SIEM
security event aggregation + correlation

// screenshot of wazuh.com ↗
Wazuh is an open-source Security Information and Event Management (SIEM) + XDR platform — endpoint security monitoring, log analysis, file integrity monitoring, vulnerability detection, threat intelligence. Backed by Wazuh Inc. (formerly OSSEC fork). Used at enterprise scale globally.
Wazuh is an open-source Security Information and Event Management (SIEM) + XDR platform — endpoint security monitoring, log analysis, file integrity monitoring, vulnerability detection, threat intelligence. Backed by Wazuh Inc. (formerly OSSEC fork). Used at enterprise scale globally.
For SOC (Security Operations Center) teams needing OSS SIEM that competes with Splunk / Elastic Security, Wazuh is the leading option.
Concrete scenarios where teams pick Wazuh over the SaaS alternative.
security event aggregation + correlation
extended detection and response
agent-based monitoring on servers + workstations
CVE scanning for installed packages
PCI DSS, HIPAA, GDPR mapped controls
If your team profile matches one of these, Wazuh is a strong fit out of the box.
running enterprise security operations
monitoring server security
providing managed security services
needing SIEM for certifications
rejecting cloud SIEM
When evaluating self-hosted options for this category, here are the dimensions on which Wazuh consistently lands above the alternatives.
The stack you'll plug Wazuh into — services, protocols, and adjacent apps in the BluixApps catalog.
wazuh/wazuh-manager:4.10 (release-tagged)Operational guidance from running this in production — what to do before you scale, what to lock down, what surprises people.