Security analytics & SIEM · Wazuh, Inc.
Wazuh
Free, open-source security platform combining SIEM and XDR capabilities for log analysis, threat detection and compliance.
Wazuh is a free, open-source security monitoring platform that combines host-based intrusion detection, log analysis, file integrity monitoring, vulnerability detection and compliance reporting (PCI-DSS, HIPAA, GDPR) in one agent-plus-manager architecture, built on an Elasticsearch/OpenSearch-compatible backend. It started as a fork of OSSEC and has grown into a full SIEM/XDR alternative to commercial platforms, appealing to security teams and MSSPs that want full control over their detection stack without per-GB licensing. It is entirely self-hosted (with a managed cloud offering from the vendor as an optional paid service), and the core software carries no license fee — revenue comes from support contracts and the managed cloud tier rather than software licensing.
At a glance
| Vendor | Wazuh, Inc. |
|---|---|
| Pricing model | Open source + paid options |
| Free tier | Yes |
| Deployment | Cloud, Self-hosted |
| Open source | Yes (GPL-2.0) |
| Best for | Security teams and MSSPs wanting a fully open-source SIEM/XDR without per-GB licensing costs. |
Pricing
The core platform is free and open source; the vendor sells an optional managed cloud tier and paid support contracts.
Pricing has not been verified yet — see the vendor's site.
Features
- Host-based intrusion detection and log analysis
- File integrity monitoring
- Vulnerability detection against installed software
- Compliance reporting (PCI-DSS, HIPAA, GDPR, NIST)
- Agent-based architecture across Linux, Windows, macOS
- SIEM and XDR use cases on the same open-source stack
Integrations
Profile last reviewed September 21, 2026