A configuration file changes. The change may be a routine update, a careless administrator, or the first useful clue that somebody has entered a machine without permission. The file itself offers no opinion. A security team needs a record of what happened, enough context to judge it, and a way to act. Wazuh puts those jobs inside a platform whose software licence costs nothing.
That price makes a splendid opening line. It also invites the wrong calculation. Collecting security data is one expense; keeping it useful is another. Wazuh’s business sits between the two. It gives people the code, then sells services to people who would rather spend their working day investigating trouble than tending the machinery that reports it.
- One platform: SIEM event analysis and XDR endpoint monitoring and response.
- Free software, paid operations: cloud hosting, support, consulting, and training.
- Useful in company: Groupon and Los Angeles use it alongside other tools.
- The deciding resource: somebody must own the alerts, rules, and maintenance.
The bargain in the log file
SIEM stands for security information and event management. In ordinary language, it brings records from different systems together so analysts can find suspicious activity. XDR, or extended detection and response, reaches into the systems being monitored. Wazuh combines these functions, covering endpoints and cloud workloads through agents, integrations, and central analysis.
The problems are wonderfully unglamorous: an altered file, software with a known vulnerability, a machine configured too loosely, a suspicious sequence of logins. Its capabilities include file integrity monitoring, configuration assessment, malware detection, and regulatory reporting. The attraction is the chance to ask several questions of the same environment without assembling a separate product for every question.
In the wider market, Splunk Enterprise Security and Microsoft Sentinel offer alternative routes to security event analysis. Wazuh’s distinctive proposition is inspectable code, a self-hosting option, and a combined endpoint and event platform without a software licence bill. The relevant comparison is what a particular team can operate, integrate, and investigate effectively.
A fork with ambitions
Wazuh began in 2015 as a fork of OSSEC, the open-source host-based intrusion detection project. Founder and CEO Santiago Bassett had contributed to both OSSEC and OSSIM. Starting with existing monitoring code gave the company a foundation; the subsequent releases show how much building remained.
Version 2.0, released in April 2017, integrated OpenSCAP and Elastic Stack 5 and supplied a Kibana application. In May 2022, version 4.3.0 introduced Wazuh’s own indexer and dashboard, based on OpenSearch. Users could install a more complete Wazuh stack rather than separately deploying the older search and visualization combination.

That evolution matters more than a founding legend. The product moved from extending a monitoring tool to supplying the pieces around it. Even the branding changed: Wazuh retired its wolf-based identity in 2022. The directory name /var/ossec, still visible in documentation, is a less ceremonial reminder of its ancestry.
Three rooms behind the dashboard
The dashboard is the visible end of a process. On a monitored endpoint, an agent collects information. The Wazuh server interprets incoming events with decoders and rules. The indexer stores and makes alerts searchable. The dashboard lets people query and visualize that information, while also managing platform configuration.
- 01AgentCollect the evidence
- 02ServerDecode + apply rules
- 03IndexerStore + search
- 04DashboardInvestigate + manage
Decoders make unfamiliar records intelligible; rules decide which patterns deserve attention. This is where customization becomes practical. A team can make the monitoring reflect its own applications and conventions. It also inherits the job of keeping those interpretations accurate as the environment changes.

