7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

Wazuh

Open source

Wazuh is a free, open-source security platform combining XDR and SIEM capabilities for endpoints, servers and cloud workloads.

wazuh.com
Wazuh homepage screenshot
GitHub stars
17k
Last commit
today
Repository age
11 years
Version
v4.14.8
Licence
Custom
Self-hosted
Yes

About Wazuh

Wazuh is a free and open-source platform for threat prevention, detection and response. It protects workloads across on-premises, virtualized, containerized and cloud environments and combines XDR and SIEM functions in one product. The code is written mainly in C++.

The solution consists of an endpoint security agent installed on monitored systems and a management server that collects and analyzes the agents' data. It is integrated with the Wazuh Indexer, which offers a search engine and visualization for navigating security alerts. Agents scan for malware, rootkits and suspicious anomalies, read system and application logs, and monitor files for changes to content, permissions, ownership and attributes.

Rule-based analysis of collected logs, including data received from network devices through syslog, helps surface misconfigurations, policy violations and attempted or successful attacks. Repository topics also cover vulnerability detection, configuration assessment, incident response and compliance such as PCI DSS. The repository lists its license as 'Other', so review the license files for the exact terms.

Key features

  • Endpoint agents with a central management server
  • Intrusion and malware detection
  • Log data analysis with rule-based alerts
  • File integrity monitoring
  • Vulnerability detection and configuration assessment
  • Cloud and container workload coverage

Good fit for

  • →Security monitoring across servers and endpoints
  • →Supporting compliance audits such as PCI DSS
Built with
C++
Tags
siem
xdr
security
intrusion-detection
log-analysis
compliance
file-integrity-monitoring
incident-response

Wazuh: questions and answers

What is Wazuh used for?
Wazuh is a free, open-source security platform combining XDR and SIEM capabilities for endpoints, servers and cloud workloads. It is a good fit for security monitoring across servers and endpoints, and supporting compliance audits such as PCI DSS.
Is Wazuh open source?
Yes. Wazuh is open source under a custom licence. Its source code is on GitHub at wazuh/wazuh and is written mainly in C++.
Is Wazuh free?
Yes. Wazuh is open source, so the software itself is free to use under the terms of its own licence.
Can I self-host Wazuh?
Yes. Wazuh can be self-hosted on your own server or infrastructure.
What is Wazuh an alternative to?
Wazuh is an open-source alternative to Splunk, CrowdStrike, SentinelOne and Rapid7. Other open-source alternatives to Splunk include Security Onion and Graylog.
Is Wazuh actively maintained?
Yes. The most recent commit to Wazuh was on 2 October 2026, and the latest release is v4.14.8, published on 25 September 2026. The project has 17k stars on GitHub.

Open-source alternatives to Wazuh

See all

SaaS alternatives to Wazuh

See all