What is our primary use case?
I use Wazuh as an open-source solution for SIEM and file integrity monitoring. I have conducted a few POCs in the bank sectors, as well as demos specifically regarding SIEM.
In Pakistan, we have a state bank that controls the regularities. The banking sector wants to save money and is only interested in compliance. Our company helps them with this. Wazuh is used for file integrity monitoring on Unix, Linux, and Windows systems.
Wazuh is available on the cloud, however, it depends on the customer. I work with the financial sector, which does not want its data to be on a public or private cloud.
What is most valuable?
I find the PCI DSS feature the most valuable, along with the feature that monitors the compliance of Windows and the CIS benchmarks on other devices like Unix or Linux systems.
There are three other features I find valuable. First, Wazuh helped me harden the appliances. Second, Wazuh gives me the opportunity to check the hardness through the CIS benchmarks and the other controls, such as Windows auditing policies. On the other hand, I have found it to be more useful for the PCI DSS compliance as it gives a very clear view regarding the benchmark of the PCI DSS. Last, Wazuh is most famous for the SIEM. The solution gives integrity monitoring for the specific file and updates on the real-time monitoring if the hashes change.
What needs improvement?
Wazuh has a drawback with regard to Unix systems. The solution does not allow us to do real-time monitoring for Unix systems. If usage increases, it would be a heavy fall on the other SIEM solutions or event monitoring solutions.
We found a workaround by reducing the frequency, so it would give us some sort of real-time monitoring.
For how long have I used the solution?
I have been using Wazuh for four months.
What do I think about the stability of the solution?
Wazuh is stable, however, at the start, I did face many difficulties managing the solution. We have a private lab in our office and the server is turned down each day. At the start of the next day, I would face an issue with our Elasticsearch not completely being loaded and the Kibana not loaded.
What do I think about the scalability of the solution?
The solution is quite scalable.
How was the initial setup?
The initial setup of Wazuh is straightforward. I was able to implement this by following the documentation. I downloaded the CentOS OS appliance, which takes a few minutes, and then another ten to twenty minutes to upload and give it the IP address and network. It takes only one integrator like me to deploy everything.
What about the implementation team?
Implementation of Wazuh depends on the organization, specifically, if the organization is on Azure Active Directory, or if it's just a normal Active Directory.
When I implement the solution, I will never go on the agent-based implementation, I will do centralized implementation which is provided by Wazuh. Using the create agent part, I have a power shell script for Windows or a different script for either Linux or Unix.
I give the script to the administrator and request them to push it directly on the systems, so within a few seconds I can see on the Wazuh dashboards that the agents are active. This allows me to manage them through centralized groups. It would not be recommended to push every script and change every file on the final device.
What's my experience with pricing, setup cost, and licensing?
Wazuh is open-source, therefore it is free. You can purchase support for $1,000 a year.
What other advice do I have?
My advice to someone considering Wazuh would depend on if they are using the open-source solution or not. If they are using open-source, I recommend that they purchase the support from Wazuh. Be prepared to be patient and wait for the services to be completely up. Once it is up, you are free to use it.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Customer but also integrator