No more typing reviews! Try our Samantha, our new voice AI agent.

Trellix XDR vs Wazuh comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 1, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
4.6
Cortex XDR offers high ROI with reduced costs, improved efficiency, affordable pricing, and enhanced security features compared to competitors.
Sentiment score
6.6
Trellix XDR boosts ROI by 20%, optimizes response times, reduces incidents, streamlines operations, and cuts workforce nearly in half.
Sentiment score
3.3
Wazuh offers rapid threat response and cost-effective security, benefiting small businesses with significant savings and no proprietary costs.
They appreciate the rich telemetry data from the solution, as it provides in-depth threat identification.
Cyber Security Manager at Welab bank
Cortex XDR by Palo Alto Networks helps to reduce my total cost of ownership significantly.
Detection and Response Consultant at Inovasys
In Cortex XDR by Palo Alto Networks, most of the remediation is automated and the accuracy is quite good.
Network Security Engineer at Cyberwell Solution
The workload has been reduced and the ROI has improved by around 20 percent.
Cyber Security Engineer Ii (Vulnerability & Threat Management) at FICO
I have seen a return on investment because, in terms of employees, 15 were cut down to eight, and it was also saving us time from the whole dashboard automation.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
Trellix helped us save our information, which is the most critical, and also save money.
System Administrator at a consultancy with 11-50 employees
I have seen value in security cost savings with Wazuh, as using proprietary EDR versions could save us substantial money.
Security Consultant at ebenezer.okoh@agorasecurity.it
 

Customer Service

Sentiment score
7.0
Cortex XDR is praised for technical support and responsiveness, despite occasional delays and varying regional support quality.
Sentiment score
6.1
Trellix XDR support receives mixed reviews; effectiveness and responsiveness vary by representative, with documentation often proving helpful.
Sentiment score
3.0
Wazuh offers valuable community forums and support, with a preference for cloud services despite occasional response time delays.
The technical support from Palo Alto deserves a mark of ten because they reach out within an hour whenever assistance is needed.
Head of data centers at a non-profit with 10,001+ employees
There is no back and forth, and they know what we are asking for and come up with the best resolution for a solution.
Senior Process Expert at A.P. Moller - Maersk
If any of these services are missed, it becomes a problem in terms of support tickets, follow-up, or special configuration that needs to be done in the system.
Chief of IT Architecture at a financial services firm with 10,001+ employees
If I require remote support, they will send a link to join a session and help me resolve any issues I have faced.
Cyber Security Engineer Ii (Vulnerability & Threat Management) at FICO
Technical support is crucial, especially when facing critical issues.
Information Security Engineer at Nhq Distribution Ltd
The most basic thing that you need from the vendor is support, and by the time they resolve it, you probably would have figured it out by yourself because the resolution came after weeks or months.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
They responded quickly, which was crucial as I was on a time constraint.
Cyber Security Software Engineer at a tech services company with 11-50 employees
We use the open-source version of Wazuh, which does not provide paid support.
Tech Lead at a tech vendor with 201-500 employees
The documentation is good and provides clear instructions, though it's targeted at those with technical backgrounds.
Student at Dakota State University
 

Scalability Issues

Sentiment score
7.5
Cortex XDR scales well for different organizations, but may be costly for small enterprises despite its cloud-based efficiency.
Sentiment score
7.5
Trellix XDR offers scalable, adaptable security management with centralized visibility and efficient threat detection for diverse organizational needs.
Sentiment score
6.4
Wazuh is seen as scalable, fitting small to medium businesses, with potential challenges in larger data and sectors.
You can onboard 10,000 endpoints in just hours, which demonstrates the excellent scalability of this product.
Assistant Security Architect at Cloudnomics
Activating the newly purchased licenses is instantaneous, allowing installations without adjustments since it's cloud-based.
Junior Security Analyst at ITSEC Asia
Cortex XDR by Palo Alto Networks can be expanded anytime by purchasing another license without any issues related to scalability.
Head of data centers at a non-profit with 10,001+ employees
Trellix XDR has good scalability because it can handle multiple security sources and multiple logs.
Cyber Security Engineer Ii (Vulnerability & Threat Management) at FICO
in our environment, we have fed a lot of data logs into the tool, and it has been reliable and scalable with no issues.
Security Consultant at Deloitte
You can scale from ten licenses to several thousand.
System Administrator at a consultancy with 11-50 employees
It can accommodate thousands of endpoints on one instance, and multiple instances can run for different clients.
Security Operations Center Analyst at mailbox.org
Currently, I don't see any limitations in terms of scalability as Wazuh can still connect many endpoints.
Security Consultant at ebenezer.okoh@agorasecurity.it
This is because of the backend work the agent is collecting and processing, causing the laptop to slow down and the bandwidth to decrease.
Security Consultant at Payatu
 

