

WithSecure Elements Endpoint Detection and Response and Wazuh compete in the endpoint security solutions category. Wazuh seems to have an edge due to its feature depth and cost-effectiveness, which caters to users with technical expertise who are willing to invest time in configuration.
Features: WithSecure Elements Endpoint Detection and Response offers advanced threat detection, seamless integration with WithSecure offerings, and robust defense mechanisms. Wazuh provides extensive customization, open-source flexibility, and integration with various tools, alongside its ability to monitor compliance with security standards.
Room for Improvement: WithSecure could enhance its customizability and adaptability to different security operations. Greater integration capabilities with third-party tools would be beneficial. Meanwhile, Wazuh could improve its ease of deployment to reduce the technical expertise required and enhance out-of-the-box user experience. Superior documentation for users unfamiliar with open-source solutions and enhanced direct customer support could also be beneficial.
Ease of Deployment and Customer Service: WithSecure is characterized by rapid deployment processes and high-quality customer service, providing a more guided onboarding experience. Wazuh's deployment can be more complicated, favoring those with technical knowledge, though it benefits from a supportive community for troubleshooting and configuration assistance.
Pricing and ROI: WithSecure tends to have a higher initial cost due to its comprehensive support and integration features, offering significant ROI for organizations valuing premium service. Wazuh offers substantial initial cost savings with its open-source model, reducing expenditure and boosting ROI rapidly via minimal licensing fees, hence ideal for budget-conscious organizations.
I have seen value in security cost savings with Wazuh, as using proprietary EDR versions could save us substantial money.
They responded quickly, which was crucial as I was on a time constraint.
We use the open-source version of Wazuh, which does not provide paid support.
The documentation is good and provides clear instructions, though it's targeted at those with technical backgrounds.
It can accommodate thousands of endpoints on one instance, and multiple instances can run for different clients.
Currently, I don't see any limitations in terms of scalability as Wazuh can still connect many endpoints.
Scalability depends on the configuration and the infrastructure resources like compute and memory we allocate.
The stability of Wazuh is strong, with no issues stemming from the solution itself.
The stability of Wazuh is largely dependent on maintenance.
The indexer frequently times out, requiring system restarts.
The system is stable with WithSecure Elements Endpoint Detection and Response.
Machine learning is needed along with understanding user behavior and behavioral patterns.
The integration modules are insufficiently developed, necessitating the creation of custom integration solutions using tools like Logstash and PubSub.
I think Wazuh should improve by introducing AI functionalities, as it would be beneficial to see AI incorporated in the threat hunting and detection functionalities.
Wazuh is completely free of charge.
I would definitely recommend Wazuh, especially considering Fortinet's licensing model which is confusing and overpriced in my opinion.
Totaling around two lakh Indian rupees per month.
Wazuh is a SIEM tool that is highly customizable and versatile.
The system allows us to monitor endpoints effectively and collect security data that can be utilized across other platforms such as SOAR.
With this open source tool, organizations can establish their own customized setup.
| Product | Market Share (%) |
|---|---|
| Wazuh | 7.9% |
| WithSecure Elements Endpoint Detection and Response | 0.7% |
| Other | 91.4% |

| Company Size | Count |
|---|---|
| Small Business | 27 |
| Midsize Enterprise | 15 |
| Large Enterprise | 8 |
| Company Size | Count |
|---|---|
| Small Business | 6 |
| Large Enterprise | 1 |
Wazuh offers an open-source platform designed for seamless integration into diverse environments, making it ideal for enhancing security infrastructure. Its features include log monitoring, compliance support, and real-time threat detection, providing effective cybersecurity management.
Wazuh stands out for its ability to integrate easily with Kubernetes, cloud-native infrastructures, and various SIEM platforms like ELK. It features robust MITRE ATT&CK correlation, comprehensive log monitoring capabilities, and detailed reporting dashboards. Users benefit from its file integrity monitoring and endpoint detection and response (EDR) capabilities, which streamline compliance and vulnerability assessments. While appreciated for its customization and easy deployment, room for improvement exists in scalability, particularly in the free version, and in areas such as threat intelligence integration, cloud integration, and container security. The platform is acknowledged for its strong documentation and technical support.
What are the key features of Wazuh?In industries like finance, healthcare, and technology, Wazuh is utilized for its capabilities in log aggregation, threat detection, and vulnerability management. Companies often implement its features to ensure compliance with stringent regulations and to enhance security practices across cloud environments. By leveraging its integration capabilities, organizations can achieve unified security management, ensuring comprehensive protection of their digital assets.
WithSecure (formerly F-Secure) Elements Endpoint Detection and Response gives you instant visibility into your IT environment and security status from a single pane of glass. It keeps your business and data safe by detecting attacks fast and responding with expert guidance. And you can elevate the hardest cases to our elite cyber security specialists, so we always have your back.
WithSecure Elements Endpoint Detection and Response is a module of the Elements cyber security platform. The cloud-based platform provides effective protection against ransomware and advanced attacks. Elements brings together vulnerability management, automated patch management, dynamic threat intelligence and continuous behavioral analytics. Use individual solutions for specific needs or combine them all seamlessly for maximum defense.
We monitor all Extended Detection and Response (XDR) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.