We stand Wazuh up and get it running in one week. Deployment goes through Terraform and Ansible, detection rules live in a versioned repository, and agents roll out in bulk. After that we can take it into round-the-clock monitoring.
An open platform for detection that combines SIEM and XDR behind a single agent.
Wazuh is an open-source security platform licensed under GPLv2. It combines SIEM and XDR: it collects logs and telemetry from agents on endpoints and servers, evaluates them against rulesets, watches file integrity, detects vulnerabilities and checks configuration against CIS benchmarks. Data lands in its own indexer built on OpenSearch. The licence is free, so you pay for infrastructure and for the people who operate the platform.
The whole deployment is described as code. Every customer gets the same procedure with different parameters, which is why it can be planned in days.
Terraform stands up the cluster, the indexer and the network; Ansible finishes the configuration.
Indexer sizing, sharding and retention are set against the volume you give us.
Bulk agent rollout across Windows, Linux and macOS through your endpoint management.
Firewalls, cloud and network gear are onboarded over syslog and API.
We deploy our rule library mapped to MITRE ATT&CK and add decoders for your applications.
Rules and decoders live in a versioned repository and ship through the same pipeline as the rest of the infrastructure.
We work through the first wave of alerts, silence the noise, and set up Active Response and ticketing integration.
By the end of the week the platform is running and sending what it should.
That is the platform. If you also want a 24/7 team managing it, SOC and MDR onboarding takes 14 days, adding the threat model, deeper tuning and the live SOC portal. SOC & MDR
The two things that separate a one-week deployment from a quarter-long project.
Installation finishes in minutes. This is the work that makes the platform catch anything.
Who looks at the alerts at three in the morning.
We can both build Wazuh and watch it around the clock. Alerts reach our analysts, who triage, separate noise from incident and contain the incident. The platform stays yours: it runs in your infrastructure or in ours, whichever suits you, and its data goes nowhere else. If you end the engagement you keep Wazuh along with the detection content we wrote for it, repository included.
It does not fit everything. Where it fits, the cost difference is decisive.
Straight answers to what clients ask us most.
Wazuh is an open-source security monitoring platform that combines SIEM and XDR capabilities. It is released under GPLv2, so there are no licence fees and no charge for data volume. It collects logs and telemetry through agents on endpoints and servers, evaluates them against rulesets, monitors file integrity, detects vulnerabilities and checks configuration against CIS benchmarks. Source code and documentation are public at documentation.wazuh.com.
The software itself is free; the cost is infrastructure and work. Because deployment runs through Terraform and Ansible, that work is short and predictable. Price is driven by agent count, the number of agentless sources, the retention period you need, and whether you operate the platform yourself or we take over monitoring. Because Wazuh does not bill per gigabyte, cost does not step up as log volume grows the way it does with commercial SIEMs. We scope the specifics against your environment.
One week to full operation. Days 1 to 2 build the cluster, indexer and network with Terraform and Ansible; days 3 to 4 roll out agents and onboard agentless sources; day 5 deploys detection content and decoders for your applications; days 6 to 7 tune the noise and hand over. It holds because deployment and detection are both code, so every customer gets the same procedure with different parameters. If you also want a 24/7 team managing it, SOC and MDR onboarding takes 14 days and adds the threat model, deeper tuning and the live SOC portal.
Wazuh covers a substantial part of the technical measures but does not deliver compliance on its own. Act No. 264/2025 Coll. on cybersecurity, in force since 1 November 2025, together with its implementing decrees, requires among other things detection and recording of cybersecurity events, vulnerability management and configuration management. Wazuh performs those specific functions. The organisational obligations, incident reporting to NÚKIB within the statutory windows, and evidencing that the measures actually work, are people and process rather than tooling. The Act is published in the Collection of Laws; guidance is issued by NÚKIB at nukib.gov.cz.
For most mid-sized environments yes; for some, no. Wazuh covers collection, correlation, detection and inventory with no licence ceiling, so it pays off where data volume is high and budget is fixed. Commercial platforms offer broader ready-made integrations, more advanced behavioural analytics, and vendor support with a contractual response time. The deciding factor is who operates it: Wazuh moves cost from licence to people, and if you do not have those people the saving does not materialise.
Yes, and it is more common than a greenfield build. We start with an assessment of the current state: what it collects, what is tuned, what the retention is, and how many alerts a day nobody reads. That produces a list of what needs finishing before a shift is worth switching on. If we find the platform only needs tuning and you can watch it yourselves, we will say so.
Tell us what state it is in. If it only needs tuning, we will say so.