Wazuh is a free, open source and enterprise-ready security monitoring solution for threat detection, integrity monitoring, incident response, and regulatory compliance.
The solution includes the Wazuh server, which is in charge of analyzing the data received from the agents, processing events through decoders and rules, and using threat intelligence to look for well-known IOCs (Indicators Of Compromise). A single Wazuh server can analyze data from hundreds or thousands of agents. Alerts generated by Wazuh are sent to Wazuh indexer, where they are indexed and stored. The unique integration between Wazuh and Wazuh dashboard provides a powerful user interface for data visualization and analysis. The server is also used to manage the agents, configuring and upgrading them remotely when necessary. Additionally, the server is capable of sending orders to the agents, for example, to trigger a response when a threat is detected.
Wazuh provides a security solution capable of monitoring your infrastructure, detecting threats, intrusion attempts, system anomalies, poorly configured applications, and unauthorized user actions. It also provides a framework for incident response and compliance, all in one platform.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
This listing is free software, so you pay no license fee to the vendor. Your only charges are the hourly rate for the AWS EC2 instance you run it on. The many dimensions listed are EC2 instance types, not separate product tiers. Each represents a different mix of compute, memory, and storage capacity. You pick one instance size to match your workload, then pay by the hour for that instance. Larger instances suit more monitored endpoints and longer data retention. Pricing scales with the instance you choose, giving you a single all-in-one deployment on one host.
Top-of-mind questions for buyers
What does the software actually cost, given the listing is marked free?
The software carries no license fee. You pay only the hourly rate for the AWS EC2 instance type you select. Because Wazuh is open source under GPL v2 and Apache 2.0, the deployment charges reflect AWS compute, memory, and storage, not the software itself.
Am I charged when the EC2 instance is stopped?
Hourly charges apply while the instance runs. A stopped instance does not accrue hourly compute charges. You may still pay AWS for attached storage that persists while stopped. Since the software has no license fee, running time on your chosen instance drives the compute cost.
How do I choose an instance size for the number of endpoints I monitor?
Instance sizing depends on how many endpoints and cloud workloads you protect and how long you retain data. A single-host all-in-one deployment typically suits up to 100 endpoints with 90 days of indexed alerts. Larger environments need instances with more compute, memory, and storage.
documentation.wazuh.com
Helpful?
Vendor refund policy
We do not currently support refunds.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
To access the instance by ssh, you will need to use the user: wazuh-user
When the instance is launched, the user passwords are automatically changed to the instance ID with the first letter capitalized. For example: I-07f25f6afe4789342. This ensures that only the creator has access to the interface. This process can take an average of five minutes, depending on the type of instance. During this time, both SSH access and access to the Wazuh dashboard are disabled.
Wazuh has one of the largest open source security communities in the world. You can become part of it to learn from other users, participate in discussions, talk to our development team, and contribute to the project.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
VAST-All-In-One offers a comprehensive solution for an 'end-to-end' migration experience to Amazon Web Services (AWS). Our suite of services includes thorough Cloud Assessment, expert AWS Infrastructure Build or Revamp, cutting-edge Security Build-out using Next Generation Firewalls, seamless Migration Services, proactive Monitoring Services, and reliable Disaster Recovery. Elevate your IT infrastructure confidently and efficiently with VAST—unlocking the full potential of your AWS journey. Contact us today for a successful transition.
The platform streamlined our security monitoring process by facilitating real-time log analysis and automated vulnerability detection which saves me hours each week instead of manually checking logs and I like the immediate threat alerts that also give us clear visibility into our system health.
What do you dislike about the product?
Nothing to dislike about it thus far it has been a great security monitoring platform and even the broader team also seems to feel the same.
What problems is the product solving and how is that benefiting you?
It effectively connects all our system logs to a centralized dashboard which helps track security events easily and an unexpected benefit is how it catches system misconfigurations we didn't even know we had furthermore the automated alerts help improve our overall security without constant manual oversight.
Information Technology and Services
All-in-One Open-Source SIEM/XDR with Powerful Customization and Integrations
Reviewed on Jul 28, 2026
Review provided by G2
What do you like best about the product?
What I like most about Wazuh is how it brings SIEM, XDR, file integrity monitoring, vulnerability detection, log management, and compliance monitoring together in one open-source platform. It also integrates smoothly with tools like Elastic, supports a broad range of operating systems, and offers highly customizable rules and dashboards—all without expensive licensing costs.
What do you dislike about the product?
Wazuh can be complex to deploy and maintain, especially in larger environments. Initial configuration, rule tuning, and reducing false positives require time, and major upgrades or integrations can sometimes involve additional manual effort.
What problems is the product solving and how is that benefiting you?
Wazuh helps centralise security monitoring across multiple systems by collecting logs, detecting suspicious activity, and highlighting configuration or compliance issues in one place. It has improved visibility into our environment, reduced the time needed to investigate alerts, and made it easier to identify potential security issues before they become larger problems.
