Sign in Agent Mode
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Reviews from AWS customer

5 AWS reviews

External reviews

26 reviews
from

External reviews are not included in the AWS star rating for the product.


4-star reviews ( Show all reviews )

    Md Salim Hossain Hossain

An open-source platform to integrate various products

  • January 31, 2024
  • Review provided by PeerSpot

What is our primary use case?

We use Wazuh for the onboarding of both Windows and Linux machines, as well as for firewall and SIM configuration. The IP address is automatically blocked if a server has multiple wrong passwords.

How has it helped my organization?


What is most valuable?

Wazuh can integrate with various open-source and paid products, allowing for flexibility in customization based on use cases. Wazuh supports multiple use cases, allowing for in-depth customization. Additionally, Wazuh incorporates detection mechanisms such as tracing, shared internal suites, and leveraging third-party feeds. Machine learning mechanisms are also built to enhance detection capabilities, helping identify suspicious or anomalous behavior. It is open-source nature, which allows for widespread adoption and community support. The growing community contributes to its continued development and improvement.

What needs improvement?

I have built some rules that produce duplicate alerts two or three times. Therefore, these rules should be consolidated. Alerts should be specific rather than repeatedly triggered by integrating multiple factors. This issue needs improvement to create a more efficient alert system.

For how long have I used the solution?

I have been using Wazuh as an end user since 2023.

What do I think about the stability of the solution?

The product is stable.

What do I think about the scalability of the solution?

The solution is scalable. In the Bangladesh market, several banks are now actively considering Wazuh. They become fully compliant with compliance issues. Earlier, they were struggling to obtain approval and maintain compliance standards.

Which solution did I use previously and why did I switch?

I have used Elastic Security. There are some customization needs in Wazuh. We cannot customize it.

How was the initial setup?

The initial setup is easy. Log management plays a crucial role in using Wazuh to its full potential. Assessing the volume and nature of the data is essential to determine EPS. This calculation is pivotal, as it dictates resource allocation, such as access, RAM, and storage specifications.

What's my experience with pricing, setup cost, and licensing?

The product is an open-source platform.

What other advice do I have?

Wazuh can onboard multiple customers onto a single deployment through its multi-tenancy feature. Each customer can have their own interface with the same deployment location.

The solution’s maintenance is easy.

Overall, I rate the solution an eight out of ten.


    David Arianto

Cost-effective solution with robust stability for threat detection and compliance

  • October 05, 2023
  • Review provided by PeerSpot

What is our primary use case?

We use it as a cost-effective solution for our customers who are in the initial stages of adopting security measures. Many of these customers are new to security practices and are primarily seeking compliance with regulations.

What is most valuable?

Its cost-effectiveness is the most valuable aspect.

What needs improvement?

There is room for improvement in terms of simplifying the deployment process. In addition, it would be beneficial if Wazuh focused on expanding its offensive modules as the primary enhancement. Another valuable development would be the introduction of a Security Orchestration, Automation, and Response capability. It could work on further developing its threat intelligence offerings as the third priority.

For how long have I used the solution?

I have been using it for two years.

What do I think about the stability of the solution?

We haven't faced any issues or challenges regarding its stability.

How are customer service and support?

One of the challenges we face in Indonesia is the time zone difference when seeking support. The support team could be more responsive and provide quicker replies during our working hours in Indonesia, which would be a significant improvement.

How would you rate customer service and support?

Negative

Which solution did I use previously and why did I switch?

I have experience with IBM QRadar. The key distinction between them and Wazuh is the presence of additional modules in IBM QRadar that are not found in Wazuh. IBM QRadar provides Security Orchestration Automation and Response capabilities, while Wazuh does not offer this feature.

How was the initial setup?

The initial setup is relatively smooth and typically takes approximately one week to complete.

What about the implementation team?

For the deployment process, I usually allocate one or two individuals. The first person is an infrastructure engineer, and the second is a Wazuh administrator. The deployment process involves several phases. The initial step is the assessment phase, where we evaluate the customer's assets, such as the number and types of assets and the specific logs they want to send. The second step involves implementing the assessment data and configuring it in the Wazuh engine. After completing the implementation, we move to the third phase, which focuses on operational tasks. In cases where a customer has new assets and there are no existing templates for parsing the data, our team needs to manually create these parsing templates. I would rate it six out of ten.