Stability Issues

Sentiment score
8.0
Cortex XDR by Palo Alto Networks is highly stable, resolving early issues and delivering consistent, reliable performance with minimal downtime.
Sentiment score
7.8
Trellix XDR is reliable with a strong support team, occasional downtime issues, and solid security expertise despite update concerns.
Sentiment score
6.3
Wazuh is reliable for small to mid-level businesses, despite occasional bugs and maintenance challenges affecting stability.
Cortex remains fast and responsive, even with increasing data and alerts.
Final Year Student at Gitam University
The thresholds we've seen on our firewall boxes at some instances reached 80% to 85%, but even at that level of utilization, we don't observe any latency or any issues reported with respect to accessing the application.
Senior Process Expert at A.P. Moller - Maersk
Cortex XDR by Palo Alto Networks can be trusted completely.
Soc Analyst at Softcell Technologies Limited
Support and stability are good. They are continuously improving.
Solutions Architect at Mideast Communication Systems-MCS
The system would go down for half an hour, an hour, or two hours in the off-hours which would then impact the business, impact the alerts, and the flow of alert.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
There is no downtime, or if there is, prior notification is sent to us so we can prepare accordingly.
Cyber Security Engineer Ii (Vulnerability & Threat Management) at FICO
The stability of Wazuh is strong, with no issues stemming from the solution itself.
Tech Lead at a tech vendor with 201-500 employees
The stability of Wazuh is largely dependent on maintenance.
Security Operations Center Analyst at mailbox.org
The indexer frequently times out, requiring system restarts.
Cyber Security Software Engineer at a tech services company with 11-50 employees
 

Room For Improvement

Cortex XDR needs better integration, user interface, automation, and competitive pricing, along with reduced performance issues and clearer features.
Trellix XDR challenges include high costs, complex setup, compatibility issues, and slow support, limiting accessibility and effectiveness.
Wazuh faces scalability and integration issues, needing enhanced security, AI features, and better support for large enterprises.
Improving reporting and dashboard customization, along with the addition of real-time and exportable reports, would help SOC teams greatly.
Final Year Student at Gitam University
The inclusion of this feature would allow the application of DLP policies alongside antivirus policies via a single agent and console, making it more competitive as other OEMs often offer DLP solutions as part of their antivirus products.
Pre Sales Architect at network techlab
If the per GB data could be provided at a certain level free of cost or at the same cost which the customer is taking for the entire bundle, that would be better.
Cyber Security Information Security Specialist at MHM Holding GmbH
Trellix support team is not highly regarded because they follow a whole hierarchical process to escalate the complaints and the feedback requests, and the resolution can take very long, from two to three weeks to a month, which is not really viable in a cybersecurity landscape which is moving this fast.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
Continuous enhancement to automation and AI-driven threat prioritization would further reduce analysts' workflow and improve response effectiveness.
Business development executive at Digitaltrack solution Pvt Ltd
The trend these days is moving toward AI security, and Trellix XDR should align with this direction.
Solutions Architect at Mideast Communication Systems-MCS
Machine learning is needed along with understanding user behavior and behavioral patterns.
Engineer Information Security at N-Able (Pvt) Ltd
If we had a correlation of logs where I could just search one unique ID and then the unique ID pulls every system in a time-wise manner, that would be a great improvement I would suggest.
Security Consultant at Payatu
The integration modules are insufficiently developed, necessitating the creation of custom integration solutions using tools like Logstash and PubSub.
Tech Lead at a tech vendor with 201-500 employees
 

