---
title: Wazuh Reviews
meta_title: 'Wazuh Reviews 2026: Details, Pricing, & Features | G2'
meta_description: Filter 69 reviews by the users' company size, role or industry to
  find out how Wazuh works for a business like yours.
aggregate_rating:
  rating_value: 4.5
  review_count: 69
  scale: '5'
date_modified: '2026-07-17'
parent_category:
  name: Endpoint Protection
  url: https://www.g2.com/categories/endpoint-protection
---

# Wazuh Reviews
**Vendor:** Wazuh Inc.  
**Category:** [Endpoint Detection &amp; Response (EDR) Software](https://www.g2.com/categories/endpoint-detection-response-edr)  
**Average Rating:** 4.5/5.0  
**Total Reviews:** 69
## About Wazuh
Wazuh is a free and open source security platform that unifies XDR and SIEM capabilities. It protects workloads across on-premises, virtualized, containerized, and cloud-based environments. Wazuh, with over 30 million downloads per year, has one of the largest open-source security communities in the world. Wazuh helps organizations of all sizes protect their data assets against security threats. Learn more about the project at wazuh.com



## Wazuh Pros & Cons
**What users like:**

- Users appreciate the **ease of use** of Wazuh, finding it user-friendly and ideal for small-scale companies. (3 reviews)
- Users value Wazuh&#39;s **affordability** , enjoying top-tier security features without the burden of high licensing fees. (2 reviews)
- Users value the **high visibility and control** provided by Wazuh for comprehensive security event management. (1 reviews)
- Users find Wazuh&#39;s **easy management** features enhance usability, facilitating efficient operations and cost reduction. (1 reviews)
- Users find the **easy setup** of Wazuh greatly beneficial for rolling out and managing security effectively. (1 reviews)
- Experience Satisfaction (1 reviews)
- Users find the **implementation ease** of Wazuh impressive, facilitating quick deployment and efficient monitoring. (1 reviews)
- Log Management (1 reviews)
- Management Ease (1 reviews)
- Monitoring (1 reviews)

**What users dislike:**

- Users struggle with the **complex interface** , finding it challenging to navigate during setup and configuration. (2 reviews)
- Users find Wazuh **not user-friendly** , struggling with steep learning curves and convoluted setup processes for new users. (2 reviews)
- Users face **complicated implementation** challenges with the on-prem console, creating frustrations during setup and management. (1 reviews)
- Users face a **steep learning curve** with Wazuh, finding initial setup and tuning time-consuming and challenging. (1 reviews)
- Users find the **difficult setup** of Wazuh challenging, particularly due to its steep learning curve and time-consuming configurations. (1 reviews)
- Integration Issues (1 reviews)
- Learning Curve (1 reviews)
- Limited Integration (1 reviews)
- Not Intuitive (1 reviews)
- Rules Management (1 reviews)

## Wazuh Reviews
  ### 1. Centralized Monitoring and security Incidents Simplified

**Rating:** 4.5/5.0 stars

**Reviewed by:** Karsh T. | SOC Engineer, Consulting, Mid-Market (51-1000 emp.)

**Reviewed Date:** May 20, 2026

**What do you like best about Wazuh?**

I like Wazuh for its log integration and dashboards, which I find genuinely helpful. I also appreciate how well Wazuh integrates with other tools. On top of that, the secure configuration assessment is valuable, and I like that it natively supports multiple clouds as well as other SaaS platforms. Overall, it lets me monitor all my logs smoothly in one place, under a single pane of glass.

**What do you dislike about Wazuh?**

Things that could be improved on Wazuh’s side include its indexing. In addition, the documentation on how to manage indices and handle data more effectively is something that could be added to or improved further. Another feature I’d like to see in Wazuh is a built-in case management system. I’d also like better multi-log correlation, meaning I should be able to correlate and coordinate logs from multiple different sources at the same time. Last but not least, the pricing for Wazuh Cloud could be revised to make it more affordable for those who don’t want to rely on an on-prem deployment.

**What problems is Wazuh solving and how is that benefiting you?**

I use Wazuh for centralized monitoring, secure configuration assessments, and monitoring cloud systems and logs so I can proactively respond to incidents. I also use it to hunt threats and monitor my infrastructure, while relying on it as a central logging system as well.

  ### 2. Powerful SIEM Tool with Robust AI Features

**Rating:** 3.5/5.0 stars

**Reviewed by:** Abhishek N. | SOC L1 Engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** June 04, 2026

**What do you like best about Wazuh?**

I love that Wazuh is open source and has active community support, along with support for various technologies like XDR, UEBA, threat hunting, and FIM. My favorite features are the scope and use case of the tool, especially the Anomaly Detector using AI and historical data patterns. The Anomaly Detector dashboard is user-friendly, and its integration with AI and machine learning utilizing the RCF algorithm is impressive.

**What do you dislike about Wazuh?**

Wazuh lacks visual correlation, has heavy storage requirements, and complex SOAR integrations. The initial setup also requires many configurations compared to other SIEM tools, making it only moderately easy.