What's my experience with pricing, setup cost, and licensing?

It is a cost-effective solution.

What other advice do I have?

When customers prioritize enhanced security and rapid cyberattack detection, and they have a more substantial budget to work with, I typically recommend IBM QRadar. For customers who are still in the early stages of security adoption, Wazuh is my preferred suggestion. It is a suitable choice for smaller companies, as larger organizations, particularly those in the financial industry, tend to have more experienced and knowledgeable security teams. Overall, I would rate it eight out of ten.


    Gopinath Ravirajan

The solution did a good job at ensuring PCA nodes were PCI compliant

  • October 03, 2023
  • Review provided by PeerSpot

What is our primary use case?

We use Wazuh for PCI compliance monitoring. It can detect whether a server or PCA node is PCI compliant.

What is most valuable?

Wazuh is simple to use for PCI compliance.

What needs improvement?

Some features, like alerting, are complex with Wazuh. Setting up alerts and triggers can be difficult, and the interface could be better. Compared to other platforms, such as New Relic, Wazuh's UI could be improved. New Relic has a similar interface, but the UI updates have made it a better product.

We have certain requirements regarding monitoring and whether Wazuh is completely compliant with them. It would be helpful to know if Wazuh is a complete solution for log monitoring, including the requirements of PCA and other security aspects.

For how long have I used the solution?

I have been using Wazuh for a couple of months. We are using the latest version of the solution.

What do I think about the stability of the solution?

While installing some agents, our team faced some issues. However, the stability is otherwise good. I rate the solution's stability a seven out of ten.

What do I think about the scalability of the solution?

The solution is scalable. We've three to five users using this solution. I rate the solution's scalability a seven or eight out of ten.

How are customer service and support?

Wazuh provided good support for whatever usage or issues we were facing. They were ready to support us at any point.

Which solution did I use previously and why did I switch?

We have used ELK before, but it was not a complete solution for our needs. We needed to integrate it with other solutions. Wazuh seemed a more comprehensive solution, especially compared to other providers. We also tried products from a local company, but their service was not as good as Wazuh. It is also an established company. We decided to use Wazuh.

How was the initial setup?

The initial setup of Wazuh is simple. The internal person sets up the application and installs the agents. They were able to do it in a day. Both setup and configuration are straightforward.

What's my experience with pricing, setup cost, and licensing?

The solution's pricing is very competitive. I rate the solution's pricing a nine out of ten, where one is expensive and ten is cheap.

What other advice do I have?

Overall, I rate the solution an eight out of ten.


    Haad Fida

An affordable and stable solution that can be used for event monitoring

  • October 02, 2023
  • Review provided by PeerSpot

What is our primary use case?

We use the solution for event monitoring.

What is most valuable?

The tool is stable.

What needs improvement?

The rules are hard coded. The tool doesn't detect anomalies or new environments. The product lacks AI features. We have to do a lot of manual searching.

For how long have I used the solution?

I have been using the solution for about eight months.

What do I think about the scalability of the solution?

The tool is scalable for our use cases. Five to ten people use the solution in our organization. We need one administrator to monitor and improve our solution.

How are customer service and support?

We did not contact support. Our company’s security personnel set everything and documented it.

Which solution did I use previously and why did I switch?

We use Elastic Stack for logs.

How was the initial setup?

The deployment was straightforward. It took two to three months. We needed two people for deployment.

What about the implementation team?

We did the deployment in-house with the help of our security personnel and someone from the DevOps team.

What's my experience with pricing, setup cost, and licensing?

The product is cheaper compared to other tools. Depending on the logs, the product costs $200 to $400. We currently have five servers.

Which other solutions did I evaluate?

We evaluated Google Cloud.

What other advice do I have?

When Google contacted us, we were looking into an AI solution. Our implementation is rather basic. Overall, I rate the solution an eight out of ten.


