Wazuh
Wazuh is an open-source unified XDR and SIEM platform providing endpoint and cloud workload protection via a universal agent and centralized analysis, indexing, and dashboard components. It serves enterprises, MSSPs, and public-sector organizations globally, monetizing through a hybrid open-core model combining free community software with paid Wazuh Cloud SaaS, professional support, consulting, and training.
- Company typePrivate
- Founded2015
- HeadquartersCampbell, United States
- Headcount101–250
- GTM typeB2B
- OfferingSoftware
What Wazuh does
Wazuh is a private, Campbell/San Jose, California-based cybersecurity software company founded in 2015 by Santiago Bassett that develops an open-source unified XDR (Extended Detection and Response) and SIEM (Security Information and Event Management) platform for endpoint and cloud workload protection. The platform is built on four components: a universal lightweight Wazuh Agent deployable across Windows, Linux, macOS, Solaris, AIX, and HP-UX; a central Wazuh Server for analysis and rule/decoders processing; a Wazuh Indexer (OpenSearch-based) for storage and search; and a Wazuh Dashboard for visualization. Core capabilities include file integrity monitoring, malware detection (integrated with VirusTotal and YARA), vulnerability detection, security configuration assessment, active response, threat hunting mapped to MITRE ATT&CK, container security, cloud security posture management across AWS/Azure/GCP, and regulatory compliance mapping for PCI DSS, GDPR, HIPAA, NIST 800-53, and TSC.
The business operates on a hybrid open-core model. The community edition is free under GNU GPL v2 and Apache 2.0, distributed via direct download, APT/YUM/ZYpp repositories, Docker, Kubernetes, and AWS Marketplace. Paid monetization comes through five streams: Wazuh Cloud SaaS (subscription, 14-day free trial), Professional Support (annual subscription), Consulting Services, Training Courses, and a Partner Program for resellers and MSSPs. The company serves a globally distributed customer base spanning enterprise (eBay, Intuit, Mondelez, Rappi, NASA, Cisco, Telefonica, Groupon, Alignet), mid-market MSSPs (Guayoyo, Firmguardian), startups (Woop), and education (University of Chichester), with reported reach of 15M+ protected endpoints, 100K+ enterprise users, and 30M+ annual downloads. Distribution is community-led and product-led at the top of the funnel, transitioning to direct enterprise field sales and a partner channel for monetization. AI capability is delivered through the Wazuh AI Analyst, an LLM-powered alert enrichment and threat-hunting feature available in the Wazuh Cloud deployment.
Wazuh firmographics
Firmographics- Name
- Wazuh
- Legal name
- Wazuh, Inc.
- Website
- https://wazuh.com
- Company type
- Private
- Founded year
- 2015
- Operating status
- Operating
- Headcount range
- 101–250 employees
- Short description
- Wazuh is an open-source unified XDR and SIEM platform providing endpoint and cloud workload protection via a universal agent and centralized analysis, indexing, and dashboard components. It serves enterprises, MSSPs, and public-sector organizations globally, monetizing through a hybrid open-core model combining free community software with paid Wazuh Cloud SaaS, professional support, consulting, and training.
- Ownership category
- akta.pro rank
Wazuh industry classification
Industry- Product category
- Security Information and Event Management (SIEM) and Extended Detection and Response (XDR)
- NAICS
- Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (5182), Computer Systems Design and Related Services (54151), Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (518)
- SIC
- Services-Computer Integrated Systems Design (7373), Services-Computer Programming, Data Processing, Etc. (7370), Services-Computer Programming Services (7371)
- akta.pro primary industry
- SIEM Platforms & Log Management (HDADAGAA)
- akta.pro secondary industries
- Unified Endpoint Management (UEM/MDM/MAM) Security (HDADAEAE), Cloud Security Logging, SIEM/SOAR & Threat Detection (HDABAHAL), Cloud Network Security (Microsegmentation, Cloud Firewall, WAF, DDoS) (HDABAHAJ)
Keywords
Where Wazuh is headquartered
LocationHeadquarters
- HQ city
- Campbell
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Wazuh business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Infrastructure, Marketing or Sales, Operations
Revenue model
- Open Source Platform: Free and open-source platform available at no cost, licensed under GNU GPL v2 and Apache License v2. This drives community adoption and ecosystem growth while creating conversion opportunities for paid services.
- Wazuh Cloud: Software as a Service (SaaS) offering providing managed, ready-to-use, and highly scalable cloud environments for security monitoring. Offers 14-day free trial with subscription-based pricing.
- Professional Support: Enterprise-grade support services for organizations requiring dedicated assistance with deployment, configuration, and ongoing operations.
- Consulting Services: Expert assistance for deployments and custom integrations tailored to specific organizational requirements.
