No more typing reviews! Try our Samantha, our new voice AI agent.
IT Infrastructure at 4 Seniors Brasil
Real User
Top 5
Aug 12, 2024
Aggregates all your logs in one place and provides a unified view to monitor
Pros and Cons
  • "It allows you to aggregate all your logs in one place and provides a unified view to monitor your security environment."
  • "Wazuh doesn't have native support for some enterprise solutions."

What is our primary use case?

My company specializes in providing SIEM as a service. We leverage Wazoo for that. Since Wazoo is open-source, I hosted it on Azure.

We provide Wazuh as a service to our customers. Currently, we have three clients whose environments are integrated with our Wazuh server on our CRM system. We handle the typical CRM use cases, including security alerts and advisories, and monitor their environments through our Wazuh server.

How has it helped my organization?

It allows you to aggregate all your logs in one place and provides a unified view to monitor your security environment. Unlike other solutions, Wazuh is open-source, so you don't need to invest in significant capital expenses. You can easily set up a server on Azure or your infrastructure. While you will need specialized personnel to operate it, this is true for any SIEM solution.

What is most valuable?

One of Wazuh's most significant advantages, aside from being open source, is its flexible dashboards. Integrated with Elasticsearch, Wazuh allows you to create customized dashboards if you have an in-house developer. This level of customization isn’t available with Fortinet, which offers only pre-made dashboards. Wazuh lets you design any dashboard you need.

What needs improvement?

Wazuh doesn't have native support for some enterprise solutions. It requires an agent installed on the server, whether Windows Server or Linux, to collect logs. While you can gather information via SNMP or Splunk logs, this isn't natively supported. Some decoders are available, but they are community-built rather than officially supported. It relies on its community to create these decoders as an open-source platform, so they may not be fully integrated.

Buyer's Guide
Wazuh
March 2026
Learn what your peers think about Wazuh. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,444 professionals have used our research since 2012.

What do I think about the stability of the solution?

It's pretty stable. If it's not properly implemented, you don't have stability problems if you follow the documentation and do it as detailed documentation.

What do I think about the scalability of the solution?

Wazuh is highly scalable. You can install it on-premises, in Azure, or using Docker. The architecture allows you to separate the dashboard, index, and node servers.

How are customer service and support?

Wazuh offers technical support, but you need to pay for it. If you are using the open-source solution, you'll need to rely on the extensive documentation and the community itself.

How was the initial setup?

The initial setup is complicated. You need a specialist in the technology to make good use of it. You can do it on-premises. You can do it on Azure. You can do it on the hybrid cloud as a docker. So it's very flexible.

We use Azure, which we currently use as a single server. We will migrate it to our partner using Azure.

It takes two months to deploy completely.

What was our ROI?

You save on licensing, and you need to invest in people.

What other advice do I have?

When Wazuh is properly implemented, it runs smoothly without causing many problems. However, if it's not set up correctly, you might encounter issues that require weekly maintenance. These can include database and disk issues because, as a VM solution, Wazuh collects a large amount of logging data. Proper implementation prevents these problems, but they can arise if you're unsure how to do it.

Overall, I rate the solution an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Md Salim Hossain Hossain - PeerSpot reviewer
Cyber Digital Transformation Engineer at OneWorldInfoTech
Real User
Mar 21, 2024
An open-source platform to integrate various products
Pros and Cons
  • "Integrates with various open-source and paid products, allowing for flexibility in customization based on use cases."
  • "Alerts should be specific rather than repeatedly triggered by integrating multiple factors. This issue needs improvement to create a more efficient alert system."

What is our primary use case?

We use Wazuh for the onboarding of both Windows and Linux machines, as well as for firewall and SIM configuration. The IP address is automatically blocked if a server has multiple wrong passwords.

How has it helped my organization?


What is most valuable?

Wazuh can integrate with various open-source and paid products, allowing for flexibility in customization based on use cases. Wazuh supports multiple use cases, allowing for in-depth customization. Additionally, Wazuh incorporates detection mechanisms such as tracing, shared internal suites, and leveraging third-party feeds. Machine learning mechanisms are also built to enhance detection capabilities, helping identify suspicious or anomalous behavior. It is open-source nature, which allows for widespread adoption and community support. The growing community contributes to its continued development and improvement.

