No more typing reviews! Try our Samantha, our new voice AI agent.
Vice President Information Technology and Security at a comms service provider with 201-500 employees
Real User
Apr 20, 2022
It's open source and useful for compliance, but it isn't user friendly and lacks out-of-the-box functionality
Pros and Cons
  • "My company implemented Wazuh because it was relatively inexpensive. They could quickly get their hands on it to check a box for some audit and compliance."
  • "My company implemented Wazuh because it was relatively inexpensive."
  • "There's not much I like about Wazuh. Other products I've used were a lot more functional and user friendly. They came with reports and use cases out of the box. We need to configure Wazuh's alerts and monitoring capabilities manually. It'd be nice if we could select from templates and presets for use cases already built and coded."
  • "There's not much I like about Wazuh. Other products I've used were a lot more functional and user friendly."

What is our primary use case?

Wazuh is used for event information and management. We have several events that are of interest, and Wazuh lets our folks know if any of them trigger.

How has it helped my organization?

My company implemented Wazuh because it was relatively inexpensive. They could quickly get their hands on it to check a box for some audit and compliance.

What needs improvement?

There's not much I like about Wazuh. Other products I've used were a lot more functional and user friendly. They came with reports and use cases out of the box. We need to configure Wazuh's alerts and monitoring capabilities manually. It'd be nice if we could select from templates and presets for use cases already built and coded. 

For how long have I used the solution?

I've only been with the company since November, but I believe they've been using Wazuh for maybe five years.

Buyer's Guide
Wazuh
March 2026
Learn what your peers think about Wazuh. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,444 professionals have used our research since 2012.

What do I think about the stability of the solution?

I haven't had issues with stability.

What do I think about the scalability of the solution?

Wazuh can scale up, but it doesn't scale easily. It's extensively used. We have about 30 people in our company using it. 

How are customer service and support?

Wazuh is an open-source solution, so there isn't any support. We look for answers in the knowledge base and on user forums.  

How was the initial setup?

I wasn't with the company during the initial installation, but Wazuh does require some maintenance. We don't have the resources to take care of it, so it tends to get out of date and require updates. We have an administrator, but maintaining Wazuh is only one of his responsibilities. 

What's my experience with pricing, setup cost, and licensing?

Wazuh is open-source, but you must consider the total cost of ownership. It may be free to acquire, but you spend a lot of time and effort supporting the product and getting it to a point where it's useful. 

Which other solutions did I evaluate?

There are more advanced and robust offerings out there like QRadar that we should try instead of upgrading to a new version of Wazuh.

What other advice do I have?

I rate Wazuh four out of 10. It can do the job, but you need to invest a lot of time configuring it for your use case.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Haad Fida - PeerSpot reviewer
Software Engineer at 7Vals
Real User
Oct 6, 2023
An affordable and stable solution that can be used for event monitoring
Pros and Cons
  • "The tool is stable."
  • "The tool doesn't detect anomalies or new environments."

What is our primary use case?

We use the solution for event monitoring.

What is most valuable?

The tool is stable.

What needs improvement?

The rules are hard coded. The tool doesn't detect anomalies or new environments. The product lacks AI features. We have to do a lot of manual searching.

For how long have I used the solution?

I have been using the solution for about eight months.

What do I think about the scalability of the solution?

The tool is scalable for our use cases. Five to ten people use the solution in our organization. We need one administrator to monitor and improve our solution.

How are customer service and support?

We did not contact support. Our company’s security personnel set everything and documented it.

Which solution did I use previously and why did I switch?

We use Elastic Stack for logs.

How was the initial setup?

The deployment was straightforward. It took two to three months. We needed two people for deployment.

What about the implementation team?

We did the deployment in-house with the help of our security personnel and someone from the DevOps team.

What's my experience with pricing, setup cost, and licensing?

The product is cheaper compared to other tools. Depending on the logs, the product costs $200 to $400. We currently have five servers.

Which other solutions did I evaluate?

We evaluated Google Cloud.

What other advice do I have?