    SyedAli17

Has excellent scalability when deployed on Azure

  • September 25, 2023
  • Review provided by PeerSpot

What is our primary use case?

We primarily use Wazuh for internal security monitoring to ensure the safety of our organization's internal systems. We have two specific requirements: first, we use it to monitor our internal operations, which is essential for general security purposes. Second, we rely on Wazuh to manage the security of the National Telecom department's specialized software. This second requirement involves using multiple SOC solutions. However, within our organization, Wazuh's main focus is on monitoring our internal software.

What is most valuable?

Some of the strengths of Wazuh that stand out for us include its scalability when deployed on Azure, its open-source nature, which allows for customization based on our needs, and its compatibility with various security solutions like threat intelligence platforms. We have encountered limitations with QRadar and Splunk in the past, which we couldn't overcome, but Wazuh has proven effective. We have successfully integrated it with 56 operators within our national telecom department, although the integration process was a bit challenging. Overall, Wazuh offers valuable features, making it a beneficial addition to our security infrastructure.

What needs improvement?

One area where Wazuh could use some improvement is in its reporting mechanism, especially for high-level management like CSOs and CEOs. Creating executive-level reports can be a bit time-consuming and requires a lot of fine-tuning to meet specific organizational requirements. It would be helpful if Wazuh offered more standardized use cases commonly seen in the industry, reducing the effort needed for customization and fine-tuning. Overall, enhancing reporting features and providing standard use cases would be a valuable improvement for Wazuh.

For how long have I used the solution?

I have been using Wazuh for almost five years.

What do I think about the stability of the solution?

I would rate the stability a seven out of ten. We had a few issues with it.

What do I think about the scalability of the solution?

Wazuh is very scalable. I would give it a ten out of ten for scalability. 18 people use the solution at my company.

How was the initial setup?

The initial setup of Wazuh was relatively straightforward, with installation being easy and not time-consuming. Challenges were minimal, thanks to the availability of comprehensive documentation, guides, and forums providing ample information. In summary, the installation process was smooth and well-supported by available resources. Installation took about 30 minutes, but integration took a few months.

What other advice do I have?

I would definitely recommend Wazuh to others. Overall, I would rate it a nine out of ten.


    Usman Arif

Transforming security features with notable vulnerability reduction and comprehensive compliance

  • September 21, 2023
  • Review provided by PeerSpot

What is our primary use case?

It is used primarily for event management in our organization, which falls into the category of an edge Intrusion Detection System (IDS) or host Internet protection system. Our company is not very large, with around twenty to thirty servers and approximately one hundred fifty to two hundred endpoints. Wazuh serves as a centralized platform for collecting security events and managing vulnerabilities across your systems. Its main purpose is to analyze and improve the overall security posture of our organization.

How has it helped my organization?

Before the deployment of Wazuh, we faced challenges related to vulnerability management and version change history. Vulnerabilities often went unreported, and there was no organized system for managing vulnerabilities. Since we implemented it, there has been a notable improvement. Vulnerabilities have significantly decreased, with nearly fifty percent of servers now reporting zero vulnerabilities. This positive change is attributed to regular reporting, remediation efforts, and frequent system updates.

What is most valuable?

It offers built-in modules for file integrity and vulnerability management. This provides the convenience of having these features integrated into one platform rather than using separate dedicated tools. Wazuh's comprehensive compliance with various modules aligns well with our organization's needs, making it a highly suitable and efficient solution.

What needs improvement?

It is an open-source tool with a strong community. We had positive experiences with community support, having received solutions for most of your inquiries in the past. However, it would be beneficial if Wazuh could provide clearer guidance or tutorials on how to add components to the user interface (UI), especially when integrating tools that aren't inherently supported by Wazuh. A more structured approach, perhaps with modular UI components, to facilitate easier integration and navigation within the Wazuh platform for such custom integrations would be beneficial.

For how long have I used the solution?

I have been working with it for the last three years.

What do I think about the stability of the solution?

The stability capabilities are almost perfect. I would rate it nine out of ten.

What do I think about the scalability of the solution?

It offers excellent scalability features. I would rate it nine out of ten.

How are customer service and support?

