No more typing reviews! Try our Samantha, our new voice AI agent.
Principal Architect at Calsoft
Real User
Sep 15, 2022
The pile integrity monitoring features are solid, but log analysis could be improved.
Pros and Cons
  • "The configuration assessment and Pile integrity monitoring features are decent."
  • "Stability-wise, Wazuh seems to have fixed all the past issues, and the latest version is possibly the most stable."
  • "Log data analysis could be improved. My IT team has been looking for an alternative because they want better log data for malware detection. We are also doing more container implementation also, so we need better container security, log data analysis, auditing and compliance, malware detection, etc."

What is our primary use case?

Our primary use case for Wazuh is monitoring endpoints. The second is incident management. Logging is essential for us because of Indian IT compliance rules require us to store logs for 180 days. We need to monitor and maintain logs also. 

Wazuh is monitoring around 1,200 inputs, but there are only about four or five members of the IT team directly using the solution. 

What is most valuable?

The configuration assessment and pile integrity monitoring features are decent.

What needs improvement?

Log data analysis could be improved. My IT team has been looking for an alternative because they want better log data for malware detection. We are also doing more container implementation also, so we need better container security, log data analysis, auditing and compliance, malware detection, etc. 

Overall, the implementation part of Azure is tricky. It can be simplified and automated more to shorten the deployment timeline, so we can immediately onboard the application. The entire implementation process should be user-friendly.

For how long have I used the solution?

We implemented Wazuh in 2019.

Buyer's Guide
Wazuh
May 2026
Learn what your peers think about Wazuh. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
900,644 professionals have used our research since 2012.

What do I think about the stability of the solution?

I rate Wazuh six out of 10 for stability. While we haven't seen any incidents lately, it used to crash a few years back. The dashboard would be inaccessible due to some service failure or something. 

What do I think about the scalability of the solution?

I rate Wazuh eight out of 10 for scalability.

How are customer service and support?

We use community forums like Stack Overflow to find answers. Most debugging and troubleshooting processes are readily available online. 

How was the initial setup?

Setting up Wazuh is complex. The deployment involved two IT engineers and took about two months

What about the implementation team?

We deployed Wazuh. 

What's my experience with pricing, setup cost, and licensing?

Wazuh is a free solution. 

Which other solutions did I evaluate?

We tried to replace Wazuh with a CrowdStrike real-time security solution. We also tried some solutions from one of our vendors We want to move to either Elastic or CrowdStrike.

What other advice do I have?

I rate Wazuh six out of 10. It's a solid open-source. Stability-wise, Wazuh seems to have fixed all the past issues, and the latest version is possibly the most stable. However, they need to add more features to keep up with the competition. Compared to products like Elastic, Wazuh still lacks a lot of in-depth information. It's still not possible to do a dive, and the configuration could be easier.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PrzemekAndula - PeerSpot reviewer
Cybersecurity specialist at a manufacturing company with 51-200 employees
Real User
Feb 14, 2024
A product that offers good integration capabilities to its users
Pros and Cons
  • "The product is easy to customize."
  • "The tool does not provide CTI to monitor darknet."

What is our primary use case?

My company uses Wazuh in our lab environment, where we have 100 endpoints.

What needs improvement?

The tool does not provide CTI to monitor darknet. In the future, I want the tool to provide CTI to monitor the darknet so that by creating a single query, I can monitor the darknet.

For how long have I used the solution?

I have been using Wazuh for a year. I am an end user of the solution.

What do I think about the stability of the solution?

Stability-wise, I rate the solution a five or six out of ten.

My company has a problem with the stability of the product because we don't have a high-availability architecture. The fact that my company does not have a high availability architecture might be our company's problem.

What do I think about the scalability of the solution?

Around three security operators in my company use the product.

Though I want the use of the product to be increased in the company, the decision to do so lies in the hands of the management.

How are customer service and support?

I have not contacted the tool's support team. If my company contacts the product's support team, it would be easier for our company to deal with the product's areas like deployment and usage. In the upcoming year, I would like to use the commercial tech support offered by the product.

Which solution did I use previously and why did I switch?

Previously, I have used IBM QRadar, SentinelOne, and Splunk, which were all very expensive products.

My company started to use Wazuh considering its low prices compared to other solutions.

How was the initial setup?