- Training Courses: Official training programs for users and administrators to maximize platform utilization.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Others | Open Source - Free community edition |
| Subscription | Monthly | Wazuh Cloud - Managed SaaS |
| Subscription | Annual | Professional Support |
| One time/ perpetual license | Others | Training Courses |
Go-to-market motion4 records
Distribution channels9 records
Marketing channels8 records
Wazuh product offering
Product offeringCore offering
Wazuh provides an open-source unified security platform that combines SIEM and XDR capabilities for log data analysis, intrusion detection, endpoint security, vulnerability assessment, cloud security monitoring, and compliance reporting. The platform is available as a free self-managed open-source deployment and as Wazuh Cloud, a managed SaaS offering, with paid Professional Support, Consulting, and Training services layered on top.
Product overview
Wazuh is an open-source security platform that unifies XDR (Extended Detection and Response) and SIEM (Security Information and Event Management) capabilities into a single architecture. The platform consists of four core components: the Wazuh Agent (a universal lightweight multi-platform agent for endpoint protection), the Wazuh Server (central analysis engine that collects and processes data from agents), the Wazuh Indexer (for storing and searching security data), and the Wazuh Dashboard (for visualization and management). Wazuh also offers Wazuh Cloud as a SaaS deployment option. The platform provides comprehensive security capabilities including file integrity monitoring, malware detection, vulnerability detection, threat hunting, log data analysis, active response, container security, cloud security posture management, and regulatory compliance mapping (PCI DSS, GDPR, HIPAA, NIST 800-53, TSC). Key integrations include Amazon Security Lake, Elastic Stack, Splunk, OpenSearch, AWS, Azure, GCP, VirusTotal, YARA, Maltiverse, TheHive, Slack, PagerDuty, and Shuffle. The platform includes AI-powered features through the Wazuh AI Analyst for alert enrichment and threat investigation.
Differentiator
Problem solved
Functional benefit
Products and services
- Wazuh XDR
- Wazuh SIEM
- Wazuh Cloud
- Wazuh Professional Support
- Wazuh Consulting Services
- Wazuh Training Courses
Quantifiable outcome
- 15+ million protected endpoints globally
- +2 more outcomes
Companies that use Wazuh
Customer profileNamed customers16 records
Segments6 records
Ideal customer profiles2 records
Wazuh technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration20 records
AI capability5 records
Feature15 records
Wazuh partnerships and signals
Strategic signalPartnerships
13 partnerships are on record, tiered key integration partner, integration partner, cloud platform partner and legacy integration partner.
- Lumukey integration partnerStrategic partnership integrating Lumu's Maltiverse Threat Intelligence offering with Wazuh's open-source XDR and SIEM platform. The integration provides Wazuh users with automatic Indicators of Compromise (IOC) enrichment, faster threat investigations, and consolidated threat feeds to reduce false positives. Both companies' CEOs have cited the partnership as strengthening security capabilities for organizations worldwide.
- VirusTotalintegration partnerIntegration with VirusTotal for malware detection and threat intelligence, allowing users to leverage VirusTotal's database to inspect and identify malicious files.
- TheHiveintegration partnerIntegration with TheHive for security orchestration and case management, enabling automated workflows and incident response coordination.
- PagerDutyintegration partnerIntegration with PagerDuty for alert routing and incident management, enabling automated alerting and on-call escalation for security events.
- Slackintegration partnerIntegration with Slack for security alert notifications and team collaboration on security incidents.
- Shuffleintegration partnerIntegration with Shuffle for security orchestration and automation, enabling SOAR capabilities for Wazuh deployments.
- Amazon Web Services (AWS)cloud platform partnerNative cloud security monitoring for AWS environments including CloudTrail, GuardDuty, VPC Flow Logs, Security Hub, and other AWS services. Amazon Machine Images (AMI) available for deployment.
- Microsoft Azurecloud platform partnerNative cloud security monitoring for Azure environments including Azure Log Analytics, Microsoft Graph, and Azure Storage.
- Google Cloud Platform (GCP)cloud platform partnerNative cloud security monitoring for GCP environments including Google Cloud Pub/Sub and Google Cloud Storage.
- Elastic Stacklegacy integration partnerBackward compatibility with Elastic Stack for organizations with existing Elastic deployments. Support for forwarding data to Elastic indexers.
- OpenSearchintegration partnerNative integration with OpenSearch for indexing and searching security events. Wazuh's own indexer is OpenSearch-based.
- Splunkintegration partnerIntegration with Splunk for SIEM data forwarding and interoperability with Splunk environments.
- Amazon Security Lakeintegration partnerIntegration with Amazon Security Lake for standardized security data management using Open Cybersecurity Schema Framework (OCSF).
