Talk to us
by WazuhTechBag Intel Page

Wazuh Cloud

No ingestion meter — Wazuh Cloud runs a platform whose core is free under GPLv2, so nothing about your bill discourages you from collecting the log that would have caught the intrusion. What you pay for is operation, not access.

Free GPLv2 core14-day trial, no cardManaged · air-gap needs self-hosting

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Licence cost
GPLv2 core — no agent cap, no feature paywall
Zero
Retention
tier-dependent; archive 3 months to 1 year
1–3 months hot
Deployment
air-gap needs the self-hosted path instead
Managed only
India residency
no published India region — confirm in writing
Undocumented

Data residency & processing — two different questions

Where data lives

Wazuh’s cloud — no documented India region

Wazuh does not publicly document an India hosting region for Wazuh Cloud, and we will not assert one exists. If Indian-jurisdiction storage is mandatory, settle this in writing BEFORE you trial. TechBag gets it confirmed as part of the quote.

Where it is processed

Wazuh operates the whole control plane

Decoding, correlation and indexing all run on Wazuh’s infrastructure. Your agents stay yours, but on the managed edition the reading of your logs is not something you host. Air-gap is therefore impossible by definition.

Be precise about which obligation binds you, because the strict reading is routinely oversold — including by vendors selling on-premises platforms, so weigh our incentive too. CERT-In’s April 2022 Directions require a rolling 180 days of ICT logs “within the Indian jurisdiction”, but CERT-In’s own May 2022 FAQ (Q35) permits storage outside India provided logs are producible in reasonable time — the hard in-India duty attaching to financial-transaction records. Where it genuinely bites is sectoral: IRDAI’s 2023 audit annexure asks, as a yes/no, whether ICT infrastructure logs are stored in India. If that is you, take the self-hosted path instead — see Wazuh Professional Support or Elastic Security. Get compliance to state which obligation applies, in writing, before shortlisting.

Quick answer

Wazuh Cloud is the managed edition of the open-source Wazuh platform: Wazuh runs the manager, indexer, dashboard, storage, upgrades and availability, and you simply deploy agents and use the console. The thing to understand first is that you are not buying features. The Wazuh core is free under GPLv2 with no agent cap and no feature paywall, and every Cloud tier runs identical capability — Small and Large differ only in how many agents they hold and how long they keep data. What the subscription buys is the removal of operational burden. Reported pricing runs about $571 a month for up to 100 agents (one month indexed, three months archive), about $923 for 250 agents (three months indexed, one year archive) and about $1,467 for 500 agents on the same retention, with custom terms above that. Standard support, PCI-DSS and SOC 2 attestation, threat intelligence and continuous updates are included at every tier, and there is a 14-day trial that needs no card — which is unusually honest for a SIEM, because it lets you measure alert volume on your real estate before a salesperson is involved. Two things buyers get wrong. First, retention forces the tier more often than agent count does: a 90-agent organisation fits Small on headcount but gets only one month of hot searchable data, so a 180-day obligation pushes it up a tier regardless. Second, the honest comparison is not against a hosting bill — the subscription folds infrastructure and operations together, so you must compare it against your infrastructure plus the engineering time self-hosting would consume. At Indian salaries and 250 agents those two numbers come out roughly level. The real limitation: Wazuh does not publicly document an India hosting region, so if your mandate requires Indian-jurisdiction storage, get that answered in writing before you trial — or self-host instead. Read more ↓ Show less ↑
Part 01 · Orient

The Microsoft platform family

This page covers Wazuh Cloud — the managed edition. The alternative:

Quick facts

30-second orientation
Product
Wazuh Cloud — the managed edition
Vendor
Wazuh — founder & CEO Santiago Bassett, bootstrapped since 2015
Category
Open-source SIEM and XDR, delivered as a managed service
Licence
GPLv2 core — free, no agent cap, no feature paywall
Priced on
Agent-count tier, all-in (infrastructure + operations)
Small
~$571/mo · 100 agents · 1 month indexed, 3 months archive
Medium
~$923/mo · 250 agents · 3 months indexed, 1 year archive
Large
~$1,467/mo · 500 agents · same retention as Medium
Feature difference by tier
None — every tier runs the full platform
Included
Standard support · PCI-DSS & SOC 2 · threat intel · updates
Trial
14 days, no credit card required
Watch this
Retention forces the tier more often than agent count does
Data residency
No publicly documented India region — confirm in writing
The honest limit
Managed means Wazuh's infrastructure; air-gap needs self-hosting
Not included
MDR — nobody watches your alerts for you
Buy in India via
TechBag — TCO modelling, INR invoicing, GST documentation
Part 02 · Learn

Understand SIEM economics before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is it?

The managed edition of an open-source SIEM and XDR platform. Agents on your endpoints ship logs, file-integrity events, inventory and configuration state to a manager that correlates them and an indexer that stores them — and Wazuh runs all of that for you.