I rate the product's initial setup phase an eight or nine on a scale of one to ten, where one is difficult, and ten is easy. Wazuh is a very simple tool.

The solution is deployed on a private cloud.

It is difficult to comment on how much time is required to deploy the product since there is always a need to add new log sources and integration. The solution can be deployed in a few days so that the testing phase can be carried out.

What's my experience with pricing, setup cost, and licensing?

Wazuh is a cheaply priced product.

What other advice do I have?

The product has been implemented in my company's environment for threat direction straight out of the box through a simple implementation process.

My company uses the product for threat detection and to create and tune playbooks with roles. My company uses the product in our lab environment, so it's not used for production, which makes it easier for us to deal with the tuning part of the product.

The product helps our company's ability to comply with industry standards since we use the CIS benchmark for hardening GDPR compliance.

My company uses the product for event analysis. My company uses Wazuh as a SIEM solution.

My company uses the product for many of our use cases, and we also deal with the configuration part of the tool. My company is trying to tune the product, and it is possible to use it for event analysis with Wazuh. The product is effective in terms of event analysis.

The integration capabilities of the product with other tools, like FortiGate and NetFlow, are good.

More time is required for me to be able to see how the product's scalability can impact our company's environment.

The product is easy to customize. The product provides good setup documentation regarding the language to be used to use the product's customization abilities. The product offers a good level of documentation along with a good online community. On the internet, it is easier to get information about any problem or issue users face with the tool.

I recommend the product be used in a team with fewer members for security operations. The tool can be used if you work in areas like security and administration, where it can be easily used and implemented.

I rate the tool an eight out of ten.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Wazuh
May 2026
Learn what your peers think about Wazuh. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
900,644 professionals have used our research since 2012.
Gopinath Ravirajan - PeerSpot reviewer
IT Lead at a financial services firm with 51-200 employees
Real User
Oct 14, 2023
The solution did a good job at ensuring PCA nodes were PCI compliant
Pros and Cons
  • "Wazuh is simple to use for PCI compliance."
  • "Some features, like alerting, are complex with Wazuh."

What is our primary use case?

We use Wazuh for PCI compliance monitoring. It can detect whether a server or PCA node is PCI compliant.

What is most valuable?

Wazuh is simple to use for PCI compliance.

What needs improvement?

Some features, like alerting, are complex with Wazuh. Setting up alerts and triggers can be difficult, and the interface could be better. Compared to other platforms, such as New Relic, Wazuh's UI could be improved. New Relic has a similar interface, but the UI updates have made it a better product.

We have certain requirements regarding monitoring and whether Wazuh is completely compliant with them. It would be helpful to know if Wazuh is a complete solution for log monitoring, including the requirements of PCA and other security aspects.

For how long have I used the solution?

I have been using Wazuh for a couple of months. We are using the latest version of the solution.

What do I think about the stability of the solution?

While installing some agents, our team faced some issues. However, the stability is otherwise good. I rate the solution's stability a seven out of ten.

What do I think about the scalability of the solution?

The solution is scalable. We've three to five users using this solution. I rate the solution's scalability a seven or eight out of ten.

How are customer service and support?

Wazuh provided good support for whatever usage or issues we were facing. They were ready to support us at any point.

Which solution did I use previously and why did I switch?

We have used ELK before, but it was not a complete solution for our needs. We needed to integrate it with other solutions. Wazuh seemed a more comprehensive solution, especially compared to other providers. We also tried products from a local company, but their service was not as good as Wazuh. It is also an established company. We decided to use Wazuh.

How was the initial setup?

The initial setup of Wazuh is simple. The internal person sets up the application and installs the agents. They were able to do it in a day. Both setup and configuration are straightforward.

What's my experience with pricing, setup cost, and licensing?

The solution's pricing is very competitive. I rate the solution's pricing a nine out of ten, where one is expensive and ten is cheap.

What other advice do I have?

Overall, I rate the solution an eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Rizwan-Alam - PeerSpot reviewer
Head Information Security at Akhtar Fuiou Technologies
Real User
Mar 6, 2023
Great for monitoring infrastructure and for vulnerabilities
Pros and Cons
  • "Good for monitoring, active response, and for vulnerabilities."
  • "A lack of certain features creates limitations."

What is our primary use case?

I use this product as an integrity marketing solution in the financial sector. We are users of Wazuh and I'm head of information security. 

What is most valuable?

