Comparison Buyer's Guide

Executive SummaryUpdated on Jun 7, 2024
 

Categories and Ranking

Security Onion
Ranking in Log Management
30th
Average Rating
7.6
Number of Reviews
3
Ranking in other categories
AWS Marketplace (1st)
Wazuh
Ranking in Log Management
2nd
Average Rating
7.4
Number of Reviews
39
Ranking in other categories
Security Information and Event Management (SIEM) (3rd), Extended Detection and Response (XDR) (3rd)
 

Mindshare comparison

As of July 2024, in the Log Management category, the mindshare of Security Onion is 6.4%, up from 0.0% compared to the previous year. The mindshare of Wazuh is 18.6%, up from 11.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management
Unique Categories:
AWS Marketplace
3.5%
Security Information and Event Management (SIEM)
15.3%
Extended Detection and Response (XDR)
15.6%
 

Featured Reviews

Jörg Kippe - PeerSpot reviewer
Jan 18, 2024
A mature and affordable solution that is easy to install and easy to update
The solution is used to learn how the tools work. It enables us to do consulting and demonstrate solutions. We develop attacks, detect them, and demonstrate how it works. The customers are interested in seeing how and what these tools can do We are only working with open-source products. The tool…
MB
Jun 15, 2023
Good for file integrity monitoring
There is room for improvement in Wazuh, but it's possible they are already working on it. The only challenge we faced with Wazuh was the lack of direct support. They charge for support, whether it's five days a week or seven days a week. We don't expect it to be free because revenue is generated through the support they provide. In future releases, I would like to see a feature. There is one feature we observed in a premium tool in the industry called Dynatrace. It provides automatic relations between different devices and components. For instance, if you receive a web login request, Dynatrace can trace and show you the path it takes from the firewall to the switch, then to the Apache server, the actual job application, and finally back to the client. It intelligently correlates all the components involved in a single event. If Wazuh could include this feature, where all the components are integrated, it would automatically relate them for any activity in your environment.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We use Security Onion for internal vulnerability assessment."
"The most valuable feature of Security Onion for security monitoring is its ability to find infected ports."
"Security Onion is the most mature solution in the market."
"Good for monitoring, active response, and for vulnerabilities."
"I like that the solution is on top of the Kubernetes stack."
"The deployment is easy and they provide very good documentation."
"The product’s interface is intuitive."
"It's stable."
"Wazuh's logging features integrate seamlessly with AWS cloud-native services. There are also Wazuh agent configurations for different use cases, like vulnerability scanning, host-based intrusion detection, and file integrity monitoring."
"The main thing I like about it is that it has an EDR."
"Some of the strengths of Wazuh that stand out for us include its scalability when deployed on Azure, its open-source nature, which allows for customization based on our needs, and its compatibility with various security solutions like threat intelligence platforms."
 

Cons

"The product is not easy to learn."
"Security Onion's user interface could be improved."
"The initial setup of the solution is a little bit difficult."
"Wazuh doesn't cover sources of events as well as Splunk. You can integrate Splunk with many sources of events, but it's a painful process to take care of some sources of events with Wazuh."
"I have yet to find the same capability in Wazuh to get logs from different sources into the system"
"One area where Wazuh could use some improvement is in its reporting mechanism, especially for high-level management like CSOs and CEOs."
"There's not much I like about Wazuh. Other products I've used were a lot more functional and user friendly. They came with reports and use cases out of the box. We need to configure Wazuh's alerts and monitoring capabilities manually. It'd be nice if we could select from templates and presets for use cases already built and coded."
"They need to go towards integrating with more cloud applications and not just OS like Windows and Linux."
"The implementation is very complex."
"I think that the next release should be more suitable for large enterprises, because currently they are not because large companies do not rely on open source solutions."
"It would be great if there could be customization for the decoder portion."
 

Pricing and Cost Advice

"Security Onion is a free solution."
"Security Onion is an open-source solution."
"It is an open-source solution."
"Wazuh is an open-source tool, which means it is freely available for use."
"Wazuh is open-source, but you must consider the total cost of ownership. It may be free to acquire, but you spend a lot of time and effort supporting the product and getting it to a point where it's useful."
"It is an open-source product."
"The solution's pricing is very competitive."
"The current pricing is open source."
"There is not a license required for Wazuh."
"Wazuh is open-source, therefore it is free. You can purchase support for $1,000 a year."
"It is a free-of-cost solution."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
793,295 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Government
11%
University
10%
Comms Service Provider
10%
Computer Software Company
17%
Government
7%
Manufacturing Company
7%
Financial Services Firm
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What do you like most about Security Onion?
The most valuable feature of Security Onion for security monitoring is its ability to find infected ports.
What is your experience regarding pricing and costs for Security Onion?
Security Onion is an open-source solution. On a scale from one to ten, where ten is expensive and one is cheap, I rate the solution's pricing a six out of ten.
What needs improvement with Security Onion?
The initial setup of the solution is a little bit difficult.
What do you like most about Wazuh?
Integrates with various open-source and paid products, allowing for flexibility in customization based on use cases.
What needs improvement with Wazuh?
I have built some rules that produce duplicate alerts two or three times. Therefore, these rules should be consolidated. Alerts should be specific rather than repeatedly triggered by integrating mu...
What is your primary use case for Wazuh?
We use Wazuh for the onboarding of both Windows and Linux machines, as well as for firewall and SIM configuration. The IP address is automatically blocked if a server has multiple wrong passwords.
 

Comparisons

 

Overview

Find out what your peers are saying about Security Onion vs. Wazuh and other solutions. Updated: July 2024.
793,295 professionals have used our research since 2012.