Wazuh

Wazuh

GPL-2.0 unified XDR and SIEM platform from Wazuh, Inc. — all capabilities including RBAC, threat hunting, and compliance mapping modules included in the open-source binary; paid tier is managed cloud only.

🩺 Vitals


🏗️ Profile

1. The Executive Summary

What is it? Wazuh is a unified, open-source XDR (Extended Detection and Response) and SIEM (Security Information and Event Management) platform developed by Wazuh, Inc. (Campbell, California). Lightweight agents deployed to endpoints — servers, cloud instances, workstations — stream security telemetry to a centralised Wazuh cluster composed of three components: the Wazuh Indexer (OpenSearch), the Wazuh Server (Manager), and the Wazuh Dashboard. All functional capabilities — RBAC, AI-assisted threat hunting, File Integrity Monitoring, intrusion detection, and pre-built compliance mapping modules for PCI DSS, HIPAA, NIST 800-53, and TSC — are included in the GPL-2.0 binary at no cost. The only commercial offering is Wazuh Cloud: managed hosting billed per agent with no feature uplift.

The Strategic Verdict:

2. The "Hidden" Costs (TCO Analysis)

Cost Component Splunk (SaaS) Wazuh (Self-Hosted)
Data Ingestion $0.10–$0.30/GB $0 (owned OpenSearch storage)
Agent Fees Recurring per-endpoint $0 (unlimited agents)
Retention Expensive indexing tier Cost of disk / object storage
Compliance Modules Custom content packs PCI DSS, HIPAA, NIST 800-53 (built-in)
RBAC Enterprise tier Included (GPL binary)

3. The "Day 2" Reality Check

🚀 Deployment & Operations

🛡️ Security & Governance (Risk Assessment)

4. Market Landscape

🏢 Proprietary Incumbents

🤝 Open Source Ecosystem