Abhinav S.
AS
Security Operations Center Analyst
Information Technology and Services
Mid-Market (51-1000 emp.)
"Highly customizable SIEM and XDR without the enterprise price tag"
5/5
What do you like best about Wazuh?

I appreciate how Wazuh unifies SIEM and XDR capabilities into a single, open source platform. The endpoint agent provides incredible visibility into host level activities, allowing us to perform deep File Integrity Monitoring (FIM) and Security Configuration Assessments (SCA) seamlessly. I frequently test our custom rules by simulating attacks from a Kali Linux VM running in VirtualBox, and it is impressive how accurately Wazuh's decoders pick up the specific indicators of compromise across our network. Additionally, the built in MITRE ATT&CK mapping makes it incredibly easy to correlate these alerts with known adversary tactics, which drastically speeds up our incident triage workflows. Review collected by and hosted on G2.com.

What do you dislike about Wazuh?

Because it is so heavily reliant on rule based detection, managing and tuning the rules to avoid alert fatigue requires a lot of manual, hands-on engineering time. Out of the box, it lacks the advanced behavioral correlation and automated threat intelligence found in commercial enterprise SIEMs. Furthermore, scalability can become a significant headache; maintaining the performance of the underlying indexer and server clusters requires dedicated infrastructure monitoring. When troubleshooting complex deployment issues, you often have to dig through community documentation rather than relying on rapid vendor support. Review collected by and hosted on G2.com.

See what 70 reviewers think of Wazuh

4.5 out of 5 · Verified reviews from real users

Read all reviews