ComparisonSIEM

    Wazuh vs. Microsoft Sentinel

    Both platforms collect logs, detect and investigate. They differ in what you pay for, who operates them and where the data sits. We run both, so this comparison is not written to make the more profitable one win.

    Verdict

    The short answer

    If you would rather not read the rest.

    If you have Microsoft 365 E5 and Defender across the business, choose Microsoft Sentinel. The integration is real rather than marketing, some Microsoft 365 data is ingested without a volume charge, and there is no cluster for you to run. If your estate is mixed, heavy on Linux and network gear, on a fixed budget, or under a hard data-residency requirement, choose Wazuh. One question decides it and it is not a technical one: who is going to operate the thing. Wazuh moves cost from licence to people. If you do not have those people and will not buy them, the saving never arrives and you end up with an unmaintained cluster instead of a SIEM.

    Comparison

    Point by point

    The eleven differences that actually reach the table in a decision.

    Point by point
    WazuhMicrosoft Sentinel
    LicenceOpen source, GPLv2. No licence fee.Commercial Azure service. You pay for data processed.
    What drives costInfrastructure and people. As log volume grows, storage cost grows linearly; the licence does not.Volume ingested and how long it is retained, discounted by prepaid commitment. Cost grows with how much you collect.
    Where it runsYour infrastructure, on-premise or cloud, your choice. Operating it is on you or on a provider.SaaS in Azure. Nothing to install and nothing to upgrade.
    Where data sitsWherever you build the cluster. Data-residency requirements are trivially answered.In your chosen Azure region. Enough for most cases; not for some regulated ones.
    Endpoint agentPart of the platform: file integrity monitoring, CIS configuration assessment and vulnerability inventory at no extra charge.Handled by Defender for Endpoint, licensed separately. Sentinel by itself has no endpoint agent.
    Out-of-the-box analyticsA large rule library. Behavioural and higher-order correlation you build yourself.Prebuilt analytics rules, UEBA and machine correlation across signals. The lead here is not close.
    Microsoft 365Connected over API and Graph. It works, but it is extra work.Native. Entra ID, Defender and Purview connect in a few clicks.
    Detection formatRules and decoders as XML and JSON files. Versioned in Git.KQL queries. Also versionable, but they live in Azure.
    Operational burdenReal. Cluster, indexer, index migrations, backups, upgrades. Wazuh is a production system and behaves like one.Minimal. Microsoft operates the platform; you deal with content and cost.
    SupportCommunity, documentation, and commercial support from Wazuh Inc. or from whoever operates it for you.Contractual Microsoft support under your plan.
    LeavingRules and decoders are readable files. You leave with them.Detection is KQL, in Azure. Portable only as a concept.
    Cost

    Cost is the whole argument

    Every other difference can be worked around. This one cannot.

    Microsoft Sentinel bills on the volume of data you send it and how long you keep it. There are cheaper tiers for high-volume low-value logs and discounts for prepaid commitment, so the cost is manageable. It is managed, however, by deciding to stop collecting something. That is the actual problem: the budget starts making the logging decisions instead of the threat model, and the first things cut are the high-volume sources such as DNS, proxy and firewall, which are precisely where lateral movement shows up first. Wazuh has no licence ceiling, so you collect what makes sense and pay for disks. You do pay for the people who keep the cluster alive. Check current Sentinel numbers in the Azure pricing calculator, because they vary by region and commitment, and any figure written here would be lying within six months.

    The decision

    Which, when

    Decided by the estate, not by preference.

    Choose Wazuh when

    • You run a lot of Linux, network gear or OT, where Microsoft covers nowhere near all of it.
    • Log volume is large and budget is fixed, so per-gigabyte pricing would eventually force you to stop collecting.
    • You are under a hard requirement about where data physically sits.
    • You want file integrity, configuration assessment and vulnerability inventory from one platform without a second licence.
    • You have the operational capacity, or you are buying it as a service.

    Choose Microsoft Sentinel when

    • You already have Microsoft 365 E5 and Defender across the business. The marginal cost is then far lower than the list price suggests.
    • The estate is predominantly Microsoft and identity lives in Entra ID.
    • You have nobody to run a cluster and do not intend to hire one.
    • You want ready-made analytics and cross-signal correlation now, not after three months of your own work.
    • You need contractual support from a single large vendor.
    In practice

    Most often, both

    Not a compromise. A split along the lines of what costs what.

