Pathick Kerketta - PeerSpot reviewer
Manager (Information Security) at Girnarsoft Private Limited
Real User
Top 5
A free and open source security platform with a valuable inventory feature
Pros and Cons
  • "I like the features we use, including malware detection, inventory, detection of hidden processes, and activity logs. Inventory is probably the most important feature. It tells us when processes and packages were installed and what they are, which is helpful."
  • "Integration with Vyara could be better."

What is our primary use case?

We use Wazuh for inventory, logging activity, malware detection, and detecting hidden processes running on the server. 

What is most valuable?

I like the features we use, including malware detection, inventory, detection of hidden processes, and activity logs. Inventory is probably the most important feature. It tells us when processes and packages were installed and what they are, which is helpful.

What needs improvement?

Integration with Vyara could be better.

For how long have I used the solution?

I have been using Wazuh for about three months.

Buyer's Guide
Wazuh
April 2024
Learn what your peers think about Wazuh. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
769,630 professionals have used our research since 2012.

What do I think about the stability of the solution?

Wazuh is a stable solution. We have not faced any issues yet.

How was the initial setup?

The initial setup is straightforward, but we faced some challenges integrating it with Vyara. 

On a scale from one to ten, I would give the initial setup a nine.

What's my experience with pricing, setup cost, and licensing?

Wazuh is free and open source.

What other advice do I have?

On a scale from one to ten, I would give Wazuh an eight.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Security Analyst at a tech services company with 501-1,000 employees
Real User
Top 20
Has efficient integration features, but they could provide enhanced customization capabilities
Pros and Cons
  • "One of the most beneficial features of Wazuh, particularly in the context of security needs, is the machine learning data handling capability."
  • "They could include flexibility and customization capabilities by modifying for customers based on partner agreements."

What is our primary use case?

We use Wazuh to deliver security features in a venture capital company project focused on building a mobile application.

What needs improvement?

They could include flexibility and customization capabilities by modifying for customers based on partner agreements. They could enhance governance-related tools for audit reports.

We conducted a cost-benefit evaluation and compared Wazuh with Sentinel and FortiCM. The decision to choose Wazuh was influenced by its compatibility with other systems and the strong open-source community.

In comparison, Microsoft has a huge community, but it needs to be easy to use. Additionally, FortiCM needs better community support.

For how long have I used the solution?

We are the latest version of Wazuh.

What do I think about the stability of the solution?

We have not encountered any performance issues for the application up until now. I rate the stability an eight out of ten.

What do I think about the scalability of the solution?

The product is easily scalable. We have around 20 executives using it daily. Our work on the use cases is still in progress.

How are customer service and support?

We contact a third-party supplier for technical support. They provide seamless services and resolve issues by the next day most of the time.

Which solution did I use previously and why did I switch?

I was a part of a service team using Splunk. I have experience working with Symantec Endpoint.

How was the initial setup?

I rate the initial setup process a seven out of ten.

What about the implementation team?

The implementation of Wazuh is done through a local third-party supplier, but the management and overall engagement with the company are handled in-house. The third-party supplier provides hardware provision, field engineers, and devices, with the day-to-day management and operations handled remotely.

There were some slight problems related to the images being used. However, these issues were attributed to infrastructure considerations rather than specific to Wazuh. Once the correct image was selected, the installation process for the first server during the proof of concept, which involved comparing Sentinel and other solutions, was completed relatively quickly—approximately one day.

It might require a team for regular patch management and vulnerability scanning. We have yet to start with the maintenance.

What's my experience with pricing, setup cost, and licensing?

For both personal and service use, the perceived cost is relatively low. They have a good pricing strategy for market expansion.

I rate the product's pricing a three out of ten.

Which other solutions did I evaluate?

We evaluated Sentinel.

What other advice do I have?

We are currently running a proof of concept and simulating usage with a select group of users as required by local bank licensing. It is utilized for vulnerability management. Up to this point, there have been minor incidents with no risks higher than moderate. Despite not needing immediate reaction, we have automation in place within your SOC and development team to respond in case of any recognized incidents.

One of the most beneficial features of Wazuh, particularly in the context of security needs, is the machine learning data handling capability. Although it has yet to be fully implemented into production and is currently in a test environment, the decision to choose Wazuh was influenced significantly by this feature. It helps us streamline and automate the assessment of security incidents. We can organize response plans proactively, even before certain incidents occur. It is the most critical aspect for us.

There were initial challenges with the real-time alerting team due to the many systems-generated alerts. It took about three months to fine-tune the system configuration, focusing on capturing only the alarms relevant from a security perspective. Despite the initial difficulties, Wazuh worked seamlessly, and there were no notable issues with configurations, handling, or investigations. The challenges primarily occurred from system-related aspects rather than issues with Wazuh.

I do not have direct experience with scalability requirements, but the implementation has been seamless. No challenges are scaling up, especially regarding adding more machines to handle the same load. The challenge is delivering logs so that Wazuh can collect, read, and analyze them effectively. We were able to overcome major issues without the need for extensive support.

Wazuh has been integrated with an intrusion prevention system (IPS) solution, Suricata, also an open-source tool. This integration adds a layer for security monitoring. The integration process is quite straightforward, especially due to the community's availability of shared use cases.

