I have been working with Wazuh for two years, and I can explain how I use Wazuh. I did not use Wazuh as a SIEM solution. I use Wazuh as a tool for services we provide. This service is called compromise assessment. I use Wazuh because Wazuh agent has EDR agent capabilities and some EDR capabilities on their agents. I use Wazuh beside some tools in my toolset. I implement deception engines using it.
Compromise assessment activity requires collecting logs and analyzing everything involved. Regarding threat detection capabilities, I speak honestly about it. When I say I use it for compromise assessment, I use it for that because Wazuh agent has great, very powerful capabilities to collect logs and correlate them against your environment to help detect threats or maybe future threats. Wazuh has an agent with EDR capabilities and some XDR capabilities also. That's why it's very good for me in terms of usage. It helps me in compromise assessment activity as a service we provide in our company.
I find the real-time dashboard in Wazuh to be very good, but I do not recommend Wazuh for day-to-day operations. I recommend it for fast activities. I do not recommend Wazuh for long-term use or building your own SOC based on it.