Setup Cost

Cortex XDR's pricing is seen as reasonable for its advanced capabilities, though setup costs can be perceived as high.
Trellix XDR offers competitive pricing for large enterprises, but recent price increases challenge affordability for small businesses.
Wazuh's open-source solution is cost-effective for enterprises, with cloud costs and scalability as key considerations.
The pricing on SentinelOne is far more reasonable and cheaper than Cortex XDR by Palo Alto Networks.
Consultant at a tech services company with 1,001-5,000 employees
I would say it is definitely not a cheap product, considering how mature it is and how scalable all Palo Alto products are together.
Senior Process Expert at A.P. Moller - Maersk
Compared to CrowdStrike, which is very costly, and SentinelOne, which is also very costly, Cortex XDR by Palo Alto Networks is a medium cost-efficient solution.
Soc Analyst at Softcell Technologies Limited
But currently, they have bumped up the prices and that is why we have now moved to a different solution totally. We have left Trellix XDR.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
My experience with pricing, setup cost, and licensing shows that the pricing is very competitive and not overly expensive.
Security Engineer at i360
Wazuh is completely free of charge.
Security Consultant at ebenezer.okoh@agorasecurity.it
I would definitely recommend Wazuh, especially considering Fortinet's licensing model which is confusing and overpriced in my opinion.
Engineer Information Security at N-Able (Pvt) Ltd
Totaling around two lakh Indian rupees per month.
Tech Lead at a tech vendor with 201-500 employees
 

Valuable Features

Cortex XDR enhances security with AI-driven analytics, user-friendly management, cloud deployment, and comprehensive threat response features.
Trellix XDR enhances threat detection and response through automation, integration, AI assistance, and contextual data, improving security operations.
Wazuh offers open-source security solutions with cloud integration, exceptional logging, scalability, and compatibility with platforms like Azure and AWS.
It incorporates AI for normal behavior detection, distinguishing unusual operations.
Cyber Security Manager at Welab bank
The product provides automation responses in case of a threat attack, severity assessments, centralized manageability, and comprehensive compliance features, resulting in reduced costs.
Pre Sales Architect at network techlab
It includes machine learning to easily analyze data and detect complex threats across endpoints, networks, or clouds.
Final Year Student at Gitam University
The core functionality includes EDR and NDR, and Trellix XDR gets threat detection on both the network and endpoint levels.
Solutions Architect at Mideast Communication Systems-MCS
The second feature is its ability for cross-platform threat correlation, meaning the platform helps to correlate all events across endpoints, network activity, security controls, and threat intelligence sources, providing us with a more in-depth view in terms of threat detection and threat research.
Security Consultant at Deloitte
You can start as a small company and when you own Trellix XDR, as your company grows, you can grow your Trellix XDR subscription from on-premise, for example, to the cloud.
System Administrator at a consultancy with 11-50 employees
Wazuh is a SIEM tool that is highly customizable and versatile.
Security Operations Center Analyst at mailbox.org
The system allows us to monitor endpoints effectively and collect security data that can be utilized across other platforms such as SOAR.
Security Consultant at ebenezer.okoh@agorasecurity.it
With this open source tool, organizations can establish their own customized setup.
Cyber Security Software Engineer at a tech services company with 11-50 employees
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Extended Detection and Response (XDR)
4th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
115
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (5th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
Trellix XDR
Ranking in Extended Detection and Response (XDR)
18th
Average Rating
7.6
Reviews Sentiment
6.6
Number of Reviews
10
Ranking in other categories
No ranking in other categories
Wazuh
Ranking in Extended Detection and Response (XDR)
5th
Average Rating
7.4
Reviews Sentiment
5.9
Number of Reviews
51
Ranking in other categories
Log Management (2nd), Security Information and Event Management (SIEM) (3rd)
 

