Recommendations to others considering Wazuh:
- Has some learning curve if you want to set it up yourself. But not impossible. There is good documentation and a helpful community that will unblock you any chance they get.
- It took our team (two engineers and one security engineer) to host the on-premise system using Elasticsearch and deploy a distributed HIDS system in three months, although those were some long hours. The initial setup took over a month, and then we spent most of our time ensuring the Wazuh agents didn't eat up the majority of our machine resources.
- If you wish to avoid the setup time and effort, go for their managed solution. However, that isn't cheap, and I haven't used it, so I can't comment on its benefits. Review collected by and hosted on G2.com.
What problems is Wazuh solving and how is that benefiting you?
- Wazuh helped us monitor all the host machines in our production environment.
- Logging suspicious activity, instrumenting machine health (needs some work), checking the packages installed on hosts, and detecting vulnerabilities.
- It has been beneficial in identifying shellshock attacks and mitigating them for hosts with the older version of operating systems. Review collected by and hosted on G2.com.