No more typing reviews! Try our Samantha, our new voice AI agent.

TrendAI Vision One – Network Security vs Wazuh comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 26, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Extended Detection and Response (XDR)
4th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
114
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (6th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
TrendAI Vision One – Networ...
Ranking in Extended Detection and Response (XDR)
31st
Average Rating
9.0
Reviews Sentiment
5.7
Number of Reviews
1
Ranking in other categories
No ranking in other categories
Wazuh
Ranking in Extended Detection and Response (XDR)
6th
Average Rating
7.4
Reviews Sentiment
5.9
Number of Reviews
51
Ranking in other categories
Log Management (2nd), Security Information and Event Management (SIEM) (3rd)
 

Mindshare comparison

As of July 2026, in the Extended Detection and Response (XDR) category, the mindshare of Cortex XDR by Palo Alto Networks is 4.6%, down from 5.1% compared to the previous year. The mindshare of TrendAI Vision One – Network Security is 0.6%, up from 0.1% compared to the previous year. The mindshare of Wazuh is 4.9%, down from 10.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Extended Detection and Response (XDR) Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks4.6%
Wazuh4.9%
TrendAI Vision One – Network Security0.6%
Other89.9%
Extended Detection and Response (XDR)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
reviewer2793894 - PeerSpot reviewer
Platform Engineer Ii at a outsourcing company with 5,001-10,000 employees
Network visibility has improved and detects zero-day threats and lateral movement swiftly
Trend Vision One - Network Security can be improved by integrating with the native firewall and bringing in that telemetry feed.I would like to see more telemetry coming in from the risk-based factor so that there should be risk-based tagging across all assets within the organization, specifically focusing on threats related to lateral movement and ransomware. This risk-based scoring is required.
RS
Engineer Information Security at N-Able (Pvt) Ltd
Has faced limitations in AI capabilities and pricing flexibility
Pricing-wise, Wazuh stands out, along with deployment flexibility and its documentation which is extremely good in comparison to Forti. The community support is also incredible. They have helped quite a bit because previously, we had a separate tool and management dashboard to do our compliance. With Wazuh, we receive that information without having to do anything extra. We just set up the SIEM and all of that information was automatically populated. The dashboards are very easy to understand and very quick with no lag or delay. I have experienced delays on Forti's dashboards, but not with Wazuh. Wazuh is quite good. In comparison to Forti, they are quite similar. They are very good at detection.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The anti-exploit is impenetrable. We chose Traps because it is the only product that we were not able to get anything past."
"Cortex XDR by Palo Alto Networks has helped lighten the load of our security analysts because it was the major tool that we were using and the one we utilized most."
"Traps is quite a stable product. Once it was properly deployed and configured, you have nothing to be worried about."
"In one single alert, we are getting the network telemetry, endpoint telemetry, email security telemetry, and proxy telemetry all in one single ticket, making it very easy."
"Cortex covers everything I need. It's a perfect solution. Cortex provides a different level of visibility because it's an extended EDR, allowing you to grab logs from the network and firewalls. Palo Alto invented the concept of the extended EDR or XDR."
"The product is very good, it has caught a lot of exploits that most products would not."
"Cortex is a very good total solution on the endpoints."
"If you are looking to deploy a security solution as a whole, this is a good option."
"Trend Vision One - Network Security has positively impacted my organization as our network operations team has found it very useful for monitoring all threats coming in via the network layer and taking swift actions compared to earlier."
"The deployment is easy and they provide very good documentation."
"Wazuh offers numerous features, such as the ability to define custom rules for detecting malicious activities and remembering behaviors."
"I like that the solution is on top of the Kubernetes stack."
"The solution is easy to maintain."
"I would recommend Wazuh to others."
"The configuration assessment and Pile integrity monitoring features are decent."
"Good for monitoring, active response, and for vulnerabilities."
"Wazuh offers an enhanced HDR version that outperforms its competitors."
 