What needs improvement?

I have built some rules that produce duplicate alerts two or three times. Therefore, these rules should be consolidated. Alerts should be specific rather than repeatedly triggered by integrating multiple factors. This issue needs improvement to create a more efficient alert system.

For how long have I used the solution?

I have been using Wazuh as an end user since 2023.

What do I think about the stability of the solution?

The product is stable.

What do I think about the scalability of the solution?

The solution is scalable. In the Bangladesh market, several banks are now actively considering Wazuh. They become fully compliant with compliance issues. Earlier, they were struggling to obtain approval and maintain compliance standards.

Which solution did I use previously and why did I switch?

I have used Elastic Security. There are some customization needs in Wazuh. We cannot customize it.

How was the initial setup?

The initial setup is easy. Log management plays a crucial role in using Wazuh to its full potential. Assessing the volume and nature of the data is essential to determine EPS. This calculation is pivotal, as it dictates resource allocation, such as access, RAM, and storage specifications.

What's my experience with pricing, setup cost, and licensing?

The product is an open-source platform.

What other advice do I have?

Wazuh can onboard multiple customers onto a single deployment through its multi-tenancy feature. Each customer can have their own interface with the same deployment location.

The solution’s maintenance is easy.

Overall, I rate the solution an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Wazuh
March 2026
Learn what your peers think about Wazuh. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,444 professionals have used our research since 2012.
reviewer2263155 - PeerSpot reviewer
Lead Security Engineer at a tech services company with 201-500 employees
Real User
Sep 11, 2023
Requires extensive configuration to suit your needs, though I appreciate its open-source aspect
Pros and Cons
  • "I like Wazuh because it is a lot like ELK, which I was already comfortable with, so I didn't have to learn from scratch."
  • "Wazuh is missing many things that a typical SIEM should have."

What is our primary use case?

We use Wazuh as a SIEM instead of Logstash, so it's like a managed version of ELK. We customized queries and search detection according to that. The good thing is that it also provides a module called Monitor, and using that, we set up alerts to Slack or email. Then, based on Slack, we implemented an automation to prevent things as per our demands.

What is most valuable?

I like Wazuh because it is a lot like ELK, which I was already comfortable with, so I didn't have to learn from scratch. Another good thing about Wazuh is that it's open-source.

What needs improvement?

A lot of things could be improved with Wazuh. A company I worked with used this product with their customizations since Wazuh is missing many things that a typical SIEM should have. One thing that was missing was log source management. We didn't have any modules for that. Wazuh's parsing is very complex. You must write decoders to make it as easy as in other SIEMs, like in QRadar.

The stability and scalability could be improved.

For how long have I used the solution?

I've been working on Wazuh for about eight months.

What do I think about the stability of the solution?

I am 60% confident in Wazuh's stability. I have one client, and I have been facing stability issues. I have to troubleshoot the solution every second or third month.

What do I think about the scalability of the solution?

I am 60% confident in Wazuh's scalability.

How was the initial setup?

The initial setup is very easy. It is exactly like ELK. You deploy Elasticsearch, Wazuh, and Kibana. It took one day to deploy the solution.

For deployment, you need to plan how many resources you need. For example, if it's a Linux machine, you just download the required binaries from their site. After that, unzip the folder downloaded from their site, and then you just want a couple of scripts, and it will install Elasticsearch. You would do the same for Logstash, Wazuh, or Kibana. You must configure the solution a little to ensure that Logstash or Elasticsearch recognizes Kibana, so you have to provide the IPs and all that. Then, the solution is all set up.

What's my experience with pricing, setup cost, and licensing?

My client uses the open-source version of Wazuh.

What other advice do I have?

Wazuh is a cloud-based SIEM solution that can be deployed on-prem. Wazuh has the same capabilities as ELK: Elastic, Logstash, and Kibana. You can integrate devices with Wazuh and deploy use cases according to your demands. For example, in the financial sector, you will have your detections according to finance. In the education sector, you will have different use cases. It all depends on the client.

