Both platforms collect logs, detect and investigate. They differ in what you pay for, who operates them and where the data sits. We run both, so this comparison is not written to make the more profitable one win.
If you would rather not read the rest.
If you have Microsoft 365 E5 and Defender across the business, choose Microsoft Sentinel. The integration is real rather than marketing, some Microsoft 365 data is ingested without a volume charge, and there is no cluster for you to run. If your estate is mixed, heavy on Linux and network gear, on a fixed budget, or under a hard data-residency requirement, choose Wazuh. One question decides it and it is not a technical one: who is going to operate the thing. Wazuh moves cost from licence to people. If you do not have those people and will not buy them, the saving never arrives and you end up with an unmaintained cluster instead of a SIEM.
The eleven differences that actually reach the table in a decision.
![]() | ![]() | |
|---|---|---|
| Licence | Open source, GPLv2. No licence fee. | Commercial Azure service. You pay for data processed. |
| What drives cost | Infrastructure and people. As log volume grows, storage cost grows linearly; the licence does not. | Volume ingested and how long it is retained, discounted by prepaid commitment. Cost grows with how much you collect. |
| Where it runs | Your infrastructure, on-premise or cloud, your choice. Operating it is on you or on a provider. | SaaS in Azure. Nothing to install and nothing to upgrade. |
| Where data sits | Wherever you build the cluster. Data-residency requirements are trivially answered. | In your chosen Azure region. Enough for most cases; not for some regulated ones. |
| Endpoint agent | Part of the platform: file integrity monitoring, CIS configuration assessment and vulnerability inventory at no extra charge. | Handled by Defender for Endpoint, licensed separately. Sentinel by itself has no endpoint agent. |
| Out-of-the-box analytics | A large rule library. Behavioural and higher-order correlation you build yourself. | Prebuilt analytics rules, UEBA and machine correlation across signals. The lead here is not close. |
| Microsoft 365 | Connected over API and Graph. It works, but it is extra work. | Native. Entra ID, Defender and Purview connect in a few clicks. |
| Detection format | Rules and decoders as XML and JSON files. Versioned in Git. | KQL queries. Also versionable, but they live in Azure. |
| Operational burden | Real. Cluster, indexer, index migrations, backups, upgrades. Wazuh is a production system and behaves like one. | Minimal. Microsoft operates the platform; you deal with content and cost. |
| Support | Community, documentation, and commercial support from Wazuh Inc. or from whoever operates it for you. | Contractual Microsoft support under your plan. |
| Leaving | Rules and decoders are readable files. You leave with them. | Detection is KQL, in Azure. Portable only as a concept. |
Every other difference can be worked around. This one cannot.
Microsoft Sentinel bills on the volume of data you send it and how long you keep it. There are cheaper tiers for high-volume low-value logs and discounts for prepaid commitment, so the cost is manageable. It is managed, however, by deciding to stop collecting something. That is the actual problem: the budget starts making the logging decisions instead of the threat model, and the first things cut are the high-volume sources such as DNS, proxy and firewall, which are precisely where lateral movement shows up first. Wazuh has no licence ceiling, so you collect what makes sense and pay for disks. You do pay for the people who keep the cluster alive. Check current Sentinel numbers in the Azure pricing calculator, because they vary by region and commitment, and any figure written here would be lying within six months.
Decided by the estate, not by preference.
Not a compromise. A split along the lines of what costs what.
In practice we rarely meet a clean deployment of either. Sentinel gets what it is irreplaceable at: signals from Microsoft 365, Entra ID and Defender, where integration is native and some data carries no volume charge. Wazuh gets the high-volume sources where per-gigabyte pricing would hurt, and the Linux estate, where you need an agent for file integrity and configuration assessment anyway. Correlation between them is solved at the SOC layer rather than the platform layer. It comes out cheaper than sending everything to Sentinel, and the coverage is wider than Wazuh alone.
We run both, so we have no reason to push one at the other's expense.
Straight answers to what clients ask us most.
Neither is better in general; the estate and the question of who will operate it decide. Wazuh is open source under GPLv2 with no licence fee and no charge for data volume, so it comes out ahead where log volume is high, budget is fixed, or data residency is constrained. Microsoft Sentinel comes out ahead where the business already has Microsoft 365 E5 and Defender: the integration is native, prebuilt analytics and UEBA are available immediately, and there is no cluster to run. Wazuh moves cost from licence to people, so without operational capacity or a provider the saving does not materialise.
Wazuh has no licence cost — you pay for infrastructure and people — while Microsoft Sentinel bills on the volume of data ingested and how long it is retained. Sentinel offers cheaper tiers for high-volume low-value logs and discounts for prepaid commitment, so cost is manageable, but it is managed by restricting what gets collected. With Wazuh, storage cost grows linearly with volume and the licence never does. Check current Sentinel pricing in the Azure pricing calculator, since it varies by region and commitment.
For collection, correlation, detection and inventory, yes; for out-of-the-box analytics, no. Wazuh additionally provides file integrity monitoring, CIS configuration assessment and vulnerability inventory inside the platform itself, which in the Microsoft world requires Defender for Endpoint licensed separately. Microsoft Sentinel, conversely, ships prebuilt analytics rules, UEBA and machine correlation across signals that you would have to build yourself in Wazuh. The difference is not what is possible but how much work it costs.
Yes, and it is the most common real-world arrangement. Sentinel takes signals from Microsoft 365, Entra ID and Defender, where integration is native and some data carries no volume charge. Wazuh takes high-volume sources such as DNS, proxy and firewall, where per-gigabyte billing would hurt, and the Linux estate, where you need an agent anyway. Correlation between the platforms is then handled at the SOC layer. It works out cheaper than sending everything to Sentinel, and coverage is wider than Wazuh alone.
Both platforms cover technical measures, but neither delivers compliance on its own. Act No. 264/2025 Coll. on cybersecurity, in force since 1 November 2025, requires among other things detection and recording of cybersecurity events, vulnerability management and configuration management, and both platforms perform those. The difference is where data sits and how long you keep it: the implementing decree expects 18 months of retention in the higher-impact regime, which under volume-based billing is a direct cost line. Organisational obligations and incident reporting to NÚKIB within the statutory windows are people and process. The Act is published in the Collection of Laws; guidance is issued by NÚKIB at nukib.gov.cz.
Wazuh, and not by a small margin. Wazuh is a production system you run yourself: the cluster, the OpenSearch-based indexer, index migrations, backups and upgrades. Microsoft Sentinel is SaaS — Microsoft operates the platform and you deal with detection content and cost. This line decides the question more often than any technical feature: the licence saving on Wazuh only means anything if you have the operational capacity or buy it as a service.
Tell us how many sources you have and what you already pay Microsoft. This can be worked out before anything is deployed.