Listing Thumbnail

    Wazuh All-In-One Deployment

     Info
    Deployed on AWS
    Wazuh All-In-One. Includes Wazuh server, Filebeat, Wazuh dashboard and Wazuh Indexer

    Overview

    Play video

    Wazuh is a free, open source and enterprise-ready security monitoring solution for threat detection, integrity monitoring, incident response, and regulatory compliance.

    The solution includes the Wazuh server, which is in charge of analyzing the data received from the agents, processing events through decoders and rules, and using threat intelligence to look for well-known IOCs (Indicators Of Compromise). A single Wazuh server can analyze data from hundreds or thousands of agents. Alerts generated by Wazuh are sent to Wazuh indexer, where they are indexed and stored. The unique integration between Wazuh and Wazuh dashboard provides a powerful user interface for data visualization and analysis. The server is also used to manage the agents, configuring and upgrading them remotely when necessary. Additionally, the server is capable of sending orders to the agents, for example, to trigger a response when a threat is detected.

    Wazuh provides a security solution capable of monitoring your infrastructure, detecting threats, intrusion attempts, system anomalies, poorly configured applications, and unauthorized user actions. It also provides a framework for incident response and compliance, all in one platform.

    Highlights

    • Open Source Security Platform
    • Host Based Intrusion Detection Solution
    • Endpoint Detection and Response

    Details

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    AmazonLinux Amazon Linux 2023

    Deployed on AWS

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Wazuh All-In-One Deployment

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (239)

     Info
    • ...
    Dimension
    Cost/hour
    c5a.xlarge
    Recommended
    $0.00
    m3.xlarge
    $0.00
    m5dn.2xlarge
    $0.00
    hs1.8xlarge
    $0.00
    u-24tb1.metal
    $0.00
    c5ad.xlarge
    $0.00
    cc2.8xlarge
    $0.00
    t2.2xlarge
    $0.00
    i2.xlarge
    $0.00
    m5d.12xlarge
    $0.00

    Vendor refund policy

    We do not currently support refunds.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Additional details

    Usage instructions

    See the instructions below

    Hardware requirements: https://documentation.wazuh.com/current/quickstart.html#hardware 

    The instance needs to have the following protocols and ports configured for its correct operation. These requirements are provided in a default Security Group: https://documentation.wazuh.com/current/getting-started/architecture.html#required-ports 

    To access the instance by ssh, you will need to use the user: wazuh-user

    When the instance is launched, the user passwords are automatically changed to the instance ID with the first letter capitalized. For example: I-07f25f6afe4789342. This ensures that only the creator has access to the interface. This process can take an average of five minutes, depending on the type of instance. During this time, both SSH access and access to the Wazuh dashboard are disabled.

    It is highly recommended to change the default passwords of Wazuh indexer users. To perform this action, see our Password management section: https://documentation.wazuh.com/current/user-manual/user-administration/password-management.html#changing-the-passwords-for-all-users 

    To access the Wazuh dashboard UI, navigate to the address https://<instance_ip> and log in with:

    • Username: admin
    • Password: <your_instance_id>

    The password is the instance ID with the first letter capitalized. For example: I-07f25f6afe4789342

    Resources

    Vendor resources

    Support

    Vendor support

    Wazuh has one of the largest open source security communities in the world. You can become part of it to learn from other users, participate in discussions, talk to our development team, and contribute to the project.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    3
    3 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    33%
    0%
    33%
    0%
    33%
    3 AWS reviews
    |
    28 external reviews
    Star ratings include only reviews from verified AWS customers. External reviews can also include a star rating, but star ratings from external reviews are not averaged in with the AWS customer star ratings.
    Rajin Sandira

    Has faced limitations in AI capabilities and pricing flexibility

    Reviewed on Sep 15, 2025
    Review provided by PeerSpot

    What is our primary use case?

    At the moment, I'm working in software integration, so we are working with FortiGate . To research and get an idea, I did some investigation into Wazuh .

    They have already used Fortinet products.

    They use pretty much almost all Fortinet products including FortiGate , FortiSIEM , FortiXDR .

    At the moment, they only use FortiGate and FortiSIEM .

    I have worked with Wazuh  before with limited experience.

    What is most valuable?