Mindshare comparison

As of August 2026, in the Extended Detection and Response (XDR) category, the mindshare of Cortex XDR by Palo Alto Networks is 4.5%, down from 5.0% compared to the previous year. The mindshare of Trellix XDR is 0.8%, up from 0.3% compared to the previous year. The mindshare of Wazuh is 4.9%, down from 9.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Extended Detection and Response (XDR) Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks4.5%
Wazuh4.9%
Trellix XDR0.8%
Other89.8%
Extended Detection and Response (XDR)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
Twinkle Solanki - PeerSpot reviewer
Business development executive at Digitaltrack solution Pvt Ltd
Unified threat detection has improved investigations and now speeds up incident response
While Trellix XDR is a strong platform overall, there are a few areas where it could be improved. The initial setup and configuration can be complex, especially for organizations with diverse environments. Some additional advanced features also have a learning curve and may require extra training for security teams to fully utilize them. Moreover, reporting and dashboard customization could be more flexible, allowing users to create highly customized views and reports more easily. There are also areas that could optimize detection surveys. Addressing these areas would further enhance the overall experience and operational effectiveness. One additional improvement would be deeper integration with a wider range of third-party security tools and cloud platforms. While Trellix XDR integrates with many solutions, simplifying the integration management would help organizations with complex security ecosystems. I would like to see more out-of-the-box reports and executive-level dashboards that make it easier to communicate security metrics to leadership. Finally, continuous enhancement to automation and AI-driven threat prioritization would further reduce analysts' workflow and improve response effectiveness. Overall, these are areas that need refinement rather than being major concerns, as the platform still delivers strong security and operational value.
RS
Engineer Information Security at N-Able (Pvt) Ltd
Has faced limitations in AI capabilities and pricing flexibility
Pricing-wise, Wazuh stands out, along with deployment flexibility and its documentation which is extremely good in comparison to Forti. The community support is also incredible. They have helped quite a bit because previously, we had a separate tool and management dashboard to do our compliance. With Wazuh, we receive that information without having to do anything extra. We just set up the SIEM and all of that information was automatically populated. The dashboards are very easy to understand and very quick with no lag or delay. I have experienced delays on Forti's dashboards, but not with Wazuh. Wazuh is quite good. In comparison to Forti, they are quite similar. They are very good at detection.
report
Use our free recommendation engine to learn which Extended Detection and Response (XDR) solutions are best for your needs.
908,800 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
13%
Financial Services Firm
10%
Comms Service Provider
10%
Manufacturing Company
10%
Financial Services Firm
14%
Computer Software Company
13%
Outsourcing Company
11%
Comms Service Provider
8%
Comms Service Provider
12%
Computer Software Company
10%
University
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise21
Large Enterprise54
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise3
Large Enterprise7
By reviewers
Company SizeCount
Small Business27
Midsize Enterprise15
Large Enterprise9
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What is your experience regarding pricing and costs for Trellix XDR?
My experience with pricing, setup cost, and licensing shows that the pricing is very competitive and not overly expen...
What needs improvement with Trellix XDR?
I believe Trellix XDR can be improved with more automation. I would like more improvements in terms of response.
What is your primary use case for Trellix XDR?
My main use case for Trellix XDR is supporting our clients and their EDR requirements. A specific example of how I us...
What do you like most about Wazuh?
Wazuh is its flexibility and open-source nature, which allows us to tailor threat detection and response across diver...
What needs improvement with Wazuh?
I expected one thing from the dashboard in Wazuh. In ManageEngine, when you use ManageEngine, you can assign a unique...
What is your primary use case for Wazuh?
Our organization is focusing on the integrity part for implementing Wazuh. We were checking solutions for File Integr...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
MVision XDR, MVision eXtended Detection and Response
Wazuh All-In-One Deployment
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Information Not Available
Information Not Available
Find out what your peers are saying about Trellix XDR vs. Wazuh and other solutions. Updated: June 2026.
908,800 professionals have used our research since 2012.