What is our primary use case?
I use Wazuh for daily security operations mainly on EDR endpoints by installing it on the agents that we are monitoring to collect security data. It helps us monitor endpoints and know what is going on at each endpoint, and we are able to tap the data and use it in other platforms such as SOAR.
I find the threat hunting features of Wazuh most valuable, as we are more interested in the threat hunting side and want to move ahead into threat hunting before any threat becomes something that cannot be dealt with. Wazuh has a threat hunting functionality that we use extensively.
The intrusion detection capabilities work effectively in my environment, as we also have firewalls, and we rely more on the firewall side for intrusion detection.
What is most valuable?
The threat hunting features of Wazuh are particularly valuable for our operations. We focus heavily on threat hunting capabilities to address potential threats before they become unmanageable.
The intrusion detection capabilities integrate seamlessly with our existing firewall infrastructure. The system allows us to monitor endpoints effectively and collect security data that can be utilized across other platforms such as SOAR.
What needs improvement?
I think Wazuh should improve by introducing AI functionalities, as it would be beneficial to see AI incorporated in the threat hunting and detection functionalities. I hope this will be part of the new versions.
Regarding challenges with Wazuh, I cannot pinpoint specific difficulties. When I face a challenge, I prefer not to spend too much time on it and may move to another solution that will give us the results. Sometimes what seems a challenge is just an implementation issue, and while the documentation is comprehensive, it can become overwhelming when quick information is needed for implementation.
For how long have I used the solution?
I have been using Wazuh for about a year now.
What was my experience with deployment of the solution?
Wazuh is easy to set up, as it's clearly defined in their documentation, with various options such as bare metal or Docker implementations. The level of documentation is superior compared to other open source products.
Sometimes issues arise with some of these tools, but because they are open source, there are limitations to what can be expected.
What do I think about the stability of the solution?
I would rate the stability of Wazuh a nine out of ten.
What do I think about the scalability of the solution?
Currently, I don't see any limitations in terms of scalability as Wazuh can still connect many endpoints. I haven't encountered issues with the engine struggling, and it's simply a matter of having enough memory to handle open search memory issues. I think they've done exceptionally in terms of scalability.
I rate the scalability of Wazuh an eight out of ten, as I haven't reached the point of struggling with it.
How was the initial setup?
I would rate the setup of Wazuh a nine out of ten.
What was our ROI?
I have seen value in security cost savings with Wazuh, as using proprietary EDR versions could save us substantial money, but I haven't made any comparisons since we started using Wazuh immediately.
What's my experience with pricing, setup cost, and licensing?
Wazuh is completely free of charge.
What other advice do I have?
I have not seen Wazuh moving in the direction of AI-driven threat detection projects myself, but since the market is moving that way, I wouldn't be surprised if they implemented it soon.
My plans to increase the usage of Wazuh or switch to another tool depend on what my boss decides.
We don't refer to any community support specifically, as we rely on other platforms such as GitHub or Discord, depending on the application.
I recommend that as more companies come on board with Wazuh, it will motivate those who contribute to it, but I am also cautious that as it gains attention, a large company might buy it and change its course of business.
Overall, I rate Wazuh a nine out of ten.
Which deployment model are you using for this solution?
On-premises
*Disclosure: My company does not have a business relationship with this vendor other than being a customer.