    Pricing-wise, Wazuh stands out, along with deployment flexibility and its documentation which is extremely good in comparison to Forti. The community support is also incredible.

    They have helped quite a bit because previously, we had a separate tool and management dashboard to do our compliance. With Wazuh, we receive that information without having to do anything extra. We just set up the SIEM  and all of that information was automatically populated.

    The dashboards are very easy to understand and very quick with no lag or delay. I have experienced delays on Forti's dashboards, but not with Wazuh.

    Wazuh is quite good. In comparison to Forti, they are quite similar. They are very good at detection.

    What needs improvement?

    The lack of AI features is an issue at the moment in the industry.

    Forti provides user behavior capabilities, which I would want to see in Wazuh.

    In FortiSIEM, they provide user behavior understanding AI capability. This is not available with Wazuh, so I would want that feature.

    Both solutions have incredible performance and stability. The only issue is Forti's dashboards tend to lag, so that needs improvement.

    Machine learning is needed along with understanding user behavior and behavioral patterns. That capability is something that other vendors provide that I would want to see.

    For how long have I used the solution?

    I started using it less than a year ago.

    What do I think about the stability of the solution?

    Both solutions have incredible performance and are incredibly stable. The only issue is Forti's dashboards tend to lag, so that needs improvement.

    What's my experience with pricing, setup cost, and licensing?

    Apart from pricing, there are no major considerations.

    If you want to consider pricing, there is no reason to switch from Forti to Wazuh.

    Wazuh differs from Forti as Forti comes in bundles that you have to pay for. With Wazuh, there is no starting payment for the SIEM  itself, but you have to pay for support.

    I would definitely recommend Wazuh, especially considering Fortinet's licensing model which is confusing and overpriced in my opinion.

    What other advice do I have?

    Right now, we haven't decided. We just want to explore and see what is available.

    I prefer Wazuh a bit more, though both are similar.

    I would rate Wazuh eight to nine out of ten.

    I would rate Forti seven to eight out of ten.

    Wazuh is actually better than Forti.

    I have utilized the solution.

    My overall rating for Wazuh is 9 out of 10.

    reviewer2711757

    Open source flexibility supports cost reduction and efficiency

    Reviewed on Jun 03, 2025
    Review provided by PeerSpot

    What is our primary use case?

    Wazuh  is a SIEM  platform with various applications in today's environment. Compliance checks have helped with regulatory requirements. I pulled in PCI DSS to check for file integrity monitoring. I completed one project where I removed malware.

    What is most valuable?

    The valuable features of Wazuh  include being open source and having the capacity to be used for anything desired. It allows for creating new automations, whereas other Software as a Service platforms have their own business models. With this open source tool, organizations can establish their own customized setup.

    What needs improvement?

    That would require me to discuss with the Wazuh team regarding areas that could be improved, as I have numerous ideas. From a developer's perspective, this is a Linux system with an active community and dense documentation. There are many people sharing different projects of similar tasks, which is beneficial.

    In the proof of concept documentation, it's a mixture of Windows, whereas they also catered to Ubuntu . I'm referring to apt and yum languages for downloading the server indexer. I downloaded in apt, but their first proof of concept is in yum, so I must change languages. This is something I do not prefer because I prefer a more uniform language. When running in production, I'm on a time crunch as time is money.

    Wazuh could improve by creating videos on YouTube covering installation, use cases, and integration of third-party APIs for different scenarios that other SAAS services provide. While Wazuh provides these features, one must read their documentation thoroughly to customize it. This is a great feature, but initially, I don't have time to scan multiple items. They could make it more uniform and developer-friendly. As a software engineer, it takes considerable time, but as a businessman, I need to complete tasks quickly and need that flexibility.

    What was my experience with deployment of the solution?

    It is relatively simple to set up Wazuh. I would give it a 7 out of 10. I have set up more complicated systems, so 7 is a good rating.

    What do I think about the stability of the solution?

    Wazuh requires substantial maintenance. The indexer frequently times out, requiring system restarts. When it comes to errors, debugging takes considerable time.

    How are customer service and support?

    I spoke with Wazuh support today regarding a quote. I would rate Wazuh support an 8 out of 10. They responded quickly, which was crucial as I was on a time constraint.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    It took one day to deploy Wazuh.