Their customer support services are excellent. I would rate it nine out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We use other tools like SpamTitan and Fortis for specific purposes. SpamTitan is employed for email spam filtering and Fortis for client-related tasks. These tools complement our overall cybersecurity and client management efforts.

How was the initial setup?

While generally straightforward, there were some challenges during the initial setup process, particularly when dealing with certificate-related issues. I would rate it seven out of ten.

What about the implementation team?

The deployment took a total of five days, involving three individuals. Once deployed, the solution is efficiently maintained by just one person.

What's my experience with pricing, setup cost, and licensing?

Wazuh is an open-source tool, which means it is freely available for use.

What other advice do I have?

I recommend it for its flexibility and adaptability to specific organizational needs. I would rate it eight out of ten.


    Rico Agung

Affordable and powerful tool for malware detection

  • September 08, 2023
  • Review provided by PeerSpot

What is our primary use case?

The primary use case for Wazuh is the detection of malware.

What is most valuable?

It is excellent in terms of visualization and indexing services, making it a powerful tool for malware detection. It is easy to install, configure, and run, requiring minimum resource investment, even for small-scale deployments on personal devices.

What needs improvement?

Improving the abilities related to security threat mapping, such as threat map landscape visualization, would be a great benefit. Adding the flexibility to integrate various plug-ins or modules into its core system would enhance functionality.

For how long have I used the solution?

I have been working with it for two years.

What do I think about the stability of the solution?

I would rate the stability eight out of ten.

Which solution did I use previously and why did I switch?

I used Azure documentation and report storage, while researching other internet resources to gain a broader perspective on different product capabilities that are available for learning and deployment needs. Wazuh offers excellent features.

What's my experience with pricing, setup cost, and licensing?

When I contacted customer care, they mentioned bundling options, that I found to be overall affordable.

What other advice do I have?

I would recommend this product to other users in the field of cybersecurity. It provides enhanced network security and many useful features. It is easy to use, with a pricing structure that is more affordable compared to other options. I would rate it eight out of ten.


    Gerard Konan

A stable solution with an intuitive interface that enables users to search logs easily

  • July 14, 2023
  • Review provided by PeerSpot

What is most valuable?

Most of our customers are satisfied with the product. The product’s interface is intuitive. We can search logs very easily.

What needs improvement?

The implementation is very complex.

For how long have I used the solution?

We are resellers of the product.

What do I think about the stability of the solution?

The tool is stable. We had issues later when the storage space was full. We had to change the location of the logs because the customer did not point the logs to the right storage. I rate the tool’s stability an eight out of ten.

What do I think about the scalability of the solution?

The scalability might be a challenge since we use the on-premise version. The system crashed when the disc was full of log data. It was a challenge. In our customer’s organization, 50 people are using the product.

How are customer service and support?

Our customers get technical support from us. They do not receive support from Wazuh.

How was the initial setup?

We need very skilled staff to implement the tool.

What about the implementation team?

The implementation took two to three weeks. Configuring the log collector from the servers was not very simple. Sometimes, we need to write some scripts and find specific assets. It is not a fully integrated solution. We need to set up three different elements. We needed three people to deploy the product. Our customers need only two people to maintain the tool.

What's my experience with pricing, setup cost, and licensing?

It is an open-source product. Apart from the implementation cost, our customers do not have to pay for the license.

What other advice do I have?

I was not directly involved in the implementation process. I was supervising the team. We did not try to integrate the tool with other security products. Our customers wanted to integrate it with Active Directory. They also wanted to collect logs from a feature service. I know that the product has a cloud version. The problems we face with the on-premise version might be solved on the cloud version. People looking to use the product must be ready to learn and study the product. It is not easy to handle.

Overall, I rate the product an eight out of ten.


    Muhammad Muaaz Bin Zaka

Good for file integrity monitoring

  • June 15, 2023
  • Review provided by PeerSpot

What is our primary use case?

We are using Wazuh for security information and event management, PCI DSS compliance, auditing, real-time sensitive monitoring, and meeting regulatory requirements.

How has it helped my organization?