I rate the product a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Buyer's Guide
Wazuh
April 2024
Learn what your peers think about Wazuh. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
769,630 professionals have used our research since 2012.
Tech Lead Security at a comms service provider with 51-200 employees
Real User
Poor detection, lacking features, but simple installation
Pros and Cons
  • "The most valuable feature of Wazuh is the ELK for doing an investigation."
  • "Wazuh could improve the detection, it is not detecting all of the attacks. Additionally, it is lacking features compared to other solutions."

What is our primary use case?

We are using Wazuh for our SOC environment. We are managing and monitoring our infrastructure using the Wazuh SIEM

What is most valuable?

The most valuable feature of Wazuh is the ELK for doing an investigation.  

What needs improvement?

Wazuh could improve the detection, it is not detecting all of the attacks. Additionally, it is lacking features compared to other solutions.

For how long have I used the solution?

I have been using Wazuh for approximately six months.

What do I think about the stability of the solution?

Wazuh is a stable solution.

What do I think about the scalability of the solution?

I have found Wazuh to be scalable.

We have approximately six people using the solution. We plan to increase the usage of the solution.

How are customer service and support?

I have not used the support from Wazuh.

Which solution did I use previously and why did I switch?

I have used Splunk previously.

How was the initial setup?

The installation of Wazuh is simple.

What about the implementation team?

We did the implementation of the solution ourselves.

We have six technicians supporting the solution.

What's my experience with pricing, setup cost, and licensing?

There is not a license required for Wazuh.

What other advice do I have?

My advice to others is Wazuh is a good starter solution but there are other more advanced solutions on the market, such as Splunk which is an industry-level solution.

I rate Wazuh a five out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Chief Information Security Officer at a financial services firm with 501-1,000 employees
Real User
Stable with good MITRE ATT&CK correlation, but needs a better user interface
Pros and Cons
  • "The MITRE ATT&CK correlation is most valuable."
  • "Its user interface for sure can be improved. It is not so comfortable to use if you're looking for specific logs."

What is our primary use case?

We collect logs in it, and then we correlate logs against the MITRE ATT&CK framework. We have configured some notifications.

What is most valuable?

The MITRE ATT&CK correlation is most valuable.

What needs improvement?

Its user interface for sure can be improved. It is not so comfortable to use if you're looking for specific logs.

For how long have I used the solution?

I have been using this solution for the last two years.

What do I think about the stability of the solution?

It is stable.

What do I think about the scalability of the solution?

I am not sure about scalability. We have a total of seven users. Our department has two people, and there are five people from the IT department. We don't have any plans to increase its usage at this time.

How are customer service and technical support?

I didn't use their technical support.

How was the initial setup?

I was not involved in its installation. I am just using it.

What about the implementation team?

Other colleagues from the IT department handle its installation. 

What other advice do I have?

For our usage, I would rate Wazuh a six out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Security engineer at a tech services company with 51-200 employees
Real User
Top 5
A flexible solution that can be used for instant response, security operations, and compliance
Pros and Cons
  • "Wazuh's most beneficial features for our security needs are flexibility, built-in rules, integration capabilities, and documentation."
  • "Wazuh should come up with more in-built rules and integrations for the cloud."

What is our primary use case?

We use Wazuh for internal testing, instant response, security operations, and compliance.

What is most valuable?

Wazuh's most beneficial features for our security needs are flexibility, built-in rules, integration capabilities, and documentation.

What needs improvement?

At the moment, we haven't tried the cloud version yet. My customers are mostly into the cloud. Wazuh should come up with more in-built rules and integrations for the cloud.

For how long have I used the solution?

I have been using Wazuh for one year.

What do I think about the stability of the solution?

I rate Wazuh seven and a half out of ten for stability.

What do I think about the scalability of the solution?

Around 10 users are using the solution in our organization.

How was the initial setup?

For a technical and experienced person, the solution's initial setup is easy. The setup would be a little hard for a non-technical person with less experience.

What about the implementation team?

The initial implementation and configuration may take a maximum of one week.

What's my experience with pricing, setup cost, and licensing?

Wazuh is not an expensive solution.

What other advice do I have?

If correctly configured, Wazuh can support threat detection and response for SMBs. Wazuh is a good solution if you can implement, integrate, and fine-tune it in the right way.

Overall, I rate Wazuh an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
CBO at a security firm with 11-50 employees
Reseller
Top 5
Offers good log monitoring and analysis tools
Pros and Cons
  • "The log monitoring and analysis tools are great in addition to SIEM file activity monitoring."
  • "I think that the next release should be more suitable for large enterprises, because currently they are not because large companies do not rely on open source solutions."

What is most valuable?

The log monitoring and analysis tools are great in addition to SIEM file activity monitoring.

What needs improvement?

I think that the next release should be more suitable for large enterprises, because currently they are not because large companies do not rely on open source solutions.

For how long have I used the solution?

I have been working with this solution for about four months.

What do I think about the stability of the solution?

For mid-level customer, stability is okay.

What do I think about the scalability of the solution?

This is a scalable solution.

How are customer service and support?

Support needs to be purchased on an annual basis but the support required is excellent.

How was the initial setup?

The initial setup is rather complex and takes a few days to perform. 

What's my experience with pricing, setup cost, and licensing?

This is a very price sensitive product.

What other advice do I have?

No hardware is required for this solution but be prepared to purchase implementation support. I would rate this solution a six or seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
PeerSpot user
Buyer's Guide
Download our free Wazuh Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2024
Buyer's Guide
Download our free Wazuh Report and get advice and tips from experienced pros sharing their opinions.