When Google contacted us, we were looking into an AI solution. Our implementation is rather basic. Overall, I rate the solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Wazuh
March 2026
Learn what your peers think about Wazuh. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,444 professionals have used our research since 2012.
Usman Arif - PeerSpot reviewer
Cyber Security Engineer at Ebryx (Pvt.) Ltd
Real User
Sep 22, 2023
Transforming security features with notable vulnerability reduction and comprehensive compliance
Pros and Cons
  • "It offers built-in modules for file integrity and vulnerability management."
  • "A more structured approach, perhaps with modular UI components, to facilitate easier integration and navigation within the Wazuh platform for custom integrations would be beneficial."

What is our primary use case?

It is used primarily for event management in our organization, which falls into the category of an edge Intrusion Detection System (IDS) or host Internet protection system. Our company is not very large, with around twenty to thirty servers and approximately one hundred fifty to two hundred endpoints. Wazuh serves as a centralized platform for collecting security events and managing vulnerabilities across your systems. Its main purpose is to analyze and improve the overall security posture of our organization.

How has it helped my organization?

Before the deployment of Wazuh, we faced challenges related to vulnerability management and version change history. Vulnerabilities often went unreported, and there was no organized system for managing vulnerabilities. Since we implemented it, there has been a notable improvement. Vulnerabilities have significantly decreased, with nearly fifty percent of servers now reporting zero vulnerabilities. This positive change is attributed to regular reporting, remediation efforts, and frequent system updates.

What is most valuable?

It offers built-in modules for file integrity and vulnerability management. This provides the convenience of having these features integrated into one platform rather than using separate dedicated tools. Wazuh's comprehensive compliance with various modules aligns well with our organization's needs, making it a highly suitable and efficient solution.

What needs improvement?

It is an open-source tool with a strong community. We had positive experiences with community support, having received solutions for most of your inquiries in the past. However, it would be beneficial if Wazuh could provide clearer guidance or tutorials on how to add components to the user interface (UI), especially when integrating tools that aren't inherently supported by Wazuh. A more structured approach, perhaps with modular UI components, to facilitate easier integration and navigation within the Wazuh platform for such custom integrations would be beneficial.

For how long have I used the solution?

I have been working with it for the last three years.

What do I think about the stability of the solution?

The stability capabilities are almost perfect. I would rate it nine out of ten.

What do I think about the scalability of the solution?

It offers excellent scalability features. I would rate it nine out of ten.

How are customer service and support?

Their customer support services are excellent. I would rate it nine out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We use other tools like SpamTitan and Fortis for specific purposes. SpamTitan is employed for email spam filtering and Fortis for client-related tasks. These tools complement our overall cybersecurity and client management efforts.

How was the initial setup?

While generally straightforward, there were some challenges during the initial setup process, particularly when dealing with certificate-related issues. I would rate it seven out of ten.

What about the implementation team?

The deployment took a total of five days, involving three individuals. Once deployed, the solution is efficiently maintained by just one person.

What's my experience with pricing, setup cost, and licensing?

Wazuh is an open-source tool, which means it is freely available for use.

What other advice do I have?

I recommend it for its flexibility and adaptability to specific organizational needs. I would rate it eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Chetan_Sharma - PeerSpot reviewer
Linux System Administrator at Amity Software Systems Limited
Reseller
Jul 6, 2023
Has good scalability but requires an efficient hardware monitoring tool
Pros and Cons
  • "It has efficient SCA capabilities."
  • "There could be a hardware monitoring tool for the solution."

What is our primary use case?

We use the solution for vulnerability metrics, auditing, and detecting SQL injection attacks.

What is most valuable?

The solution's most valuable feature is its SCA capabilities.

What needs improvement?

There could be a hardware monitoring tool for the solution. It helps reduce the cost of utilizing external resources for the same.

For how long have I used the solution?

We have been using the solution for five to six months.

What do I think about the scalability of the solution?

I rate the solution's scalability a ten out of ten. We have enterprise business clients.

How are customer service and support?

We are currently evaluating the cost of the solution's support services.

How was the initial setup?

