See how Wazuh's open source SIEM and XDR platform works, what its free and cloud pricing looks like, and where it fits in a security stack.
Wazuh is a free, open source security platform that combines SIEM and XDR functionality to help organizations detect threats, monitor compliance, and respond to security incidents across endpoints and cloud workloads. The company behind the project was founded in 2015 and is based in San Jose, California.
The platform grew out of the open source intrusion detection ecosystem, evolving from an earlier OSSEC-based project into a broader, independently maintained security monitoring stack with its own agent, server, and dashboard components.
Because the entire stack is open source with no licensing fee, Wazuh has become one of the most widely adopted free security platforms, used by security teams that want full control over their data or a lower-cost alternative to commercial SIEM tools.
Lightweight agents deployed on servers, workstations, cloud instances, and containers collect logs, system inventory, and file integrity data for centralized analysis.
Log data analysis and correlation identify suspicious activity and security events across the monitored environment, feeding into a central alerting and dashboard system.
File integrity monitoring tracks changes to critical files and configurations, helping detect unauthorized modifications or tampering.
Vulnerability detection scans installed software against known vulnerability databases to flag outdated or exploitable packages.
Configuration assessment checks systems against security benchmarks like CIS to identify misconfigurations.
Compliance support maps monitoring and reporting capabilities to regulatory frameworks such as PCI DSS, HIPAA, and GDPR.
Active response features can automatically take action, such as blocking an IP address, when certain threats are detected.
Wazuh's core platform, including the agents, server, and dashboard, is free and open source with no licensing cost, so organizations can deploy the full SIEM and XDR stack on their own infrastructure at no software charge.
Costs for a self-hosted deployment come from infrastructure (servers, storage, and scaling for log volume) and internal engineering time to deploy, tune, and maintain the platform.
For organizations that prefer a managed option, Wazuh Cloud offers hosted deployment and support, priced through custom quotes based on data volume, number of agents, and support level rather than fixed published pricing.
Yes, the core Wazuh platform is free and open source with no licensing cost. Costs come from your own hosting infrastructure, or from the optional paid Wazuh Cloud managed service.
Wazuh's SIEM functionality focuses on aggregating and correlating log data for threat detection and compliance, while its XDR functionality extends detection and automated response across endpoints and cloud workloads in a unified platform.
Yes, Wazuh includes monitoring and reporting features that map to compliance frameworks such as PCI DSS, HIPAA, and GDPR.
Yes, Wazuh agents and integrations support major cloud providers like AWS, Azure, and Google Cloud, and Wazuh also offers a managed Wazuh Cloud hosting option.
Wazuh is used by security operations center teams, managed security service providers, and IT teams that need centralized threat detection and compliance monitoring without commercial SIEM licensing costs.
Wazuh uses lightweight agents installed on endpoints that send data to a central Wazuh server, with results visualized through a dashboard built on OpenSearch.
Wazuh Cloud, the managed hosting option, uses custom pricing based on data volume and support needs rather than fixed published rates, so pricing requires contacting Wazuh directly.