Wazuh All-In-One Deployment logo

    Wazuh All-In-One Deployment

    Sold by
    Wazuh All-In-One. Includes Wazuh server, Filebeat, Wazuh dashboard and Wazuh Indexer

    Ratings and reviews

    4.2
    102 ratings
    53%
    40%
    6%
    0%
    1%
    5 AWS reviews
    |
    97 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (102)
    Gulsan P.

    Great Platform for Quick Threat Detection

    Reviewed on Aug 13, 2026
    Review provided by G2
    What do you like best about the product?
    The platform streamlined our security monitoring process by facilitating real-time log analysis and automated vulnerability detection which saves me hours each week instead of manually checking logs and I like the immediate threat alerts that also give us clear visibility into our system health.
    What do you dislike about the product?
    Nothing to dislike about it thus far it has been a great security monitoring platform and even the broader team also seems to feel the same.
    What problems is the product solving and how is that benefiting you?
    It effectively connects all our system logs to a centralized dashboard which helps track security events easily and an unexpected benefit is how it catches system misconfigurations we didn't even know we had furthermore the automated alerts help improve our overall security without constant manual oversight.
    Information Technology and Services

    All-in-One Open-Source SIEM/XDR with Powerful Customization and Integrations

    Reviewed on Jul 28, 2026
    Review provided by G2
    What do you like best about the product?
    What I like most about Wazuh is how it brings SIEM, XDR, file integrity monitoring, vulnerability detection, log management, and compliance monitoring together in one open-source platform. It also integrates smoothly with tools like Elastic, supports a broad range of operating systems, and offers highly customizable rules and dashboards—all without expensive licensing costs.
    What do you dislike about the product?
    Wazuh can be complex to deploy and maintain, especially in larger environments. Initial configuration, rule tuning, and reducing false positives require time, and major upgrades or integrations can sometimes involve additional manual effort.
    What problems is the product solving and how is that benefiting you?
    Wazuh helps centralise security monitoring across multiple systems by collecting logs, detecting suspicious activity, and highlighting configuration or compliance issues in one place. It has improved visibility into our environment, reduced the time needed to investigate alerts, and made it easier to identify potential security issues before they become larger problems.
    Sudarson Prabhu

    File integrity monitoring has strengthened our data protection and supports compliance needs

    Reviewed on Jul 03, 2026
    Review provided by PeerSpot

    What is our primary use case?

    Our organization is focusing on the integrity part for implementing Wazuh. We were checking solutions for File Integrity Monitoring systems that are available online. Wazuh caught my attention as a very cool solution for verifying file integrity. We decided to try Wazuh for focusing on the integrity part. While implementing it, our objective was achieved. We were able to monitor entire file integrity. Because our organization's business requires core concepts of integrity to be maintained, this was very important for us. Wazuh did this very well. We were not able to make it available to all endpoints. Instead, we tried it with servers. We changed our business requirements by storing all files that are processing into the server as a shared server and then we put File Integrity Monitoring and Wazuh in a single server. This worked out very well.

    What is most valuable?

    The dashboards in Wazuh are very cool and they provided whatever data is required.

    I would give ten out of ten for the technical suggestion that I received from the documentation of Wazuh. The documentation provides everything that we are expecting. I have not tried any support from staff for Wazuh, but the documentation was very clear and I can give it ten out of ten.

    What needs improvement?

    I expected one thing from the dashboard in Wazuh. In ManageEngine, when you use ManageEngine, you can assign a unique ID to all employees. Then with the unique ID, if you search any unique ID in the dashboard itself, you can get the unique ID everywhere, including where the laptop has been logged in, when the logout happened, and what actions have been done for that unique ID. I expected the same in Wazuh, but whenever we want to check any monitoring activities for a specific person, we need to search for the endpoint and then get the endpoint details from our Active Directory or wherever we have the endpoint name stored in our resources, and then search for the endpoint to see the history for that specific endpoint only. This made a simple thing a bit complex. If we had a correlation of logs where I could just search one unique ID and then the unique ID pulls every system in a time-wise manner, that would be a great improvement I would suggest.

    For how long have I used the solution?

    I have been using Wazuh for around seven to eight months. In my previous organization, I was about to install and work with Wazuh. Since it is open source, I was fully configuring it for the organization.

    What do I think about the scalability of the solution?

    When we use a very good configuration laptop, it functions very smoothly. However, when we use low-end laptops for low-level employees, then the laptops become slow. This is because of the backend work the agent is collecting and processing, causing the laptop to slow down and the bandwidth to decrease.

    Which solution did I use previously and why did I switch?

    We had FortiNet and then we had McAfee.

    What other advice do I have?

    I have not worked very well with Wazuh's threat detection capabilities because we already had some solution in place. Our focus was to implement Wazuh for integrity only and File Integrity Monitoring only. I have worked earlier with Wazuh and ManageEngine. When I was working with Wazuh, there was no artificial intelligence introduced. My overall review rating for Wazuh is eight out of ten.

    Abhishek N.