Scale indicators5 records
Recent moves6 records
Expansion highlights5 records
Wazuh competitors and assessment
Company assessmentBroad incumbents
- LogRhythm (now Exabeam):
- Splunk: Splunk (now part of Cisco) is the dominant commercial SIEM and observability platform. It competes directly with Wazuh's SIEM and log analysis capabilities but targets large enterprises with premium-priced licensing, whereas Wazuh attacks the cost-conscious and open-source-leaning segment.
- Microsoft Sentinel: Microsoft Sentinel is a cloud-native SIEM built on Azure that competes head-on with Wazuh in enterprise SIEM. Bundled with Microsoft 365 / Azure E5 and consumption-priced, it presents a structural challenge to Wazuh's cloud-neutral positioning.
- Google Chronicle (SecOps): Google Chronicle SecOps (formerly Chronicle SIEM) is a hyperscaler-backed SIEM/EDR platform. It targets the same enterprise customers as Wazuh with the backing of Google Cloud's scale, threat intelligence, and pricing flexibility, making it a direct competitor for multi-cloud and GCP-centric accounts.
- CrowdStrike Falcon: CrowdStrike Falcon LogScale and Falcon Insight deliver XDR/SIEM-style capabilities via a single lightweight agent — directly comparable to Wazuh's unified agent architecture. CrowdStrike targets the same enterprise endpoint security budgets but at premium pricing with a more mature go-to-market motion.
Direct peers
- Elastic: Elastic (Elastic Stack / Security) is the closest open-source-adjacent competitor to Wazuh, offering SIEM, log analysis, and endpoint security built on Elasticsearch. Wazuh even provides forwarder integrations into Elastic Stack, highlighting functional overlap and a competitive substitution dynamic.
- Graylog: Graylog is an open-source log management and SIEM platform that directly overlaps with Wazuh's log data analysis, threat hunting, and compliance use cases. It is frequently cited alongside Wazuh in open-source SIEM comparisons, serving similar mid-market and security-conscious customers.
- Sumo Logic: Sumo Logic is a SaaS log management and security analytics platform that overlaps with Wazuh SIEM in log ingestion, correlation, and compliance reporting. Both target cloud-forward enterprises, and Sumo Logic's Cloud SIEM product competes for the same budget line items.
Emerging players
- OpenSearch (AWS): OpenSearch is an open-source search and analytics suite forked from Elasticsearch that underpins both AWS OpenSearch Service and Wazuh's own indexer. It represents an ecosystem competitor for organizations building custom SIEMs and could either be a complement or substitute depending on customer architecture.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks5 records
Key highlights7 records
Customer concentration
Wazuh social profiles
Digital presenceWazuh compliance and trust
Trust signalCompliance5 records
Wazuh financial estimates
Financial estimateRevenue estimate
Valuation estimate
Wazuh leadership team
Management profileNumber of profiles
Profiles1 record
Wazuh funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Wazuh M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Wazuh
What does Wazuh do?
Wazuh provides an open-source unified security platform that combines SIEM and XDR capabilities for log data analysis, intrusion detection, endpoint security, vulnerability assessment, cloud security monitoring, and compliance reporting. The platform is available as a free self-managed open-source deployment and as Wazuh Cloud, a managed SaaS offering, with paid Professional Support, Consulting, and Training services layered on top.
Is Wazuh a public or private company?
Wazuh is a private company. It is classified as unknown and is currently operating.
When was Wazuh founded?
Wazuh was founded in 2015. It employs 101 to 250 people.
Where is Wazuh based?
Wazuh is headquartered in Campbell, United States, in the North America region.
How does Wazuh make money?
Five revenue lines are on record. Open Source Platform is the primary driver. The others are wazuh Cloud, professional Support, consulting Services and training Courses.
Who are Wazuh's main competitors?
Broad incumbents on record are LogRhythm (now Exabeam), Splunk, Microsoft Sentinel, Google Chronicle (SecOps) and CrowdStrike Falcon. Direct peers are Elastic, Graylog and Sumo Logic. OpenSearch (AWS) is listed as an emerging player.
Does Wazuh have an API?
Yes. Wazuh provides multiple RESTful APIs: (1) Wazuh Server API for configuring and managing the Wazuh platform, managing agents, security events, rules, decoders, and RBAC; (2) Wazuh Indexer API for managing data storage, indexing, re-indexing, and performance tuning; (3) Wazuh Cloud API for programmatically interacting with and managing Wazuh Cloud environments. The APIs support authentication, RBAC, and use Wazuh Query Language (WQL) for filtering data. Developer documentation is at documentation.wazuh.com/current/user-manual/api/index.html.
What industry is Wazuh in?
Wazuh's product category is Security Information and Event Management (SIEM) and Extended Detection and Response (XDR). Its primary akta.pro industry code is HDADAGAA, SIEM Platforms & Log Management, with a secondary code of HDADAEAE, Unified Endpoint Management (UEM/MDM/MAM) Security. Its NAICS code is 5182 and its SIC code is 7373.