**What problems is Wazuh solving and how is that benefiting you?**

Wazuh offers great community support and supports technologies like XDR, UEBA, and threat hunting. Its Anomaly Detector using AI and historical data patterns is a valuable feature.

  ### 3. Powerful Open-Source On-Prem Security Monitoring with Easy Integration

**Rating:** 4.5/5.0 stars

**Reviewed by:** Yogesh G. | Linux Administrator, Information Technology and Services, Mid-Market (51-1000 emp.)

**Reviewed Date:** January 27, 2026

**What do you like best about Wazuh?**

It’s an open-source platform that’s easy to install in an on-prem environment. I can easily create rules and decoders for custom logs, and the integrations are straightforward to set up. It also provides excellent tools for log analysis, vulnerability detection, FIM, threat detection, compliance management, and incident management. Deploying the agent across multiple hosts is simple via the command line. Wazuh supports real-time monitoring of system logs and configuration, with automated alerts and VM detection. The documentation is also well maintained.

**What do you dislike about Wazuh?**

It’s very difficult for new users to learn and get started with. It also uses a lot of resources when working with large data. Sometimes, it causes problems when upgrading to a newer version.

**What problems is Wazuh solving and how is that benefiting you?**

We are using Wazuh for file integrity monitoring, and the results for this purpose have been exceptional. You don’t need to spend any money if you want to try it. It also comes with many dashboards where you can view the number of vulnerabilities on the agents, agent syslogs, and other useful insights, and you can create a custom dashboard as well.

  ### 4. Wazuh: FREE - Powerful, Customizable Security Monitoring with Smart Alerts

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Computer Networking | Small-Business (50 or fewer emp.)

**Reviewed Date:** March 12, 2026

**What do you like best about Wazuh?**

Wazuh helps keep all your computers and servers safe by watching for bad behavior, checking for weaknesses, and sending alerts when something suspicious happens. It’s free, open, and can be customized to fit any setup, from small networks to large companies.

**What do you dislike about Wazuh?**

Some common drawbacks of Wazuh are that it can be complex to set up and configure, especially for large environments, and managing rules, alerts, and integrations can require significant time and expertise. Additionally, its UI and reporting features are less polished compared to some commercial alternatives, which can make monitoring at scale more cumbersome.

**What problems is Wazuh solving and how is that benefiting you?**

Wazuh detects security threats, monitors system activity, and checks for vulnerabilities, helping prevent breaches and maintain compliance. This benefits you by giving real-time alerts, centralized visibility, and actionable insights, so you can respond quickly to issues and keep your environment secure without manually checking each system.

  ### 5. Open-Source Security Platform with Strong Visibility and Control

**Rating:** 5.0/5.0 stars

**Reviewed by:** Ayush G. | Customer Success Engineer, Computer & Network Security, Small-Business (50 or fewer emp.)

**Reviewed Date:** January 29, 2026

**What do you like best about Wazuh?**

Wazuh is the level of visibility and control it provides over security events across the entire infrastructure. The real-time threat detection, log analysis, and compliance monitoring are very powerful for an open-source platform. It delivers enterprise-level security capabilities without high licensing costs.

**What do you dislike about Wazuh?**

The main drawback is the steep learning curve, especially for new users during initial setup and tuning. Some configurations and rule customizations can be time-consuming, and the UI could be more intuitive. Better guided setup and clearer documentation for advanced use cases would help a lot.

**What problems is Wazuh solving and how is that benefiting you?**

I use Wazuh for centralized security monitoring and threat detection, solving fragmented security visibility by centralizing logs. It helps us quickly detect threats and compliance issues, improving security posture without multiple tools.

  ### 6. A Very Good, Fully Open-Source SIEM

**Rating:** 4.0/5.0 stars

**Reviewed by:** Gibrain  S. | information security engineer, Small-Business (50 or fewer emp.)

**Reviewed Date:** May 05, 2026

**What do you like best about Wazuh?**

which is a very good SIEM and is completely open source

**What do you dislike about Wazuh?**

that in order for it to work optimally, you need to spend a lot of time fine-tuning the settings

**What problems is Wazuh solving and how is that benefiting you?**

traceability of connections, access, and specific file usage; vulnerability detection; and integration with various technologies

  ### 7. Free, Open-Source, and User-Friendly SIEM for SMB

**Rating:** 4.5/5.0 stars

**Reviewed by:** naty d. | Security Engineer, Small-Business (50 or fewer emp.)

**Reviewed Date:** February 26, 2026

**What do you like best about Wazuh?**

The main reasons that i like about wazuh is being free and opensouce, having simpler learning curve and ease of use, it is user friendly and best choice for small scale companies

**What do you dislike about Wazuh?**

In my openion the down side of wazuh is it is difficult to integrate it with 3rd party solutions, and don't have built in plugins to do so compared to other SIEMs in the ecosystem.

**What problems is Wazuh solving and how is that benefiting you?**

The main problem that i used to tackel wazuh is endpoint security and log coorelation/normalization. i have deployed the agent in all of our company assets and able to analyze logs, better visibility regarding security events and much more.