There were certain tasks we couldn't carry out before. However, with Wazuh, we found a solution within a single platform. It only required a one-time effort to set up and configure the version. After that, it's just about monitoring the alerts and making revisions. No additional efforts are needed.

What is most valuable?

The most valuable features include file integrity monitoring, Wazuh engines, Wazuh rulesets (including rulesets for Apache and firewall routers), and vulnerability detection.

What needs improvement?

There is room for improvement in Wazuh, but it's possible they are already working on it. The only challenge we faced with Wazuh was the lack of direct support. They charge for support, whether it's five days a week or seven days a week. We don't expect it to be free because revenue is generated through the support they provide.

In future releases, I would like to see a feature. There is one feature we observed in a premium tool in the industry called Dynatrace. It provides automatic relations between different devices and components. For instance, if you receive a web login request, Dynatrace can trace and show you the path it takes from the firewall to the switch, then to the Apache server, the actual job application, and finally back to the client. It intelligently correlates all the components involved in a single event.

If Wazuh could include this feature, where all the components are integrated, it would automatically relate them for any activity in your environment.

For how long have I used the solution?

We have been working with Wazuh for the last year. We currently use the latest version.

What do I think about the stability of the solution?

Sometimes, it has disturbances, but at the end of the day, it's not Wazuh but, actually, the configurations that engineers do sometimes do not have compatibility. So at that time, we face issues, but as of now, Wazuh has not disappointed us in any way.

What do I think about the scalability of the solution?

It is scalable. We can add a new machine or server, install the components, and inform the other components about its IP address. We add it to the cluster, and a restart of the cluster is all that's needed to integrate the new component.

While there are many people involved, only three or four security engineers manage and oversee the events collected and provided by Wazuh.

Which solution did I use previously and why did I switch?

We used Splunk primarily for log management purposes. There were no extra security modules or playbooks involved. We indexed the logs, built dashboards, generated reports, and set up alerts. That was the extent of our usage, without any additional security features.

How was the initial setup?

The initial setup was not complex. We had prior experience with Elastic and Elk, so the deployment of Wazuh was quite familiar to us. It wasn't a major challenge.

However, we do need maintenance as we need to upgrade the version periodically. During maintenance, we have to switch off all the endpoints, turn off all the components, and then power off one by one to upgrade them to the latest version. This is done during a maintenance window.

One or two engineers are usually enough to handle the maintenance tasks.

What about the implementation team?

In terms of the deployment plan, if we exclude the endpoints (monitored servers), we have multiple nodes for each component: indexer, manager, and dashboard. We also implemented an NGINX-based load balancer, following the documentation provided by Wazuh on configuring NGINX as a load balancer. This helps in load disturbance and redundancy, so we don't have a single point of failure when any server goes down.

The deployment process took approximately one to two weeks to fully test and deploy the system. We had to spend time on research and development to properly configure everything. The resources mainly involved Linux servers. There were not many additional resources involved beyond that.

Which other solutions did I evaluate?

We evaluated LogRhythm, which is an excellent intelligence-based tool. However, it comes with a high cost for the intelligence features. Wazuh lacks AI or machine learning capabilities, but otherwise, it has all the necessary capabilities for a similar solution.

What other advice do I have?

I would advise you to carefully follow the documentation. It is straightforward and to the point. If any issues arise, the Wazuh Slack community is highly active and responsive. They can provide assistance within 24 hours or even less, helping with any deployment or management challenges.

Wazuh offers numerous features, such as the ability to define custom rules for detecting malicious activities and remembering behaviors. Unlike some paid tools, Wazuh is extensive and extendible and allows integration with open-source tools and scripts. It is flexible, reliable, and open-source, which is its biggest advantage.

Overall, it is a good solution. I would rate the solution a nine out of ten. Considering that Wazuh is open source and free of cost while providing all the necessary features, I would rate it nine or ten. I lean towards ten because it offers a comprehensive solution without any financial burden. However, compared to industry leaders like LogRhythm and Splunk, which have machine learning modules, Wazuh lacks in that aspect. So, overall, I would rate it nine, but because of its cost-effectiveness, it deserves a ten.