The product is good for security-related features like monitoring, active response, and for vulnerabilities. I'm currently using the whole feature setup for Azure, from A to Z, everything. Wazuh enables me to monitor my whole infrastructure. I have Windows Linux and the firewalls are also integrated with Wazuh. 

What needs improvement?

The rules are very difficult because there are some limitations such as the inability to correlate two events. It should be easy to edit or change, but it can't be done. They are technical issues and I'm assuming they will be fixed over time.  

For how long have I used the solution?

I've been using this solution for four years. 

What do I think about the stability of the solution?

The solution is stable. 

What do I think about the scalability of the solution?

The solution is highly scalable but from a deployment perspective, it's quite difficult. We have five internal users and around 200 agents using the solution. 

How are customer service and support?

I haven't used the customer support because I'm using the open source version. 

How was the initial setup?

The initial setup can be complex. It's not a smooth process and I need an expert system engineer to deploy it in a clustered environment. 

What's my experience with pricing, setup cost, and licensing?

There's no licensing fee because we're using the open-source version. 

What other advice do I have?

I like this product and the fact that we're getting everything for free. However, it's a complex solution to deploy and manage and that's a pain point for us so I deduct two points and rate it eight out of 10. 



Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Sulabh Khanal - PeerSpot reviewer
Head of DevSecOps at Vairav Technology
Real User
Nov 15, 2022
Good vulnerability assessment and scoring with helpful support
Pros and Cons
  • "The deployment is easy and they provide very good documentation."
  • "Other than that, it's a highly recommended product from our side, and we wish that this product had intel support."
  • "We would like to see more improvements on the cloud. They need better cloud integration."

What is our primary use case?

We're using it in our company as well as our customer's companies. 

It is usually used for SIM and log collection and licenses.

What is most valuable?

The vulnerability assessment and scoring of Wazuh is the most important feature that we have found. 

It also integrates well with Windows and different types of operating systems as well, so we found it very easy to deploy.

It is stable. 

The deployment is easy, and they provide very good documentation.

It can scale well.

Technical support is quite helpful.

What needs improvement?

We would like to see more improvements on the cloud. They need better cloud integration. We already have it on the latest version. However, we have yet to upgrade it. We'd like to see more overall integration support. That includes integration with cloud providers and more API-based integration, which would be helpful for lots of other integrations as well.

The active response needs to be better. I hope they create something on the front end. We have to do a lot of backend coding in Wazuh for active response. That's the major thing that we would like to see to improve it.

For how long have I used the solution?

We've been using the solution for around one year.

What do I think about the stability of the solution?

The product is very stable. We have had it deployed for more than six months and we deployed that product on our premises and also on the customer's end. We haven't found any performance issues so far.

What do I think about the scalability of the solution?

As far as I can see, it is scalable. 

We've deployed it in a Kubernetes cluster, and Wazuh works in a clustered environment. It is a cluster-aware product. We can scale it as much as we want to in the future.

Right now, our SOC Analyst team, which is around 11 to 15 people, as well as a few customers, are using the solution currently. 

How are customer service and support?

Technical support is very extensive. We had a long conversation regarding some role-based access control with their team, and they were really helpful, and the support was really good, even though we were using the open-source version of that product.

Which solution did I use previously and why did I switch?

We did previously use Alien Vault. There are some licensing obligations, so it's a bit difficult to maintain. We also preferred using an open-source option.

How was the initial setup?

It is very easy to deploy and works well with different types of operating systems. 

They provide very good documentation, and they also have got it in containers, so it was very easy to set up.

The overall agent installation and the server installation took maybe half an hour.

What's my experience with pricing, setup cost, and licensing?

We're using the open-source version, and their licensing is fairly straightforward. We do not have to worry about any other monitoring matters since we are using the pre-version.

What other advice do I have?

We're customers. We're using multi-tenant and have companies that are mostly SMEs. We also have a few enterprises as well. 

My advice to new users is that you should do extensive research and need a system team in your company to deploy, configure, and set up everything. Other than that, it's a highly recommended product from our side, and we wish that this product had intel support. I hope that it improves in the future as well.

