Forescout Platform and Wazuh compete in the network access control and security monitoring categories respectively. Forescout has the upper hand in comprehensive network access control and device management, while Wazuh shines in open-source security monitoring and integration capabilities.
Features: Forescout Platform offers agentless network access control, exceptional endpoint visibility without the need for 802.1x, and robust integration with third-party products. Wazuh provides comprehensive log monitoring, host-based intrusion detection, and compliance checking, all within its open-source framework.
Room for Improvement: Forescout's reporting features and partner integration need enhancement, and licensing can be complex. Wazuh requires improvement in threat detection and scalability, and could benefit from advanced AI-driven features for better threat intelligence.
Ease of Deployment and Customer Service: Forescout supports primarily on-premises deployments with limited hybrid cloud capabilities, and its customer support has varied feedback, particularly in response times. Wazuh offers flexible deployments for on-premises and cloud environments, although clearer guidance and documentation for customer support are necessary.
Pricing and ROI: Forescout's pricing is high due to additional costs for support and integration, yet its ROI is often justified by enhanced security. Wazuh has a lower total cost of ownership as an open-source solution, despite potential expenses for deployment and support services.
I have seen value in security cost savings with Wazuh, as using proprietary EDR versions could save us substantial money.
We have had experience with their technical support and must pay additionally for maintenance, support, and regional service.
They responded quickly, which was crucial as I was on a time constraint.
We use the open-source version of Wazuh, which does not provide paid support.
The documentation is good and provides clear instructions, though it's targeted at those with technical backgrounds.
Scalability can be costly since a physical box needs to be installed for every site.
It can accommodate thousands of endpoints on one instance, and multiple instances can run for different clients.
Currently, I don't see any limitations in terms of scalability as Wazuh can still connect many endpoints.
Scalability depends on the configuration and the infrastructure resources like compute and memory we allocate.
I would rate its stability as 9.5 out of ten.
The stability of Wazuh is strong, with no issues stemming from the solution itself.
The stability of Wazuh is largely dependent on maintenance.
The indexer frequently times out, requiring system restarts.
Forescout Platform could enhance its integration of AI to improve IoT and OT device security to better meet our needs.
The console is a fat client, and a web interface would be preferable.
Machine learning is needed along with understanding user behavior and behavioral patterns.
The integration modules are insufficiently developed, necessitating the creation of custom integration solutions using tools like Logstash and PubSub.
I think Wazuh should improve by introducing AI functionalities, as it would be beneficial to see AI incorporated in the threat hunting and detection functionalities.
Installing a physical box on each site can be expensive.
The overall pricing of Forescout Platform is reasonable for the functionality it provides.
Wazuh is completely free of charge.
I would definitely recommend Wazuh, especially considering Fortinet's licensing model which is confusing and overpriced in my opinion.
Totaling around two lakh Indian rupees per month.
One of the most valuable features of Forescout Platform is its automation, particularly the ability to automate remediation of rogue devices on the network.
The most effective feature has been network access management, which has been crucial for our primary use cases in the organization.
Wazuh is a SIEM tool that is highly customizable and versatile.
The system allows us to monitor endpoints effectively and collect security data that can be utilized across other platforms such as SOAR.
With this open source tool, organizations can establish their own customized setup.
Product | Market Share (%) |
---|---|
Wazuh | 10.2% |
Forescout Platform | 0.8% |
Other | 89.0% |
Company Size | Count |
---|---|
Small Business | 30 |
Midsize Enterprise | 10 |
Large Enterprise | 43 |
Company Size | Count |
---|---|
Small Business | 26 |
Midsize Enterprise | 15 |
Large Enterprise | 8 |
Forescout Platform provides today’s busy enterprise organizations with policy and protocol management, workflow coordination, streamlining, and complete device and infrastructure visibility to improve overall network security. The solution also provides concise real-time intelligence of all devices and users on the network. Policy and protocols are delineated using gathered intelligence to facilitate the appropriate levels of remediation, compliance, network access, and all service operations. Forescout Platform is very flexible, integrates well with most of today’s leading network security products, and is a very cost-effective solution.
Forescout Platform Features
Real User Reviews
An important main feature of Forescout is the visibility the solution offers.
One reviewer who is a Consultant at a tech services company, says, "Within three or four days, you can have complete visibility of your infrastructure on the network. Compared to other solutions, the deployment of the solution is easier and we can close the project quickly."
Users also appreciate that the user interface is clear and easy to understand.
An Instructor at a tech services company, shares, "The most valuable feature of the Forescout Platform is the large capacity it can handle. Additionally, the interface of the platform is good."
Wazuh offers comprehensive security features like MITRE ATT&CK correlation, log monitoring, and cloud-native infrastructure. It ensures compliance and provides intrusion detection with high scalability and open-source flexibility, ideal for businesses seeking robust SIEM capabilities.
Wazuh stands out in security information and event management by providing efficient log aggregation, vulnerability scanning, and event correlation against MITRE ATT&CK. Its capability to integrate seamlessly with environments, manage compliance, and monitor files makes it suitable for cloud-native infrastructures and financial sectors. Despite its technical support needing enhancement and opportunities for improving AI integration and threat intelligence, its open-source nature and cost-effectiveness make it appealing. Users can leverage custom dashboards powered by Elasticsearch for precise data analysis, even though there is a desire for a more user-friendly interface and better enterprise solution integration. Deployment may be complex, but its features contribute significantly to fortified security postures.
What are the essential features of Wazuh?Industries like finance and cloud infrastructure heavily utilize Wazuh for its security strengths. By monitoring endpoints and ensuring compliance with frameworks, companies can improve security posture and swiftly detect anomalies. The platform's focus on event correlation and alerts for security incidents is particularly beneficial.
We monitor all Extended Detection and Response (XDR) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.