We have multiple teams using the solution in the virtual environment. It was easy to deploy for a few teams while challenging for others.

What's my experience with pricing, setup cost, and licensing?

I rate the solution's pricing a seven out of ten.

What other advice do I have?

I rate the solution a seven out of ten. There needs to be monitoring for the hardware similar to Zabbix and Nagios solutions.

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
Youssef EL AZZOUZI - PeerSpot reviewer
Intern Master in Cybersecurity and Cybercrime at Université Abdelmalek Essaâdi
Real User
Leaderboard
May 10, 2023
Provides a range of features, but its configuration process needs to be faster
Pros and Cons
  • "It is a stable solution."
  • "Its configuration process is time-consuming."

What is our primary use case?

We use the solution for endpoint detection and response. It helps us detect malicious files.

What is most valuable?

The solution is easy to integrate with other SOC tools. Also, it has a lot of capabilities like active response, cloud security, etc.

What needs improvement?

The solution's configuration could be faster.

For how long have I used the solution?

We have been using the solution for two months.

What do I think about the stability of the solution?

The solution is easy to install. However, it takes a long time to configure.

What do I think about the scalability of the solution?

It is a stable solution.

What's my experience with pricing, setup cost, and licensing?

It is an open-source solution.

What other advice do I have?

I recommend the solution to others and rate it a seven. It has many features and integrates with other substitutes like QRadar, Hive, etc.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Pathick Kerketta - PeerSpot reviewer
Manager (Information Security) at Girnarsoft Private Limited
Real User
Apr 10, 2023
A free and open source security platform with a valuable inventory feature
Pros and Cons
  • "I like the features we use, including malware detection, inventory, detection of hidden processes, and activity logs. Inventory is probably the most important feature. It tells us when processes and packages were installed and what they are, which is helpful."
  • "Integration with Vyara could be better."

What is our primary use case?

We use Wazuh for inventory, logging activity, malware detection, and detecting hidden processes running on the server. 

What is most valuable?

I like the features we use, including malware detection, inventory, detection of hidden processes, and activity logs. Inventory is probably the most important feature. It tells us when processes and packages were installed and what they are, which is helpful.

What needs improvement?

Integration with Vyara could be better.

For how long have I used the solution?

I have been using Wazuh for about three months.

What do I think about the stability of the solution?

Wazuh is a stable solution. We have not faced any issues yet.

How was the initial setup?

The initial setup is straightforward, but we faced some challenges integrating it with Vyara. 

On a scale from one to ten, I would give the initial setup a nine.

What's my experience with pricing, setup cost, and licensing?

Wazuh is free and open source.

What other advice do I have?

On a scale from one to ten, I would give Wazuh an eight.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Maikel Richard Villar Rodriguez - PeerSpot reviewer
Cybersecurity supervisior at Optical Network
Real User
Sep 17, 2022
Open-source solution that immediately resolves vulnerabilities
Pros and Cons
  • "Wazuh's best features are syscheck, its ability to immediately resolve vulnerabilities, and that it's open source."
  • "Wazuh's best features are syscheck, its ability to immediately resolve vulnerabilities, and that it's open source."
  • "Wazuh needs more security and features, particularly visualization features and a health monitor."
  • "Wazuh needs more security features, particularly visualization features and a health monitor."

What is our primary use case?

My main use case for Wazuh is checking security events.

What is most valuable?

Wazuh's best features are syscheck, its ability to immediately resolve vulnerabilities, and that it's open source.

What needs improvement?

Wazuh needs more security features, particularly visualization features and a health monitor. In the next release, it should be easier to see the origin of events when connected to a firewall or switch. I would also like more integration with XDR and cloud-based formats like the GCO log testing system or Huawei.

For how long have I used the solution?

I've just started using Wazuh.

What do I think about the stability of the solution?

Wazuh is stable.

What do I think about the scalability of the solution?

I believe Wazuh is scalable.

Which solution did I use previously and why did I switch?

I previously used Splunk and changed to Wazuh because of its lower cost.

How was the initial setup?

The initial setup is easy.