According to the use case scenario we have, I would rate it an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Vijay Muddu - PeerSpot reviewer
Manager server admin and security at Vivaconnect
Real User
Nov 3, 2022
Security monitoring solution that facilitates custom logs and automatically scans for benchmarks but could have improved scalability
Pros and Cons
  • "Wazuh automatically scans the host for CIS benchmarks for the latest updates and vulnerabilities and gives a host score. It provides a percentage of perceived risk due to of non patches or any missing patches on that work."
  • "I would definitely recommend Wazuh to those who want a SIEM tool as a central logging system and for log management."
  • "Scalability is a challenge because it is distributed architecture and it uses Elastic DB. Their Elastic DB doesn't allow open source waste application."

What is our primary use case?

We wanted a solution as an in-house SIEM tool, which can collect security and order logs for compliance purposes. We tried to explore a lot of tools and considering our budget and use cases, this tool matched our requirements.

We have five to seven users and we will be adding more users.

What is most valuable?

There are two features that stand out. Wazuh automatically scans the host for CIS benchmarks for the latest updates and vulnerabilities and gives a host score. It provides a percentage of perceived risk due to of non patches or any missing patches on that work. Second, we can configure the logs per our requirement. 

What needs improvement?

The scalability of this solution could be improved. 

For how long have I used the solution?

We have been Wazah for the past month. 

What do I think about the stability of the solution?

This is a stable solution but we have only tested that for one month. 

What do I think about the scalability of the solution?

Scalability is a challenge because it is distributed architecture and it uses Elastic DB. Their Elastic DB doesn't allow open source waste application. 

How are customer service and support?

We have not reached out to the support team. We have just followed the Wazuh online documentation.

How was the initial setup?

The initial setup is a little bit complex as it takes some time to understand the configurations. 

What about the implementation team?

We started the implementation with the assistance of a consultant but completed it in-house. 

What other advice do I have?

I would definitely recommend Wazuh to those who want a SIEM tool as a central logging system and for log management. You can complete the necessary security audits using this tool and have your security alerts configured if your system is receiving unknown attacks.

Overall, this is a fantastic tool but you will need an expert to assist with configuration. Scaling this solution is also challenging. We have not tested migrating from one server to another. 

I would rate this solution a six out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
SHEERAZ AHMED - PeerSpot reviewer
Managing Director at SharpTel
Real User
Oct 14, 2022
Great reporting features that allow us to complete forensic tasks and track attacks
Pros and Cons
  • "Wazuh has very flexible and robust features."
  • "The reporting and attractive dashboard are the most valuable features."
  • "The computing resources are consuming and do not make sense."

What is our primary use case?

It is a basic level requirement for the compliance factor. There is regulatory compliance by the regulator called CDDISR, and we need to ensure that all the network's critical components send the logs. Wazuh allows us to complete forensic tasks to track any attacks.

What is most valuable?

The reporting and attractive dashboard are the most valuable features. We used Splunk, but it was a bit expensive. On the other hand, Wazuh has very flexible and robust features.

What needs improvement?

The computing resources are consuming and do not make sense. It should be lighter in terms of memory, CPU, and computing. There is a direct need for improvisation for any user, and it should be lighter than the current version. In the next release, they should include secure mobile app integration.

For how long have I used the solution?

We have been using this solution for almost three months. It is deployed on-premises by our vendor.

What do I think about the stability of the solution?

It is a stable solution, and the performance is good.

What do I think about the scalability of the solution?

It is scalable and does not require adding further devices. The number of devices that we already have are listed there. The basic use case is the compliance factor, and there's no additional need. However, if we start doing more extensive logging, we might need Splunk because Wazuh has some limitations in consuming heavier resources. Splunk is the best for large data computing and big data.

How are customer service and support?

The vendor provides support, but we haven't approached them for support yet.

How was the initial setup?

We hired a third-party company for the setup, and they took considerable time to complete it. They were not experts, and it took them about a week. It should have taken only about three days. I rate the setup an eight out of ten. After setup, it does not require any additional maintenance.

What's my experience with pricing, setup cost, and licensing?

We paid a lump sum as managed services, so the operator charges an amount for a year using a complete compliance system. The complete compliance system is just one component, so we are not being charged separately for the suite. This means we have the luxury of using it as a combo deal.

What other advice do I have?