Cons

"It would be good if they could make an exception for applications. Sometimes, it can be a bit of a challenge to make exceptions for certain applications that have been used as rogue."
"I would like to see some additional features related to email protection included."
"Traps doesn't work with McAfee. You need to remove McAfee to install Traps. This is very common, and its nothing that should be an issue. Some antivirus engines recognize Traps as an threat component, so maybe they need to shake hands somewhere."
"I would like to see improvement in the tool's user interface, particularly in the area of managing alerts and providing more reporting capabilities."
"In terms of areas of improvement, we have not completed our review of the product. We're also looking at other products. So, it's a little bit hard to tell what could be different because we have not completed the review of this product, but based on our experience so far, its implementation is quite complex."
"The solution should enhance the ADR and reporting."
"It's not an ideal choice for smaller businesses, as you need a minimum of 200 endpoints to even use the solution at all."
"It would be better if they could educate the customers more. Some sort of seminars and roadshows will help educate the customers and show what the product can do. The price could be better. It would also help if they had a team for deployment and support."
"Trend Vision One - Network Security can be improved by integrating with the native firewall and bringing in that telemetry feed."
"There's not much I like about Wazuh. Other products I've used were a lot more functional and user friendly. They came with reports and use cases out of the box. We need to configure Wazuh's alerts and monitoring capabilities manually. It'd be nice if we could select from templates and presets for use cases already built and coded."
"The lack of AI features is an issue at the moment in the industry."
"They could include flexibility and customization capabilities by modifying for customers based on partner agreements."
"Scalability is a constraint in the on-prem version of Wazuh in terms of the volume of logs we can manage."
"The computing resources are consuming and do not make sense."
"Log data analysis could be improved. My IT team has been looking for an alternative because they want better log data for malware detection. We are also doing more container implementation also, so we need better container security, log data analysis, auditing and compliance, malware detection, etc."
"When I face a challenge, I prefer not to spend too much time on it and may move to another solution that will give us the results."
"Wazuh should come up with more in-built rules and integrations for the cloud."
 

Pricing and Cost Advice

"It has a higher cost than other solutions, like CrowdStrike or Microsoft’s EDR tools, but it reduces the cost of our operations because it’s a new generation antivirus tool."
"Compared to CrowdStrike, Cortex XDR is an expensive solution."
"Our license will require renewal in August, after which the maintenance will continue as usual."
"It is cost-effective compared to similar solutions. It fits for the small businesses through to the big businesses."
"I don't recall what the cost was, but it wasn't really that expensive."
"Every customer has to pay for a license because it doesn't work with what you get from a managed services provider."
"In terms of the cost Cortex XDR by Palo Alto Networks is very expensive because we are a Mexican company and when you translate dollars to pesos the cost is very high. The solution is very expensive for Mexican companies. I understand that they have international prices, but I do not think it offsets the price enough for many companies in countries, such as Mexico. The amount it is reduced is not a massive percentage."
"Our customers have expressed that the price is high."
Information not available
"When I contacted customer care, they mentioned bundling options, that I found to be overall affordable."
"It is a cost-effective solution."
"The current pricing is open source."
"We use the free version of Wazuh."
"My client uses the open-source version of Wazuh."
"Wazuh is totally free and open source. There are no licensing costs, only support costs if you need them."
"It is an open-source product."
"The solution's pricing is very competitive."
report
Use our free recommendation engine to learn which Extended Detection and Response (XDR) solutions are best for your needs.
905,526 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
12%
Financial Services Firm
11%
Manufacturing Company
10%
Comms Service Provider
9%
No data available
Comms Service Provider
11%
Computer Software Company
10%
University
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise21
Large Enterprise53
No data available
By reviewers
Company SizeCount
Small Business27
Midsize Enterprise15
Large Enterprise9
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What is your experience regarding pricing and costs for Trend Vision One - Network Security?
My experience with pricing, setup cost, and licensing was straightforward and seamless.
What needs improvement with Trend Vision One - Network Security?
Trend Vision One - Network Security can be improved by integrating with the native firewall and bringing in that tele...
What is your primary use case for Trend Vision One - Network Security?
My main use case for Trend Vision One - Network Security is to protect from zero-day threats, specifically by detecti...
What do you like most about Wazuh?
Wazuh is its flexibility and open-source nature, which allows us to tailor threat detection and response across diver...
What needs improvement with Wazuh?
Regarding compliance, I find it not stable. I do not recommend it for that purpose. It can comply with Wazuh NCA, whi...
What is your primary use case for Wazuh?
I have been working with Wazuh for two years, and I can explain how I use Wazuh. I did not use Wazuh as a SIEM soluti...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
Trend Cloud One Network Security
Wazuh All-In-One Deployment
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Information Not Available
Information Not Available
Find out what your peers are saying about CrowdStrike, SentinelOne, TrendAI and others in Extended Detection and Response (XDR). Updated: July 2026.
905,526 professionals have used our research since 2012.