The solution is open-source, and I can't access technical support. I have been searching for someone to assist me, but my team and I have always been figuring out how to work with the solution.

I rate Wazuh a five-point five out of ten.

I wouldn't tell anyone not to use Wazuh. They can still choose if it fits in their budget, but I would ask them to plan first. And instead of going all in one, I recommend they use separate instances for separate modules to ensure the solution is scalable and stable. They should not use one instance for all of their modules. When their log or your business size grows, they will have more logs and then have to deal with stability issues.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Senior consultant at a tech services company with 51-200 employees
Consultant
Top 10
Jan 13, 2023
Great modules and metrics, good for small budgets, with excellent integration
Pros and Cons
  • "The most valuable features are the modules and metrics."
  • "It would be great if there could be customization for the decoder portion."

What is our primary use case?

Our primary use case is for monitoring the cloud as well as infrastructure.

What is most valuable?

The most valuable features are the modules and metrics. The asset inventory and everything from the agent and the capabilities to integrate the Windows Defender directly into the SIEM solution.

What needs improvement?

When the agents are not upgraded in comparison to the server they start behaving unknowingly. Some modules will be working, some modules will not be working. It would be great if there could be customization for the decoder portion.

For how long have I used the solution?

I have been using Wazuh for the past year and a half.

What do I think about the stability of the solution?

The stability is excellent and I would rate it a ten out of ten.

What do I think about the scalability of the solution?

the scalability is high and I would rate it an eight on a scale of one to ten.

How was the initial setup?

The initial setup was straightforward and easy to deploy.

What about the implementation team?

The time for deployment on the hardware takes only a few days.

What's my experience with pricing, setup cost, and licensing?

The current pricing is open source.

What other advice do I have?

I would highly recommend it, considering the current threats and cyber war also going on. if companies do not have a large budget to have a proper cybersecurity solution, they might consider Wazuh, another open source so that they can actually secure what is going on in the infrastructure. I would rate Wazuh a nine out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
PeerSpot user
Tiara Sakinah - PeerSpot reviewer
Information Technology Security Consultant at a computer software company with 1,001-5,000 employees
Consultant
Oct 5, 2022
Is easy to use both on the cloud and on-premises
Pros and Cons
  • "Wazuh is free and easy to use. It is also adjustable, and we can use it on the cloud and on-premises."
  • "Wazuh is free and easy to use, it is also adjustable, and we can use it on the cloud and on-premises."
  • "The technical support can be improved. Wazuh has some bugs that need to be fixed. It would be good if we can have automation with respect to incidence responses."
  • "The technical support can be improved. Wazuh has some bugs that need to be fixed."

What is most valuable?

Wazuh is free and easy to use. It is also adjustable, and we can use it on the cloud and on-premises.

What needs improvement?

The technical support can be improved. Wazuh has some bugs that need to be fixed.

It would be good if we can have automation with respect to incidence responses.

For how long have I used the solution?

I've been working with this solution for almost a year.

It's deployed both on the cloud and on-premises.

How are customer service and support?

I rate technical support at eight out of ten. It could be improved.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is easy.

Which other solutions did I evaluate?

We looked at AlienVault and EventLog Analyzer.

What other advice do I have?

If you have a small company or if you are new to SIEM and want to create your own tools, I highly recommend Wazuh.

I would rate Wazuh at eight on a scale from one to ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer1804125 - PeerSpot reviewer
Tech Lead Security at a comms service provider with 51-200 employees
Real User
Mar 18, 2022
Poor detection, lacking features, but simple installation
Pros and Cons
  • "The most valuable feature of Wazuh is the ELK for doing an investigation."
  • "The most valuable feature of Wazuh is the ELK for doing an investigation."
  • "Wazuh could improve the detection, it is not detecting all of the attacks. Additionally, it is lacking features compared to other solutions."
  • "Wazuh could improve the detection, it is not detecting all of the attacks. Additionally, it is lacking features compared to other solutions."

What is our primary use case?