I rate this solution an eight out of ten. Regarding advice, if anyone is going for Wazuh, they have to understand their buying compute if they're going on cloud. They should ideally evaluate the Apple-to-Apple comparison between the products in terms of how computing-intensive the product is. So if Wazuh is inefficient in computing, it should be option two. They should identify any other product which has efficient computing capabilities. There should also be a skilled resource available as an implementation partner.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Dr. Sushan Banerjee - PeerSpot reviewer
GISO - Global Information Security Officer at Beyon Connect
Real User
Jul 27, 2022
A free and open source security monitoring solution with useful cloud-native infrastructure, but it would be better if they had an app with an alerting mechanism
Pros and Cons
  • "I like the cloud-native infrastructure and that it's free. We didn't have to pay anything, and it has the capabilities of many premium solutions in the market. We could integrate all of our services and infrastructure in the cloud with Wazuh. From an integration point of view, Wazuh is pretty good. I had a good experience with this platform."
  • "It would be better if they had a vulnerability assessment plug-in like the one AlienVault has. In the next release, I would like to have an app with an alerting mechanism."

What is our primary use case?

We integrated all of our services and infrastructure in the cloud with Wazuh.

What is most valuable?

I like the cloud-native infrastructure and that it's free. We didn't have to pay anything, and it has the capabilities of many premium solutions in the market. We could integrate all of our services and infrastructure in the cloud with Wazuh. From an integration point of view, Wazuh is pretty good. I had a good experience with this platform.

What needs improvement?

It would be better if they had a vulnerability assessment plug-in like the one AlienVault has. In the next release, I would like to have an app with an alerting mechanism.

For how long have I used the solution?

I have been working with Wazuh for two and a half years.

What do I think about the stability of the solution?

Wazuh is a stable solution.

What do I think about the scalability of the solution?

Wazuh is a scalable solution. We had 18 employees using this solution.

Which solution did I use previously and why did I switch?

We had an AlienVault setup, but it does not support the cloud servers and infrastructure. Wazuh is known for cloud security event management.

How was the initial setup?

It took less than ten days for the integration and to get the complete setup up and running.

What about the implementation team?

Wazuh was implemented by one of my team members, who is a Wazuh expert. This employee did the complete installation and everything else.

What's my experience with pricing, setup cost, and licensing?

Wazuh has a community edition, and I was using that. It's free and open source.

What other advice do I have?

I would tell potential users to review the technical implementation documentation before setting up Wazuh. This is because setting up Wazuh is a little bit tricky for a newbie because they won't be able to understand the technicalities of the solution. Just go through the technical documentation and implementation documentation once before installing Wazuh.

On a scale from one to ten, I would give Wazuh a seven.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Software Engineer at a computer software company with 1,001-5,000 employees
Real User
Top 20
Dec 16, 2024
Good for file integrity monitoring
Pros and Cons
  • "Wazuh offers numerous features, such as the ability to define custom rules for detecting malicious activities and remembering behaviors."
  • "The only challenge we faced with Wazuh was the lack of direct support."

What is our primary use case?

We are using Wazuh for security information and event management, PCI DSS compliance, auditing, real-time sensitive monitoring, and meeting regulatory requirements.

How has it helped my organization?

There were certain tasks we couldn't carry out before. However, with Wazuh, we found a solution within a single platform. It only required a one-time effort to set up and configure the version. After that, it's just about monitoring the alerts and making revisions. No additional efforts are needed.

What is most valuable?

The most valuable features include file integrity monitoring, Wazuh engines, Wazuh rulesets (including rulesets for Apache and firewall routers), and vulnerability detection.

What needs improvement?

There is room for improvement in Wazuh, but it's possible they are already working on it. The only challenge we faced with Wazuh was the lack of direct support. They charge for support, whether it's five days a week or seven days a week. We don't expect it to be free because revenue is generated through the support they provide. 

In future releases, I would like to see a feature. There is one feature we observed in a premium tool in the industry called Dynatrace. It provides automatic relations between different devices and components. For instance, if you receive a web login request, Dynatrace can trace and show you the path it takes from the firewall to the switch, then to the Apache server, the actual job application, and finally back to the client. It intelligently correlates all the components involved in a single event. 

If Wazuh could include this feature, where all the components are integrated, it would automatically relate them for any activity in your environment.

For how long have I used the solution?

We have been working with Wazuh for the last year. We currently use the latest version.

What do I think about the stability of the solution?

Sometimes, it has disturbances, but at the end of the day, it's not Wazuh but, actually, the configurations that engineers do sometimes do not have compatibility. So at that time, we face issues, but as of now, Wazuh has not disappointed us in any way.

