--- title: Wazuh Reviews meta_title: 'Wazuh Reviews 2026: Details, Pricing, & Features | G2' meta_description: Filter 72 reviews by the users' company size, role or industry to find out how Wazuh works for a business like yours. aggregate_rating: rating_value: 4.5 review_count: 72 scale: '5' date_modified: '2026-09-23' parent_category: name: Endpoint Protection url: https://www.g2.com/categories/endpoint-protection ---

Wazuh Reviews & Product Details

Profile Status

This profile is currently managed by Wazuh but has limited features.

Are you part of the Wazuh team? Upgrade your plan to enhance your branding and engage with visitors to your profile!

Value at a Glance

Averages based on real user reviews.

Time to Implement

2 months

Return on Investment

15 months

User Insights

Average based on 72 real user reviews.

Implementation Time

2 months

Perceived Cost

$$$$$
Abhinav S.
AS
Abhinav S.
Security Operations Center Analyst
Information Technology and Services
Mid-Market (51-1000 emp.)
"Highly customizable SIEM and XDR without the enterprise price tag"
5/5
What do you like best about Wazuh?

I appreciate how Wazuh unifies SIEM and XDR capabilities into a single, open source platform. The endpoint agent provides incredible visibility into host level activities, allowing us to perform deep File Integrity Monitoring (FIM) and Security Configuration Assessments (SCA) seamlessly. I frequently test our custom rules by simulating attacks from a Kali Linux VM running in VirtualBox, and it is impressive how accurately Wazuh's decoders pick up the specific indicators of compromise across our network. Additionally, the built in MITRE ATT&CK mapping makes it incredibly easy to correlate these alerts with known adversary tactics, which drastically speeds up our incident triage workflows. Review collected by and hosted on G2.com.

What do you dislike about Wazuh?

Because it is so heavily reliant on rule based detection, managing and tuning the rules to avoid alert fatigue requires a lot of manual, hands-on engineering time. Out of the box, it lacks the advanced behavioral correlation and automated threat intelligence found in commercial enterprise SIEMs. Furthermore, scalability can become a significant headache; maintaining the performance of the underlying indexer and server clusters requires dedicated infrastructure monitoring. When troubleshooting complex deployment issues, you often have to dig through community documentation rather than relying on rapid vendor support. Review collected by and hosted on G2.com.

Karsh T.
KT
Karsh T.
SOC Engineer
Consulting
Mid-Market (51-1000 emp.)
"Centralized Monitoring and security Incidents Simplified"
4.5/5
What do you like best about Wazuh?

I like Wazuh for its log integration and dashboards, which I find genuinely helpful. I also appreciate how well Wazuh integrates with other tools. On top of that, the secure configuration assessment is valuable, and I like that it natively supports multiple clouds as well as other SaaS platforms. Overall, it lets me monitor all my logs smoothly in one place, under a single pane of glass. Review collected by and hosted on G2.com.

What do you dislike about Wazuh?

Things that could be improved on Wazuh’s side include its indexing. In addition, the documentation on how to manage indices and handle data more effectively is something that could be added to or improved further. Another feature I’d like to see in Wazuh is a built-in case management system. I’d also like better multi-log correlation, meaning I should be able to correlate and coordinate logs from multiple different sources at the same time. Last but not least, the pricing for Wazuh Cloud could be revised to make it more affordable for those who don’t want to rely on an on-prem deployment. Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
UI
Verified User in Information Technology and Services
Mid-Market (51-1000 emp.)
"All-in-One Open-Source SIEM/XDR with Powerful Customization and Integrations"
4.5/5
What do you like best about Wazuh?

What I like most about Wazuh is how it brings SIEM, XDR, file integrity monitoring, vulnerability detection, log management, and compliance monitoring together in one open-source platform. It also integrates smoothly with tools like Elastic, supports a broad range of operating systems, and offers highly customizable rules and dashboards—all without expensive licensing costs. Review collected by and hosted on G2.com.

What do you dislike about Wazuh?

Wazuh can be complex to deploy and maintain, especially in larger environments. Initial configuration, rule tuning, and reducing false positives require time, and major upgrades or integrations can sometimes involve additional manual effort. Review collected by and hosted on G2.com.

Abhishek N.
AN
Abhishek N.
SOC L1 Engineer
Mid-Market (51-1000 emp.)
"Powerful SIEM Tool with Robust AI Features"
3.5/5
What do you like best about Wazuh?

I love that Wazuh is open source and has active community support, along with support for various technologies like XDR, UEBA, threat hunting, and FIM. My favorite features are the scope and use case of the tool, especially the Anomaly Detector using AI and historical data patterns. The Anomaly Detector dashboard is user-friendly, and its integration with AI and machine learning utilizing the RCF algorithm is impressive. Review collected by and hosted on G2.com.

What do you dislike about Wazuh?

Wazuh lacks visual correlation, has heavy storage requirements, and complex SOAR integrations. The initial setup also requires many configurations compared to other SIEM tools, making it only moderately easy. Review collected by and hosted on G2.com.

