heavy fall on the other SIEM solutions or event monitoring solutions."
"Wazuh's scalability and out-of-the-box functionality are slightly lagging behind, but Wazuh has improved a lot since the first time we saw it."
"The tool doesn't detect anomalies or new environments."
"There could be a hardware monitoring tool for the solution."
"The support channel is not optimal, and extensive research is required on our part to implement Wazuh effectively."
 

Pricing and Cost Advice

"There is a licensing fee and the customer can choose whether he wishes this to be subscription-based or perpetual."
"We are on an annual license for the use of the solution."
"This is a pricey solution; it's not cheap."
"The licenses are good but the cost is very expensive."
"We have yearly licensing costs. The license fee can be based on the volume of EPS. Some organizations may have, as a gentlemanly gesture, 10,000 EPS and get a 3,000 EPS license but actually use 5,000 EPS."
"Many clients are not able to purchase the packet capability because there is a huge amount of data, and the cost depends on the number of EPS (Events per second), as well as the number of gigabytes of data per day."
"It’s cheaper to run virtual machines in a VMware environment."
"The tool is very expensive, so I rate the pricing a ten out of ten. The solution has an annual subscription."
"Wazuh is a cheaply priced product."
"Wazuh has a community edition, and I was using that. It's free and open source."
"Wazuh is not an expensive solution."
"We use the free version of Wazuh."
"Wazuh is open-source, therefore it is free. You can purchase support for $1,000 a year."
"Wazuh is free and open source."
"They have a good pricing strategy for market expansion."
"My client uses the open-source version of Wazuh."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
914,351 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Construction Company
13%
Financial Services Firm
11%
Comms Service Provider
11%
Outsourcing Company
10%
Comms Service Provider
13%
University
9%
Computer Software Company
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise7
Large Enterprise20
By reviewers
Company SizeCount
Small Business27
Midsize Enterprise15
Large Enterprise9
 

Questions from the Community

What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem ), though there could be potential enhancements by integrating with AI.
What is your primary use case for NetWitness Platform?
I use NetWitness Platform ( /products/netwitness-platform-reviews ) in the financial industry as a good product with excellent capabilities and integration with various devices.
What do you like most about Wazuh?
Wazuh is its flexibility and open-source nature, which allows us to tailor threat detection and response across diverse client environments. Its integration capabilities with SOAR, cloud platforms,...
What needs improvement with Wazuh?
I expected one thing from the dashboard in Wazuh. In ManageEngine, when you use ManageEngine, you can assign a unique ID to all employees. Then with the unique ID, if you search any unique ID in th...
What is your primary use case for Wazuh?
Our organization is focusing on the integrity part for implementing Wazuh. We were checking solutions for File Integrity Monitoring systems that are available online. Wazuh caught my attention as a...
 

Also Known As

RSA Security Analytics
Wazuh All-In-One Deployment
 

Overview

 

Sample Customers

Los Angeles World Airports, Reply
Information Not Available
Find out what your peers are saying about NetWitness Platform vs. Wazuh and other solutions. Updated: September 2026.
914,351 professionals have used our research since 2012.