What do I think about the scalability of the solution?

It is scalable. We can add a new machine or server, install the components, and inform the other components about its IP address. We add it to the cluster, and a restart of the cluster is all that's needed to integrate the new component.

While there are many people involved, only three or four security engineers manage and oversee the events collected and provided by Wazuh.

Which solution did I use previously and why did I switch?

We used Splunk primarily for log management purposes. There were no extra security modules or playbooks involved. We indexed the logs, built dashboards, generated reports, and set up alerts. That was the extent of our usage, without any additional security features.

How was the initial setup?

The initial setup was not complex. We had prior experience with Elastic and Elk, so the deployment of Wazuh was quite familiar to us. It wasn't a major challenge.

However, we do need maintenance as we need to upgrade the version periodically. During maintenance, we have to switch off all the endpoints, turn off all the components, and then power off one by one to upgrade them to the latest version. This is done during a maintenance window.

One or two engineers are usually enough to handle the maintenance tasks.

What about the implementation team?

In terms of the deployment plan, if we exclude the endpoints (monitored servers), we have multiple nodes for each component: indexer, manager, and dashboard. We also implemented an NGINX-based load balancer, following the documentation provided by Wazuh on configuring NGINX as a load balancer. This helps in load disturbance and redundancy, so we don't have a single point of failure when any server goes down.

The deployment process took approximately one to two weeks to fully test and deploy the system. We had to spend time on research and development to properly configure everything. The resources mainly involved Linux servers. There were not many additional resources involved beyond that.

Which other solutions did I evaluate?

We evaluated LogRhythm, which is an excellent intelligence-based tool. However, it comes with a high cost for the intelligence features. Wazuh lacks AI or machine learning capabilities, but otherwise, it has all the necessary capabilities for a similar solution.

What other advice do I have?

I would advise you to carefully follow the documentation. It is straightforward and to the point. If any issues arise, the Wazuh Slack community is highly active and responsive. They can provide assistance within 24 hours or even less, helping with any deployment or management challenges.

Wazuh offers numerous features, such as the ability to define custom rules for detecting malicious activities and remembering behaviors. Unlike some paid tools, Wazuh is extensive and extendible and allows integration with open-source tools and scripts. It is flexible, reliable, and open-source, which is its biggest advantage. 

Overall, it is a good solution. I would rate the solution a nine out of ten. Considering that Wazuh is open source and free of cost while providing all the necessary features, I would rate it nine or ten. I lean towards ten because it offers a comprehensive solution without any financial burden. However, compared to industry leaders like LogRhythm and Splunk, which have machine learning modules, Wazuh lacks in that aspect. So, overall, I would rate it nine, but because of its cost-effectiveness, it deserves a ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Haad Fida - PeerSpot reviewer
Software Engineer at 7Vals
Real User
Oct 6, 2023
An affordable and stable solution that can be used for event monitoring
Pros and Cons
  • "The tool is stable."
  • "The tool doesn't detect anomalies or new environments."

What is our primary use case?

We use the solution for event monitoring.

What is most valuable?

The tool is stable.

What needs improvement?

The rules are hard coded. The tool doesn't detect anomalies or new environments. The product lacks AI features. We have to do a lot of manual searching.

For how long have I used the solution?

I have been using the solution for about eight months.

What do I think about the scalability of the solution?

The tool is scalable for our use cases. Five to ten people use the solution in our organization. We need one administrator to monitor and improve our solution.

How are customer service and support?

We did not contact support. Our company’s security personnel set everything and documented it.

Which solution did I use previously and why did I switch?

We use Elastic Stack for logs.

How was the initial setup?

The deployment was straightforward. It took two to three months. We needed two people for deployment.

What about the implementation team?

We did the deployment in-house with the help of our security personnel and someone from the DevOps team.

What's my experience with pricing, setup cost, and licensing?

The product is cheaper compared to other tools. Depending on the logs, the product costs $200 to $400. We currently have five servers.

Which other solutions did I evaluate?

We evaluated Google Cloud.

What other advice do I have?

When Google contacted us, we were looking into an AI solution. Our implementation is rather basic. Overall, I rate the solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Wazuh Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2026
Buyer's Guide
Download our free Wazuh Report and get advice and tips from experienced pros sharing their opinions.