    Powerful SIEM Tool with Robust AI Features

    Reviewed on Jun 04, 2026
    Review provided by G2
    What do you like best about the product?
    I love that Wazuh is open source and has active community support, along with support for various technologies like XDR, UEBA, threat hunting, and FIM. My favorite features are the scope and use case of the tool, especially the Anomaly Detector using AI and historical data patterns. The Anomaly Detector dashboard is user-friendly, and its integration with AI and machine learning utilizing the RCF algorithm is impressive.
    What do you dislike about the product?
    Wazuh lacks visual correlation, has heavy storage requirements, and complex SOAR integrations. The initial setup also requires many configurations compared to other SIEM tools, making it only moderately easy.
    What problems is the product solving and how is that benefiting you?
    Wazuh offers great community support and supports technologies like XDR, UEBA, and threat hunting. Its Anomaly Detector using AI and historical data patterns is a valuable feature.
    Karsh T.

    Centralized Monitoring and security Incidents Simplified

    Reviewed on May 20, 2026
    Review provided by G2
    What do you like best about the product?
    I like Wazuh for its log integration and dashboards, which I find genuinely helpful. I also appreciate how well Wazuh integrates with other tools. On top of that, the secure configuration assessment is valuable, and I like that it natively supports multiple clouds as well as other SaaS platforms. Overall, it lets me monitor all my logs smoothly in one place, under a single pane of glass.
    What do you dislike about the product?
    Things that could be improved on Wazuh’s side include its indexing. In addition, the documentation on how to manage indices and handle data more effectively is something that could be added to or improved further. Another feature I’d like to see in Wazuh is a built-in case management system. I’d also like better multi-log correlation, meaning I should be able to correlate and coordinate logs from multiple different sources at the same time. Last but not least, the pricing for Wazuh Cloud could be revised to make it more affordable for those who don’t want to rely on an on-prem deployment.
    What problems is the product solving and how is that benefiting you?
    I use Wazuh for centralized monitoring, secure configuration assessments, and monitoring cloud systems and logs so I can proactively respond to incidents. I also use it to hunt threats and monitor my infrastructure, while relying on it as a central logging system as well.
    Parth R.

    Wazuh Solution

    Reviewed on May 14, 2026
    Review provided by G2
    What do you like best about the product?
    We can see all the different types by adding a field, which makes it easier to use.
    What do you dislike about the product?
    Many times the dashboard gets disconnected, and the logs come in with a delay. Also, there is no option for a normal user to switch the theme.
    What problems is the product solving and how is that benefiting you?
    It’s easy to configure, and I appreciate that it’s free and open source.
    Gibrain S.

    A Very Good, Fully Open-Source SIEM

    Reviewed on May 05, 2026
    Review provided by G2
    What do you like best about the product?
    which is a very good SIEM and is completely open source
    What do you dislike about the product?
    that in order for it to work optimally, you need to spend a lot of time fine-tuning the settings
    What problems is the product solving and how is that benefiting you?
    traceability of connections, access, and specific file usage; vulnerability detection; and integration with various technologies
    Computer Networking

    Wazuh: FREE - Powerful, Customizable Security Monitoring with Smart Alerts

    Reviewed on Mar 12, 2026
    Review provided by G2
    What do you like best about the product?
    Wazuh helps keep all your computers and servers safe by watching for bad behavior, checking for weaknesses, and sending alerts when something suspicious happens. It’s free, open, and can be customized to fit any setup, from small networks to large companies.
    What do you dislike about the product?
    Some common drawbacks of Wazuh are that it can be complex to set up and configure, especially for large environments, and managing rules, alerts, and integrations can require significant time and expertise. Additionally, its UI and reporting features are less polished compared to some commercial alternatives, which can make monitoring at scale more cumbersome.
    What problems is the product solving and how is that benefiting you?
    Wazuh detects security threats, monitors system activity, and checks for vulnerabilities, helping prevent breaches and maintain compliance. This benefits you by giving real-time alerts, centralized visibility, and actionable insights, so you can respond quickly to issues and keep your environment secure without manually checking each system.
    naty d.

    Free, Open-Source, and User-Friendly SIEM for SMB

    Reviewed on Feb 26, 2026
    Review provided by G2
    What do you like best about the product?
    The main reasons that i like about wazuh is being free and opensouce, having simpler learning curve and ease of use, it is user friendly and best choice for small scale companies
    What do you dislike about the product?
    In my openion the down side of wazuh is it is difficult to integrate it with 3rd party solutions, and don't have built in plugins to do so compared to other SIEMs in the ecosystem.
    What problems is the product solving and how is that benefiting you?
    The main problem that i used to tackel wazuh is endpoint security and log coorelation/normalization. i have deployed the agent in all of our company assets and able to analyze logs, better visibility regarding security events and much more.
    Ayush G.

    Open-Source Security Platform with Strong Visibility and Control

    Reviewed on Jan 29, 2026
    Review provided by G2
    What do you like best about the product?
    Wazuh is the level of visibility and control it provides over security events across the entire infrastructure. The real-time threat detection, log analysis, and compliance monitoring are very powerful for an open-source platform. It delivers enterprise-level security capabilities without high licensing costs.
    What do you dislike about the product?
    The main drawback is the steep learning curve, especially for new users during initial setup and tuning. Some configurations and rule customizations can be time-consuming, and the UI could be more intuitive. Better guided setup and clearer documentation for advanced use cases would help a lot.
    What problems is the product solving and how is that benefiting you?
    I use Wazuh for centralized security monitoring and threat detection, solving fragmented security visibility by centralizing logs. It helps us quickly detect threats and compliance issues, improving security posture without multiple tools.