    What was our ROI?

    Due to confidentiality, I cannot share specific quantifiable benefits that deploying Wazuh has brought to my company. However, it resulted in cost reduction by avoiding lump sum payments and providing the benefit of having our own system.

    What's my experience with pricing, setup cost, and licensing?

    Wazuh is free to use, but there are licensing fees for third parties. Their consultancy fee and support fees are relatively high. On a scale of 1 to 10, I would rate their consultancy and support fees a 5.

    Which other solutions did I evaluate?

    Wazuh can incorporate third parties and utilizes artificial intelligence for various features. Wazuh integrates effectively, deserving a solid 9 rating. That aspect is straightforward.

    What other advice do I have?

    I would be willing to provide a review for products I have experience with. I recommend Wazuh to everyone and believe more platforms, not just SIEM  and XDR  capability platforms, should be open source, allowing people to leverage these tools for the greater good. I support it completely. Overall, I rate Wazuh 8 out of 10.

    Ebenezer Okoh

    Innovative platform enables proactive threat hunting and endpoint monitoring

    Reviewed on Jun 03, 2025
    Review provided by PeerSpot

    What is our primary use case?

    I use Wazuh  for daily security operations mainly on EDR endpoints by installing it on the agents that we are monitoring to collect security data. It helps us monitor endpoints and know what is going on at each endpoint, and we are able to tap the data and use it in other platforms such as SOAR .

    I find the threat hunting features of Wazuh  most valuable, as we are more interested in the threat hunting side and want to move ahead into threat hunting before any threat becomes something that cannot be dealt with. Wazuh has a threat hunting functionality that we use extensively.

    The intrusion detection capabilities work effectively in my environment, as we also have firewalls, and we rely more on the firewall side for intrusion detection.

    What is most valuable?

    The threat hunting features of Wazuh are particularly valuable for our operations. We focus heavily on threat hunting capabilities to address potential threats before they become unmanageable.

    The intrusion detection capabilities integrate seamlessly with our existing firewall infrastructure. The system allows us to monitor endpoints effectively and collect security data that can be utilized across other platforms such as SOAR .

    What needs improvement?

    I think Wazuh should improve by introducing AI functionalities, as it would be beneficial to see AI incorporated in the threat hunting and detection functionalities. I hope this will be part of the new versions.

    Regarding challenges with Wazuh, I cannot pinpoint specific difficulties. When I face a challenge, I prefer not to spend too much time on it and may move to another solution that will give us the results. Sometimes what seems a challenge is just an implementation issue, and while the documentation is comprehensive, it can become overwhelming when quick information is needed for implementation.

    For how long have I used the solution?

    I have been using Wazuh for about a year now.

    What was my experience with deployment of the solution?

    Wazuh is easy to set up, as it's clearly defined in their documentation, with various options such as bare metal or Docker  implementations. The level of documentation is superior compared to other open source products.

    Sometimes issues arise with some of these tools, but because they are open source, there are limitations to what can be expected.

    What do I think about the stability of the solution?

    I would rate the stability of Wazuh a nine out of ten.

    What do I think about the scalability of the solution?

    Currently, I don't see any limitations in terms of scalability as Wazuh can still connect many endpoints. I haven't encountered issues with the engine struggling, and it's simply a matter of having enough memory to handle open search memory issues. I think they've done exceptionally in terms of scalability.

    I rate the scalability of Wazuh an eight out of ten, as I haven't reached the point of struggling with it.

    How was the initial setup?

    I would rate the setup of Wazuh a nine out of ten.

    What was our ROI?

    I have seen value in security cost savings with Wazuh, as using proprietary EDR versions could save us substantial money, but I haven't made any comparisons since we started using Wazuh immediately.

    What's my experience with pricing, setup cost, and licensing?

    Wazuh is completely free of charge.

    What other advice do I have?

    I have not seen Wazuh moving in the direction of AI-driven threat detection projects myself, but since the market is moving that way, I wouldn't be surprised if they implemented it soon.

    My plans to increase the usage of Wazuh or switch to another tool depend on what my boss decides.

    We don't refer to any community support specifically, as we rely on other platforms such as GitHub  or Discord, depending on the application.