We are using Wazuh for our SOC environment. We are managing and monitoring our infrastructure using the Wazuh SIEM

What is most valuable?

The most valuable feature of Wazuh is the ELK for doing an investigation.  

What needs improvement?

Wazuh could improve the detection, it is not detecting all of the attacks. Additionally, it is lacking features compared to other solutions.

For how long have I used the solution?

I have been using Wazuh for approximately six months.

What do I think about the stability of the solution?

Wazuh is a stable solution.

What do I think about the scalability of the solution?

I have found Wazuh to be scalable.

We have approximately six people using the solution. We plan to increase the usage of the solution.

How are customer service and support?

I have not used the support from Wazuh.

Which solution did I use previously and why did I switch?

I have used Splunk previously.

How was the initial setup?

The installation of Wazuh is simple.

What about the implementation team?

We did the implementation of the solution ourselves.

We have six technicians supporting the solution.

What's my experience with pricing, setup cost, and licensing?

There is not a license required for Wazuh.

What other advice do I have?

My advice to others is Wazuh is a good starter solution but there are other more advanced solutions on the market, such as Splunk which is an industry-level solution.

I rate Wazuh a five out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1785186 - PeerSpot reviewer
CBO at a security firm with 11-50 employees
Reseller
Feb 22, 2022
Offers good log monitoring and analysis tools
Pros and Cons
  • "The log monitoring and analysis tools are great in addition to SIEM file activity monitoring."
  • "The log monitoring and analysis tools are great in addition to SIEM file activity monitoring."
  • "I think that the next release should be more suitable for large enterprises, because currently they are not because large companies do not rely on open source solutions."
  • "I think that the next release should be more suitable for large enterprises, because currently they are not because large companies do not rely on open source solutions."

What is most valuable?

The log monitoring and analysis tools are great in addition to SIEM file activity monitoring.

What needs improvement?

I think that the next release should be more suitable for large enterprises, because currently they are not because large companies do not rely on open source solutions.

For how long have I used the solution?

I have been working with this solution for about four months.

What do I think about the stability of the solution?

For mid-level customer, stability is okay.

What do I think about the scalability of the solution?

This is a scalable solution.

How are customer service and support?

Support needs to be purchased on an annual basis but the support required is excellent.

How was the initial setup?

The initial setup is rather complex and takes a few days to perform. 

What's my experience with pricing, setup cost, and licensing?

This is a very price sensitive product.

What other advice do I have?

No hardware is required for this solution but be prepared to purchase implementation support. I would rate this solution a six or seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
reviewer1593909 - PeerSpot reviewer
Chief Information Security Officer at a financial services firm with 501-1,000 employees
Real User
Jun 6, 2021
Stable with good MITRE ATT&CK correlation, but needs a better user interface
Pros and Cons
  • "The MITRE ATT&CK correlation is most valuable."
  • "The MITRE ATT&CK correlation is most valuable."
  • "Its user interface for sure can be improved. It is not so comfortable to use if you're looking for specific logs."
  • "Its user interface for sure can be improved. It is not so comfortable to use if you're looking for specific logs."

What is our primary use case?

We collect logs in it, and then we correlate logs against the MITRE ATT&CK framework. We have configured some notifications.

What is most valuable?

The MITRE ATT&CK correlation is most valuable.

What needs improvement?

Its user interface for sure can be improved. It is not so comfortable to use if you're looking for specific logs.

For how long have I used the solution?

I have been using this solution for the last two years.

What do I think about the stability of the solution?

It is stable.

What do I think about the scalability of the solution?

I am not sure about scalability. We have a total of seven users. Our department has two people, and there are five people from the IT department. We don't have any plans to increase its usage at this time.

How are customer service and technical support?

I didn't use their technical support.

How was the initial setup?

I was not involved in its installation. I am just using it.

What about the implementation team?

Other colleagues from the IT department handle its installation. 

What other advice do I have?

For our usage, I would rate Wazuh a six out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Wazuh Report and get advice and tips from experienced pros sharing their opinions.
Updated: March 2026
Buyer's Guide
Download our free Wazuh Report and get advice and tips from experienced pros sharing their opinions.