Sudarson Prabhu
File integrity monitoring has strengthened our data protection and supports compliance needs
Reviewed on Jul 03, 2026
Review provided by PeerSpot
What is our primary use case?
Our organization is focusing on the integrity part for implementing Wazuh. We were checking solutions for File Integrity Monitoring systems that are available online. Wazuh caught my attention as a very cool solution for verifying file integrity. We decided to try Wazuh for focusing on the integrity part. While implementing it, our objective was achieved. We were able to monitor entire file integrity. Because our organization's business requires core concepts of integrity to be maintained, this was very important for us. Wazuh did this very well. We were not able to make it available to all endpoints. Instead, we tried it with servers. We changed our business requirements by storing all files that are processing into the server as a shared server and then we put File Integrity Monitoring and Wazuh in a single server. This worked out very well.
What is most valuable?
The dashboards in Wazuh are very cool and they provided whatever data is required.
I would give ten out of ten for the technical suggestion that I received from the documentation of Wazuh. The documentation provides everything that we are expecting. I have not tried any support from staff for Wazuh, but the documentation was very clear and I can give it ten out of ten.
What needs improvement?
I expected one thing from the dashboard in Wazuh. In ManageEngine, when you use ManageEngine, you can assign a unique ID to all employees. Then with the unique ID, if you search any unique ID in the dashboard itself, you can get the unique ID everywhere, including where the laptop has been logged in, when the logout happened, and what actions have been done for that unique ID. I expected the same in Wazuh, but whenever we want to check any monitoring activities for a specific person, we need to search for the endpoint and then get the endpoint details from our Active Directory or wherever we have the endpoint name stored in our resources, and then search for the endpoint to see the history for that specific endpoint only. This made a simple thing a bit complex. If we had a correlation of logs where I could just search one unique ID and then the unique ID pulls every system in a time-wise manner, that would be a great improvement I would suggest.
For how long have I used the solution?
I have been using Wazuh for around seven to eight months. In my previous organization, I was about to install and work with Wazuh. Since it is open source, I was fully configuring it for the organization.
What do I think about the scalability of the solution?
When we use a very good configuration laptop, it functions very smoothly. However, when we use low-end laptops for low-level employees, then the laptops become slow. This is because of the backend work the agent is collecting and processing, causing the laptop to slow down and the bandwidth to decrease.
Which solution did I use previously and why did I switch?
We had FortiNet and then we had McAfee.
What other advice do I have?
I have not worked very well with Wazuh's threat detection capabilities because we already had some solution in place. Our focus was to implement Wazuh for integrity only and File Integrity Monitoring only. I have worked earlier with Wazuh and ManageEngine. When I was working with Wazuh, there was no artificial intelligence introduced. My overall review rating for Wazuh is eight out of ten.
Abhishek N.
Powerful SIEM Tool with Robust AI Features
Reviewed on Jun 04, 2026
Review provided by G2
What do you like best about the product?
I love that Wazuh is open source and has active community support, along with support for various technologies like XDR, UEBA, threat hunting, and FIM. My favorite features are the scope and use case of the tool, especially the Anomaly Detector using AI and historical data patterns. The Anomaly Detector dashboard is user-friendly, and its integration with AI and machine learning utilizing the RCF algorithm is impressive.
What do you dislike about the product?
Wazuh lacks visual correlation, has heavy storage requirements, and complex SOAR integrations. The initial setup also requires many configurations compared to other SIEM tools, making it only moderately easy.
What problems is the product solving and how is that benefiting you?
Wazuh offers great community support and supports technologies like XDR, UEBA, and threat hunting. Its Anomaly Detector using AI and historical data patterns is a valuable feature.
Karsh T.
Centralized Monitoring and security Incidents Simplified
Reviewed on May 20, 2026
Review provided by G2
What do you like best about the product?
I like Wazuh for its log integration and dashboards, which I find genuinely helpful. I also appreciate how well Wazuh integrates with other tools. On top of that, the secure configuration assessment is valuable, and I like that it natively supports multiple clouds as well as other SaaS platforms. Overall, it lets me monitor all my logs smoothly in one place, under a single pane of glass.
What do you dislike about the product?
Things that could be improved on Wazuh’s side include its indexing. In addition, the documentation on how to manage indices and handle data more effectively is something that could be added to or improved further. Another feature I’d like to see in Wazuh is a built-in case management system. I’d also like better multi-log correlation, meaning I should be able to correlate and coordinate logs from multiple different sources at the same time. Last but not least, the pricing for Wazuh Cloud could be revised to make it more affordable for those who don’t want to rely on an on-prem deployment.
What problems is the product solving and how is that benefiting you?
I use Wazuh for centralized monitoring, secure configuration assessments, and monitoring cloud systems and logs so I can proactively respond to incidents. I also use it to hunt threats and monitor my infrastructure, while relying on it as a central logging system as well.