What other advice do I have?

Wazuh is a good solution if you want to visualize your environment. I would rate Wazuh eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Robert Cheruiyot - PeerSpot reviewer
IT Security Consultant at Microlan Kenya Limited
Real User
Nov 4, 2021
Good integration with other platforms but not easily scalable and lacks threat intelligence
Pros and Cons
  • "It's very easy to integrate Wazuh with other environments, cloud applications, and on-prem applications. So, the advantage is that it's easy to implement and integrate with other solutions."
  • "It's very easy to integrate Wazuh with other environments, cloud applications, and on-prem applications."
  • "Wazuh doesn't cover sources of events as well as Splunk. You can integrate Splunk with many sources of events, but it's a painful process to take care of some sources of events with Wazuh."
  • "Wazuh is not easily scalable. You have to consider the sources of events and maybe the amount of traffic."

What is most valuable?

It's very easy to integrate Wazuh with other environments, cloud applications, and on-prem applications. So, the advantage is that it's easy to implement and integrate with other solutions.

What needs improvement?

Wazuh doesn't cover sources of events as well as Splunk. You can integrate Splunk with many sources of events, but it's a painful process to take care of some sources of events with Wazuh. It's hard to really go into what Wazuh should add. If we call for Wazuh to improve one thing, then many things have to be improved. So if Wazuh's primary purpose is to cover the logs, then we can't really keep asking them to cover endpoints as well. And Wazuh doesn't have threat intelligence, to my knowledge. It can integrate with other sources of threat intel, but I haven't seen a native threat intel platform. Many people subscribe to Splunk for this platform. You can integrate threat intelligence from other solutions, but I haven't seen this feature in Wazuh.

For how long have I used the solution?

I only started working with Wazuh recently. 

What do I think about the stability of the solution?

It seems like they're constantly updating Wazuh, and it causes some instability. So you get a lot of updates after a short while, and there are so many things that Wazuh is trying to implement. When I see these rapid changes, it means the Wazuh team is trying to implement some of the things that are not yet implemented. So when you implement new features, you only have to understand that it's not covering many sources of events. That's where I would say stability becomes an issue.

What do I think about the scalability of the solution?

Wazuh is not easily scalable. You have to consider the sources of events and maybe the amount of traffic. I think it's still a solution that's not easily adaptable to a massive amount of information.

How are customer service and support?

Our current clients are happy with Wazuh support. One client upgraded from the basic open-source package to a support subscription, so I haven't heard any complaints from that person since.

How was the initial setup?

Wazuh is a straightforward platform to set it up in a new environment. I wouldn't say it's complex. Another platform I used had a lot of licenses that were a pain to implement. Of course, after I implemented these licenses, it was very nice to work with. But Wazuh and Splunk are effortless to deploy.

What's my experience with pricing, setup cost, and licensing?

Wazuh is open-source, so I think it's an option for a small organization that cannot go for enterprise-grade solutions like Splunk.

What other advice do I have?

I would rate Wazuh a six out of 10. It's hard to compare Wazuh to commercial solutions like Splunk. It's fairer to evaluate the open-source tools together. So if I were to rate Wazuh alongside other open-source platforms, I would say it's the best in that category. 

If customers are considering Wazuh, they should think about what kind of coverage they want. If they're focusing on the logs and threat monitoring, maybe Wazuh is okay by itself, but it's not something that provides traffic monitoring. Still, you can root out threats on your network using the logs. It's valuable information. So if you are looking to cover that scope, that's well and good. And if you're not familiar with this product, it's essential to have support. You can buy a subscription for support. So you need to know that Wazuh only covers logs and you need to consider if it suits your needs in terms of scalability. If you are comfortable with these few things, then Wazuh is okay. The solution is good. And if you need something for endpoint protection, Opex is another open-source tool used to monitor the endpoints for anything suspicious

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Wazuh Report and get advice and tips from experienced pros sharing their opinions.
Updated: March 2026
Buyer's Guide
Download our free Wazuh Report and get advice and tips from experienced pros sharing their opinions.