Wazuh alternatives

3 tools to consider instead of Wazuh, shown against it.

Wazuh OpenSearch Rapid7 InsightIDR IBM QRadar
Vendor Wazuh, Inc. OpenSearch Software Foundation (originated at Amazon) Rapid7, Inc. IBM
Pricing model Open source + paid options Open source + paid options Quote only Quote only
Free tier Yes Yes No No
Deployment Cloud, Self-hosted Cloud, Self-hosted Cloud Cloud, Self-hosted
Open source Yes (GPL-2.0) Yes (Apache-2.0) No No
Best for Security teams and MSSPs wanting a fully open-source SIEM/XDR without per-GB licensing costs. Teams that want an Elasticsearch-compatible, fully open-source log analytics stack without license-model risk. Lean security teams wanting predictable, asset-based SIEM pricing tied into vulnerability management context. Large enterprises and MSSPs with mature SOC processes built around correlation rules and offense management.
Pricing

The core platform is free and open source; the vendor sells an optional managed cloud tier and paid support contracts.

Pricing has not been verified yet — see the vendor's site.

The software is free under Apache-2.0; cost is entirely the compute/storage of self-hosting or a managed service like Amazon OpenSearch Service.

Pricing has not been verified yet — see the vendor's site.

Asset-based pricing (not per-GB), sold in Essential/Advanced/Ultimate tiers; exact rates require a quote, with volume discounts from ~500 assets.

Checked on the vendor's own page on September 21, 2026: no prices are published. Expect to be quoted.

Quoted per events-per-second (EPS) or flow capacity; no published self-serve pricing.

Pricing has not been verified yet — see the vendor's site.

Features
  • Host-based intrusion detection and log analysis
  • File integrity monitoring
  • Vulnerability detection against installed software
  • Compliance reporting (PCI-DSS, HIPAA, GDPR, NIST)
  • Agent-based architecture across Linux, Windows, macOS
  • SIEM and XDR use cases on the same open-source stack
  • Distributed search and log analytics on a Lucene-based engine
  • OpenSearch Dashboards for visualization
  • Security Analytics plugin for detection rules
  • k-NN vector search
  • Index lifecycle management for hot/warm/cold tiering
  • Fully open-source, forkable under Apache-2.0
  • Cloud SIEM with log search and correlation
  • User and entity behavior analytics (UEBA)
  • Endpoint detection and response (EDR) agent
  • Asset-based pricing model instead of per-GB
  • Shared context with Rapid7 vulnerability management
  • Managed detection and response (MDR) add-on available
  • Real-time correlation rules across log and network flow data
  • User and entity behavior analytics (UEBA)
  • Integrated SOAR case management and playbooks
  • Network flow analysis alongside log data
  • SaaS or on-premises appliance deployment
  • Threat intelligence feed integration

In the index now