Security analytics & SIEM · Wazuh, Inc.

Wazuh

Free, open-source security platform combining SIEM and XDR capabilities for log analysis, threat detection and compliance.

Wazuh is a free, open-source security monitoring platform that combines host-based intrusion detection, log analysis, file integrity monitoring, vulnerability detection and compliance reporting (PCI-DSS, HIPAA, GDPR) in one agent-plus-manager architecture, built on an Elasticsearch/OpenSearch-compatible backend. It started as a fork of OSSEC and has grown into a full SIEM/XDR alternative to commercial platforms, appealing to security teams and MSSPs that want full control over their detection stack without per-GB licensing. It is entirely self-hosted (with a managed cloud offering from the vendor as an optional paid service), and the core software carries no license fee — revenue comes from support contracts and the managed cloud tier rather than software licensing.

At a glance

Vendor Wazuh, Inc.
Pricing model Open source + paid options
Free tier Yes
Deployment Cloud, Self-hosted
Open source Yes (GPL-2.0)
Best for Security teams and MSSPs wanting a fully open-source SIEM/XDR without per-GB licensing costs.

Pricing

The core platform is free and open source; the vendor sells an optional managed cloud tier and paid support contracts.

Pricing has not been verified yet — see the vendor's site.

Features

  • Host-based intrusion detection and log analysis
  • File integrity monitoring
  • Vulnerability detection against installed software
  • Compliance reporting (PCI-DSS, HIPAA, GDPR, NIST)
  • Agent-based architecture across Linux, Windows, macOS
  • SIEM and XDR use cases on the same open-source stack

Integrations

Profile last reviewed September 21, 2026

Head to head

Alternatives

Wazuh in the index now

Terms to know

Related guides