    In practice we rarely meet a clean deployment of either. Sentinel gets what it is irreplaceable at: signals from Microsoft 365, Entra ID and Defender, where integration is native and some data carries no volume charge. Wazuh gets the high-volume sources where per-gigabyte pricing would hurt, and the Linux estate, where you need an agent for file integrity and configuration assessment anyway. Correlation between them is solved at the SOC layer rather than the platform layer. It comes out cheaper than sending everything to Sentinel, and the coverage is wider than Wazuh alone.

    Kybit

    What we do with this

    We run both, so we have no reason to push one at the other's expense.

    Wazuh deployment
    Cluster, indexer, agents and detection content are all code. One week to full operation, because every customer gets the same procedure with different parameters.
    Running Sentinel
    Analytics rules, noise tuning, playbooks, and above all cost control: what goes to the expensive tier, what goes to the cheap one, and what should not be collected at all.
    Monitoring either
    Alerts from either platform reach our analysts. Triage, separating noise from incident and containing the incident is the same work regardless of where the alert came from.
    Assessing what you have
    The usual brief is not greenfield. It is a platform that is running while nobody knows whether it catches anything. We start by finding out.
    FAQ

    Frequently asked questions

    Straight answers to what clients ask us most.

    Neither is better in general; the estate and the question of who will operate it decide. Wazuh is open source under GPLv2 with no licence fee and no charge for data volume, so it comes out ahead where log volume is high, budget is fixed, or data residency is constrained. Microsoft Sentinel comes out ahead where the business already has Microsoft 365 E5 and Defender: the integration is native, prebuilt analytics and UEBA are available immediately, and there is no cluster to run. Wazuh moves cost from licence to people, so without operational capacity or a provider the saving does not materialise.

    Wazuh has no licence cost — you pay for infrastructure and people — while Microsoft Sentinel bills on the volume of data ingested and how long it is retained. Sentinel offers cheaper tiers for high-volume low-value logs and discounts for prepaid commitment, so cost is manageable, but it is managed by restricting what gets collected. With Wazuh, storage cost grows linearly with volume and the licence never does. Check current Sentinel pricing in the Azure pricing calculator, since it varies by region and commitment.

    For collection, correlation, detection and inventory, yes; for out-of-the-box analytics, no. Wazuh additionally provides file integrity monitoring, CIS configuration assessment and vulnerability inventory inside the platform itself, which in the Microsoft world requires Defender for Endpoint licensed separately. Microsoft Sentinel, conversely, ships prebuilt analytics rules, UEBA and machine correlation across signals that you would have to build yourself in Wazuh. The difference is not what is possible but how much work it costs.

    Yes, and it is the most common real-world arrangement. Sentinel takes signals from Microsoft 365, Entra ID and Defender, where integration is native and some data carries no volume charge. Wazuh takes high-volume sources such as DNS, proxy and firewall, where per-gigabyte billing would hurt, and the Linux estate, where you need an agent anyway. Correlation between the platforms is then handled at the SOC layer. It works out cheaper than sending everything to Sentinel, and coverage is wider than Wazuh alone.

    Both platforms cover technical measures, but neither delivers compliance on its own. Act No. 264/2025 Coll. on cybersecurity, in force since 1 November 2025, requires among other things detection and recording of cybersecurity events, vulnerability management and configuration management, and both platforms perform those. The difference is where data sits and how long you keep it: the implementing decree expects 18 months of retention in the higher-impact regime, which under volume-based billing is a direct cost line. Organisational obligations and incident reporting to NÚKIB within the statutory windows are people and process. The Act is published in the Collection of Laws; guidance is issued by NÚKIB at nukib.gov.cz.

    Wazuh, and not by a small margin. Wazuh is a production system you run yourself: the cluster, the OpenSearch-based indexer, index migrations, backups and upgrades. Microsoft Sentinel is SaaS — Microsoft operates the platform and you deal with detection content and cost. This line decides the question more often than any technical feature: the licence saving on Wazuh only means anything if you have the operational capacity or buy it as a service.

    Not sure which comes out cheaper for you?

    Tell us how many sources you have and what you already pay Microsoft. This can be worked out before anything is deployed.