    I recommend that as more companies come on board with Wazuh, it will motivate those who contribute to it, but I am also cautious that as it gains attention, a large company might buy it and change its course of business.

    Overall, I rate Wazuh a nine out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Sean-Cox

    Open source customization and CVE reporting enhance threat detection

    Reviewed on Feb 28, 2025
    Review provided by PeerSpot

    What is our primary use case?

    We use Wazuh  as a SIEM  solution because it is open source, highly customizable, and continually expanding. Our clients can request various solutions for their issues, which Wazuh  is able to address.

    What is most valuable?

    One of the most valuable features of Wazuh is its capability as a CVE helper. It assists in pulling reports about active CVEs in the system. Wazuh is a SIEM  tool that is highly customizable and versatile. The fact that it is open source means it is always being expanded, which is beneficial for customizing solutions for individual client requests.

    What needs improvement?

    There is room for improvement by integrating more AI into Wazuh. It requires constant nurturing, as I have to provide it with code and specific requirements. This maintenance can be quite labor-intensive and time-consuming.

    For how long have I used the solution?

    I have been using Wazuh for nearly three years.

    What do I think about the stability of the solution?

    The stability of Wazuh is largely dependent on maintenance. If it is well-maintained, it is stable, rating around eight to nine. Without proper maintenance, stability could drop to around five to six.

    What do I think about the scalability of the solution?

    Wazuh is scalable and suitable for small to medium-sized businesses or enterprises. It can accommodate thousands of endpoints on one instance, and multiple instances can run for different clients.

    How are customer service and support?

    There is no dedicated technical support for Wazuh as it is open source. I rely on available documentation and self-support.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    The initial setup of Wazuh is not more complex than any other SIEM solutions available.

    What other advice do I have?

    I would recommend Wazuh to others. It is a good system that provides a comprehensive view of network activities when correctly set up with syslog and proper log injection. Overall, I would rate Wazuh an eight out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Sandip_Patel

    Evaluating robust file monitoring with insights for community support improvements

    Reviewed on Nov 22, 2024
    Review provided by PeerSpot

    What is our primary use case?

    I am currently evaluating and using Wazuh  for file monitoring and compliance reporting. We are in the process of conducting a POC to understand how the rules work. I lead this effort to explore and evaluate Wazuh  as part of my learning and work experience.

    What is most valuable?

    Wazuh's most valuable features include file monitoring and compliance reporting, which do not require excessive costs. These aspects are vital as they provide alerts for changes and facilitate the monitoring of compliance. The platform is also relatively easy to set up and operate. Reports are straightforward to extract and prove useful for compliance requirements.

    What needs improvement?

    I am investigating more about the community support for Wazuh. I can't provide a definitive answer yet. An issue I noticed is with tag values in certain rules not functioning properly. It's unclear if this is a design flaw or intentional. These are areas I'm still exploring.

    For how long have I used the solution?

    I have been using Wazuh for about seven months.

    What do I think about the scalability of the solution?

    Wazuh offers scaling options and is scalable from a mid to advanced level. However, I am still evaluating if it meets enterprise-scale requirements.

    How are customer service and support?

    The documentation is good and provides clear instructions, though it's targeted at those with technical backgrounds.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    Before Wazuh, we used market products for our needs. We are exploring other options due to Wazuh being open source.

    How was the initial setup?

    The initial setup of Wazuh was not complex once the requirements were understood. In a POC environment, setting up took about a day and a half.

    What about the implementation team?

    I am spearheading this POC effort. Once completed, more people will likely be involved.

    What was our ROI?

    There is high potential for ROI, especially for small to medium businesses comparing Wazuh to market solutions. Wazuh offers more cost-effective options without compromising on security.

    What's my experience with pricing, setup cost, and licensing?

    Since Wazuh is open source, the pricing for support could be applicable to medium-sized companies without much issue. However, I haven't fully explored what comes with this pricing.

    Which other solutions did I evaluate?

    We have looked into the Elastic Stac k and haven't explored integrating it with Wazuh since Elastic Stack  is no longer open source.

    What other advice do I have?

    I would recommend Wazuh. It's a valuable tool for security operations. On a scale of one to ten, I currently rate Wazuh as a six. I may rate it higher after more experience.

    Which deployment model are you using for this solution?

    On-premises
    View all reviews