Gulsan P.
GP
Gulsan P.
Codeinyourself
Small-Business (50 or fewer emp.)
"Great Platform for Quick Threat Detection"
5/5
What do you like best about Wazuh?

The platform streamlined our security monitoring process by facilitating real-time log analysis and automated vulnerability detection which saves me hours each week instead of manually checking logs and I like the immediate threat alerts that also give us clear visibility into our system health. Review collected by and hosted on G2.com.

What do you dislike about Wazuh?

Nothing to dislike about it thus far it has been a great security monitoring platform and even the broader team also seems to feel the same. Review collected by and hosted on G2.com.

YG
Yogesh G.
Sr. Devops Engineer
Information Technology and Services
Mid-Market (51-1000 emp.)
Business partner of the seller or seller's competitor, not included in G2 scores.
"Powerful Open-Source On-Prem Security Monitoring with Easy Integration"
4.5/5
What do you like best about Wazuh?

It’s an open-source platform that’s easy to install in an on-prem environment. I can easily create rules and decoders for custom logs, and the integrations are straightforward to set up. It also provides excellent tools for log analysis, vulnerability detection, FIM, threat detection, compliance management, and incident management. Deploying the agent across multiple hosts is simple via the command line. Wazuh supports real-time monitoring of system logs and configuration, with automated alerts and VM detection. The documentation is also well maintained. Review collected by and hosted on G2.com.

What do you dislike about Wazuh?

It’s very difficult for new users to learn and get started with. It also uses a lot of resources when working with large data. Sometimes, it causes problems when upgrading to a newer version. Review collected by and hosted on G2.com.

Verified User in Computer Networking
AC
Verified User in Computer Networking
Small-Business (50 or fewer emp.)
"Wazuh: FREE - Powerful, Customizable Security Monitoring with Smart Alerts"
5/5
What do you like best about Wazuh?

Wazuh helps keep all your computers and servers safe by watching for bad behavior, checking for weaknesses, and sending alerts when something suspicious happens. It’s free, open, and can be customized to fit any setup, from small networks to large companies. Review collected by and hosted on G2.com.

What do you dislike about Wazuh?

Some common drawbacks of Wazuh are that it can be complex to set up and configure, especially for large environments, and managing rules, alerts, and integrations can require significant time and expertise. Additionally, its UI and reporting features are less polished compared to some commercial alternatives, which can make monitoring at scale more cumbersome. Review collected by and hosted on G2.com.

Ayush G.
AG
Ayush G.
Customer Success Engineer
Computer & Network Security
Small-Business (50 or fewer emp.)
"Open-Source Security Platform with Strong Visibility and Control"
5/5
What do you like best about Wazuh?

Wazuh is the level of visibility and control it provides over security events across the entire infrastructure. The real-time threat detection, log analysis, and compliance monitoring are very powerful for an open-source platform. It delivers enterprise-level security capabilities without high licensing costs. Review collected by and hosted on G2.com.

What do you dislike about Wazuh?

The main drawback is the steep learning curve, especially for new users during initial setup and tuning. Some configurations and rule customizations can be time-consuming, and the UI could be more intuitive. Better guided setup and clearer documentation for advanced use cases would help a lot. Review collected by and hosted on G2.com.

GS
Gibrain S.
information security engineer
Small-Business (50 or fewer emp.)
"A Very Good, Fully Open-Source SIEM"
4/5
What do you like best about Wazuh?

which is a very good SIEM and is completely open source Review collected by and hosted on G2.com.

What do you dislike about Wazuh?

that in order for it to work optimally, you need to spend a lot of time fine-tuning the settings Review collected by and hosted on G2.com.

naty d.
ND
naty d.
Security Engineer
Small-Business (50 or fewer emp.)
"Free, Open-Source, and User-Friendly SIEM for SMB"
4.5/5
What do you like best about Wazuh?

The main reasons that i like about wazuh is being free and opensouce, having simpler learning curve and ease of use, it is user friendly and best choice for small scale companies Review collected by and hosted on G2.com.

What do you dislike about Wazuh?

In my openion the down side of wazuh is it is difficult to integrate it with 3rd party solutions, and don't have built in plugins to do so compared to other SIEMs in the ecosystem. Review collected by and hosted on G2.com.

Questions about Wazuh? Ask real users or explore answers from the community

Get practical answers, real workflows, and honest pros and cons from the G2 community or share your insights.

GU
Guest User
•
Last activity over 2 years ago

What is Wazuh - The Open Source Security Platform used for?

0 Upvotes
1
Join the conversation

Pricing Insights

Averages based on real user reviews.

Time to Implement

2 months

Return on Investment

15 months

Perceived Cost

$$$$$
Wazuh Comparisons
Wazuh Features
Resolution Automation
Resolution Guidance
System Isolation
Incident Logs
Incident Reports
Incident Alerts
Incident Case Management
Workflow Management
AI Text Generation
AI Text Summarization