Description of Wazuh - The Open Source Security Platform
Wazuh is a free, open source and enterprise-ready security monitoring solution for threat detection, integrity monitoring, incident response and compliance.
I like that it's easy to configure rules in order to monitor my network devices (servers/applications).
It also has an API which makes integration with other tools very simple as well! There are some features missing such as support of SNMP v3 or OID resolution but this could be solved by adding more developers into its team so they can add these new functionalities themselves. We use wazer mainly because we want our servers monitored 24x7 without having too many alerts generated each day from
Pros
It has a great API which makes integration with other tools very simple
It's easy to install & configure with few clicks of mouse (it also supports ansible by default). Very fast in detecting threats from an external network or firewall/proxy servers. Free version offers limited number of rules which makes it unsuitable if you have too many users who are using your server as web proxy / gateway etc. If there should be only one rule set then I would highly recommend this product! You can use wazuh against any linux platform including cloud native environments like…
Pros
Easy installation
Great community support both for devs&endusers(you get very quick resolution)
great API that allows integration between products eg ntop +wazuhtransport+WAF