The log monitoring and analysis tools are great in addition to SIEM file activity monitoring.
CBO at a security firm with 11-50 employees
Offers good log monitoring and analysis tools
Pros and Cons
- "The log monitoring and analysis tools are great in addition to SIEM file activity monitoring."
- "I think that the next release should be more suitable for large enterprises, because currently they are not because large companies do not rely on open source solutions."
What is most valuable?
What needs improvement?
I think that the next release should be more suitable for large enterprises, because currently they are not because large companies do not rely on open source solutions.
For how long have I used the solution?
I have been working with this solution for about four months.
What do I think about the stability of the solution?
For mid-level customer, stability is okay.
Buyer's Guide
Wazuh
January 2026
Learn what your peers think about Wazuh. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,176 professionals have used our research since 2012.
What do I think about the scalability of the solution?
This is a scalable solution.
How are customer service and support?
Support needs to be purchased on an annual basis but the support required is excellent.
How was the initial setup?
The initial setup is rather complex and takes a few days to perform.
What's my experience with pricing, setup cost, and licensing?
This is a very price sensitive product.
What other advice do I have?
No hardware is required for this solution but be prepared to purchase implementation support. I would rate this solution a six or seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Security engineer at a tech services company with 51-200 employees
A flexible solution that can be used for instant response, security operations, and compliance
Pros and Cons
- "Wazuh's most beneficial features for our security needs are flexibility, built-in rules, integration capabilities, and documentation."
- "Wazuh should come up with more in-built rules and integrations for the cloud."
What is our primary use case?
We use Wazuh for internal testing, instant response, security operations, and compliance.
What is most valuable?
Wazuh's most beneficial features for our security needs are flexibility, built-in rules, integration capabilities, and documentation.
What needs improvement?
At the moment, we haven't tried the cloud version yet. My customers are mostly into the cloud. Wazuh should come up with more in-built rules and integrations for the cloud.
For how long have I used the solution?
I have been using Wazuh for one year.
What do I think about the stability of the solution?
I rate Wazuh seven and a half out of ten for stability.
What do I think about the scalability of the solution?
Around 10 users are using the solution in our organization.
How was the initial setup?
For a technical and experienced person, the solution's initial setup is easy. The setup would be a little hard for a non-technical person with less experience.
What about the implementation team?
The initial implementation and configuration may take a maximum of one week.
What's my experience with pricing, setup cost, and licensing?
Wazuh is not an expensive solution.
What other advice do I have?
If correctly configured, Wazuh can support threat detection and response for SMBs. Wazuh is a good solution if you can implement, integrate, and fine-tune it in the right way.
Overall, I rate Wazuh an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Wazuh Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2026
Product Categories
Security Information and Event Management (SIEM) Log Management Extended Detection and Response (XDR)Popular Comparisons
CrowdStrike Falcon
Datadog
Dynatrace
Splunk Enterprise Security
Darktrace
Microsoft Sentinel
SentinelOne Singularity Complete
IBM Security QRadar
Cortex XDR by Palo Alto Networks
Microsoft Defender XDR
Cribl
Elastic Security
Grafana Loki
Trellix Endpoint Security Platform
Elastic Observability
Buyer's Guide
Download our free Wazuh Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the difference between SIEM and Next-Gen SIEM solutions?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- RSA-EMC vs. other SIEM products?
- What Questions Should I Ask Before Buying SIEM?