  ### 8. Wazuh Solution

**Rating:** 5.0/5.0 stars

**Reviewed by:** Parth R. | Cyber Security Intern, Small-Business (50 or fewer emp.)

**Reviewed Date:** May 14, 2026

**What do you like best about Wazuh?**

We can see all the different types by adding a field, which makes it easier to use.

**What do you dislike about Wazuh?**

Many times the dashboard gets disconnected, and the logs come in with a delay. Also, there is no option for a normal user to switch the theme.

**What problems is Wazuh solving and how is that benefiting you?**

It’s easy to configure, and I appreciate that it’s free and open source.

  ### 9. It is an inexpensive tool that has a lot of capabilities.

**Rating:** 4.5/5.0 stars

**Reviewed by:** Matthew C. | Information Security Manager, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 29, 2025

**What do you like best about Wazuh?**

It does not cost me anything. The agents that are installed are preconfigured to look at specific details of my end points. It can ID out of date patches on all major applications. It identifies certain items that have CVE's associated with them. I can custom query anything. It was pretty easy to roll out. My organization does not use PowerShell on typical endpoints, so we have to use kind of a modified .msi to roll out updates.

**What do you dislike about Wazuh?**

It cannot push end point agent updates without a paid subscription.  Setting up the user roles is a little tough - it is very convoluted and hard to follow the process.

**What problems is Wazuh solving and how is that benefiting you?**

It allows me to easily see activity per end point for at least 30 days at a time. It is not a full XDR/MDR platform for me - I use it to gather information daily. I could use it to find files or other end point actions if needed.

  ### 10. Cost-Saving Open Source, Easy to Implement—But Comes with Risk

**Rating:** 3.5/5.0 stars

**Reviewed by:** Bartłomiej P. | System Engineer, Small-Business (50 or fewer emp.)

**Reviewed Date:** January 23, 2026

**What do you like best about Wazuh?**

Reduce costs with open source product. Popularity - a lot informations and big KB. 
Easy to management.

**What do you dislike about Wazuh?**

Opensource is always a risk. Complicated implementation on-prem console.

**What problems is Wazuh solving and how is that benefiting you?**

Practice wizard to implementation on-prem server.


## Wazuh Discussions
  - [What is Wazuh - The Open Source Security Platform used for?](https://www.g2.com/discussions/what-is-wazuh-the-open-source-security-platform-used-for) - 1 comment

- [View Wazuh pricing details and edition comparison](https://www.g2.com/products/wazuh/reviews/wazuh-review-5175445?section=pricing&secure%5Bexpires_at%5D=2026-07-20+02%3A21%3A25+-0500&secure%5Bsession_id%5D=4f3a49f5-f269-4802-a7fc-0d83c3911292&secure%5Btoken%5D=5976d5afce08d613ebc7e86f6e336c021b12d9ea516425e66308239772e350e3&format=llm_user)
## Wazuh Integrations
  - [AWS CloudTrail](https://www.g2.com/products/aws-cloudtrail/reviews)
  - [Discord](https://www.g2.com/products/textaify-discord/reviews)
  - [Grafana Labs](https://www.g2.com/products/grafana-labs/reviews)
  - [Microsoft Defender for Endpoint](https://www.g2.com/products/microsoft-defender-for-endpoint/reviews)
  - [Microsoft Teams](https://www.g2.com/products/microsoft-teams/reviews)
  - [n8n](https://www.g2.com/products/n8n/reviews)
  - [Safetica](https://www.g2.com/products/safetica/reviews)
  - [Shuffle](https://www.g2.com/products/shuffle/reviews)
  - [TheHive](https://www.g2.com/products/thehive/reviews)
  - [VirusTotal](https://www.g2.com/products/virustotal/reviews)
  - [WatchGuard Network Security](https://www.g2.com/products/watchguard-network-security/reviews)

## Wazuh Features
**Services - Endpoint Detection & Response (EDR) **
- Managed Services

**Response**
- Resolution Automation
- Resolution Guidance
- System Isolation
- Threat Intelligence
- Incident Investigation

**System Control**
- Device Control
- Web Control
- Application Control
- Asset Management
- System Isolation

**Records**
- Incident Logs
- Incident Reports

**Vulnerability Prevention**
- Endpoint Intelligence
- Firewall
- Malware Detection

**Management**
- Incident Alerts
- Incident Case Management
- Workflow Management

**Security Management**
- Incident Reports
- Security Validation
- Compliance 

**Generative AI**
- AI Text Generation
- AI Text Summarization

## Top Wazuh Alternatives
  - [CrowdStrike Falcon Endpoint Protection Platform](https://www.g2.com/products/crowdstrike-falcon-endpoint-protection-platform/reviews) - 4.6/5.0 (417 reviews)
  - [SentinelOne Singularity Endpoint](https://www.g2.com/products/sentinelone-singularity-endpoint/reviews) - 4.7/5.0 (195 reviews)
  - [IBM QRadar SIEM](https://www.g2.com/products/ibm-ibm-qradar-siem/reviews) - 4.4/5.0 (282 reviews)