The customer who wanted to keep choosing
Groupon started using Wazuh in 2018. Its challenge was to monitor a high volume of AWS data while preserving the ability to scale and integrate other tools. The company’s Wazuh-published case study describes an evaluation led by IT security manager Martin Petracca.
Groupon chose Wazuh alongside ELK, AWS-native services, Prowler, and Cloud Custodian. The result was a working collection of tools, with Wazuh helping centralize monitoring. The case study reports better visibility and lower costs, and identifies Wazuh as Groupon’s chosen intrusion detection system for PCI DSS needs.
“not paying for a license is not the biggest advantage of using an open-source tool.”
Martin Petracca / Groupon IT Security Manager
The buyer’s checklist included an active repository, customization, and professional support. That is a useful correction to the romance of free software. The bargain included the freedom to keep assembling a system around Groupon’s requirements.
A city is a very untidy network
Los Angeles’s Information Technology Agency offers a different test. Its integrated security operations center faced more than 40 departments with their own infrastructure. A large department and a small one could have very different resources, yet both needed a minimum level of security visibility.
The team used Wazuh Cloud to collect logs, particularly Windows events, and built custom rules for specific channels and integrations. It also collected information from Windows Defender and its existing endpoint detection and response tools, helping identify bypasses or tampering without visiting every endpoint individually.
The Los Angeles case study reports custom rules deployed across them in minutes.
The lesson is organizational: a useful detection can travel. Shared telemetry and rules let the central team work with departments instead of treating every machine as a separate expedition. The city’s case study describes both faster threat response and ongoing work, which is a sensible way to describe security.
The bill arrives elsewhere
Wazuh sells a choice about who runs the central infrastructure. Self-hosting gives a team direct control and the accompanying maintenance duties. Wazuh Cloud hosts and manages the central components, including scaling and updates. Both routes leave the customer with decisions about coverage and what to do when something looks wrong.
| Plan | Agents | Monthly |
|---|---|---|
| Small | Up to 100 | $571 |
| Medium | Up to 250 | $923 |
| Large | Up to 500 | $1,467 |
Checked October 2, 2026. Small includes one month of indexed retention and three months of archive retention; Medium and Large list three months and one year respectively. Custom plans are available.
Professional support and consulting address deployment, integrations, and tuning. Training makes the economics particularly plain: the listed public Essential course costs $1,800 per seat, and Advanced costs $2,200. Both are four-day practical courses. Access to software and the ability to run it well have separate price tags.
There is a physical cost, too. For a small quickstart deployment of 1-25 agents, Wazuh recommends four virtual CPUs, 8 GiB of memory, and 50 GB of storage for 90 days of indexed alert data. Larger environments require more planning. Free code still occupies a server and somebody’s calendar.

The company describes a distributed team of more than 200 people and reports over 30 million downloads a year. Downloads are a measure of distribution, not a census of paying customers. Its public repository and community channels make contribution and discussion part of the product’s operating environment.
The queue that stopped the alerts
Security tools need maintenance for the same reason other software does. Wazuh’s September 23, 2026 release notes document a particularly instructive failure: a deadlock in the analysis engine stopped alert generation when the Active Response queue filled. Version 4.14.8 fixed it. A response mechanism could interfere with the system’s ability to report what was happening.
Active Response executes scripts when specified alerts trigger. It can block malicious access or remove malicious files, and supports responses that revert after a period. Wazuh’s documentation explicitly cautions that poor rules and response implementations can increase an endpoint’s vulnerability. Automation needs testing, ownership, and a decision about reversal.
The platform can also help collect evidence for compliance frameworks, including PCI DSS, NIST, GDPR, and HIPAA. A report remains evidence within a larger process. Installing a monitoring tool cannot establish that an entire organization meets a standard.
Start smaller than your ambition
Here is a practical way to borrow the customer stories: begin with one log source, one meaningful detection, and one named person responsible for investigating it. Check that a test event arrives, receives the expected interpretation, and produces a useful alert. Add coverage once that small chain works. This is an editorial recommendation, rather than a promised deployment recipe.
Wazuh’s recent partnerships extend the model to service providers. September 2026 announcements describe E Defence building SOC services for West Africa and AI Cyber Consulting serving colleges, universities, and small companies in South Africa. The provider supplies operational expertise around a platform customers could download themselves.
That arrangement explains the company’s appeal. A small team can experiment without first negotiating a licence. An enterprise can customize a stack. A provider can sell the labour of watching it. Each still needs to answer the question raised by the altered file: who will notice, who will decide, and who will act?