A two-copy SIEM architecture vs Elastic’s — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionNo / separate AI toolWazuh Cloud
Licence modelPer GB ingested, or per agentGPLv2 — free core, no agent cap
What the meter punishesCollecting more security dataNothing — there is no meter
Feature tieringDetection held back for higher tiersEvery tier runs the full platform
Detection logicProprietary correlation languagePlain-text decoders and rules you can read
Endpoint breadthLog forwarding, endpoint sold separatelyFIM, SCA, vuln detection in the core
TrialSales process first14 days, no card
DeploymentOften cloud-onlyCloud, self-hosted, or fully air-gapped
Honest caveat—Ops cost is real; no ML detections; tuning required

The deployment-freedom answer — for the deepest out-of-the-box content, weigh Splunk (TechBag sells it).

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
What you keep control of

Agents

Your estate

A single lightweight agent per endpoint, server, container or cloud workload collects logs, file-integrity events, running processes, installed packages, users and groups. Agentless collection covers network devices. You install and control these regardless of where the manager runs.

02
Decode and correlate

Manager

Managed by Wazuh

Wazuh operates the manager that decodes raw logs into fields and correlates them against rules. This is the part you are actually buying — not features, but the fact that cluster sizing, upgrades and 2am failures become someone else's problem.

03
Store and search

Indexer

Managed by Wazuh

The search and storage layer holding processed events. Self-hosted, this is the component that consumes the most engineering effort; on Cloud it is invisible to you, which is precisely the value proposition.

04
Decoders and rules

Detection content

Included, and readable

Thousands ship out of the box, each mapped to MITRE ATT&CK, with continuous updates included. Both decoders and rules are plain files, so the logic stays inspectable and portable even on the managed edition — no proprietary correlation language you cannot read or take with you.

05
Indexed and archive

Retention

Two layers, per tier

Indexed retention is hot and directly searchable. Archive is colder, longer and not instantly queryable. Which one your obligation requires decides your tier: retaining logs is a different requirement from investigating across them.

06
The honest constraint

Region

Wazuh's infrastructure

Data sits on Wazuh's cloud in a region Wazuh selects. Wazuh does not publicly document an India region, and this is the question an Indian regulated buyer must settle before trialling rather than after.

One workspace where people meet, make, and share — work moving in one place, not emailed between tools.

Part 03 · Evaluate

Twelve capabilities. Draft, analyse, automate.

Sentinel collects, correlates and stores security telemetry — and the tier each table lands in is what sets your bill. Here are the five pieces that matter. Part of Defender XDR, managed in one portal, with Security Copilot AI.

Collect
Agent

One agent, genuinely mixed estates

Windows, Linux, macOS, Solaris, AIX and HP-UX from one agent, plus containers and cloud workloads. For an Indian estate running a Windows domain, a rack of RHEL, some legacy AIX and a growing Kubernetes footprint, one agent covering all of it removes an integration tax that appears in every competitor's implementation quote.

Collect
FIM

File integrity monitoring

Continuous watching of critical files and registry keys for unauthorised change, in the free core rather than sold as a module. PCI-DSS requirement 11.5 asks for exactly this, and buyers routinely budget separately for it before discovering it is already included.

Detect
Rules

Detection logic you can read

Decoders parse raw log lines into named fields; rules turn those fields into alerts with a severity and a MITRE ATT&CK mapping. Both are plain text you can open, audit and edit. When an auditor asks how an alert was produced, you can show them the file.

Detect
VulnDet

Vulnerability detection without scans

The agent maintains a package inventory per endpoint and correlates it against CVE feeds, so you get vulnerability visibility without authenticated network scanning and without a separate scanner licence.

Detect
SCA

Configuration assessment against CIS

Scans endpoints against hardening benchmarks continuously and reports drift, rather than telling you once a year at audit time that a server had been misconfigured for eleven months.

Respond
Response

Active response

Automated action on the endpoint when a rule fires — blocking an IP, disabling an account, quarantining a file. Included in the core, with the usual caveat that automated response should be staged carefully before it acts on production.

Respond
Compliance

Built-in compliance mappings

PCI-DSS, HIPAA, NIST 800-53, GDPR and TSC mappings with dashboards to evidence them. Read these as reporting aids rather than a compliance guarantee — no product makes you compliant.

See it, don’t just read it

Watch Microsoft Defender in action

Endpoint protection, XDR and Security Copilot.

Wazuh (official)·Overview

Wazuh — the open source security platform

The platform, explained by Wazuh.

Wazuh (official)·Release

Introducing Wazuh 4.8

What a major Wazuh release brings.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Unified Defense SIEM

AI works best where the work already happens.

Here’s what genuinely sets Elastic Security apart (and where Splunk or Sentinel may fit better).

01

The licence is free, and always will be

This is not a trial, a community edition or a crippled tier. GPLv2 covers the whole platform: no per-agent charge, no ingestion metering, no feature paywall. You could run Wazuh across ten thousand endpoints and pay Wazuh nothing, legitimately and with the vendor's blessing. Cloud exists because operating a distributed indexer well is a real job, not because the software is being withheld from you.

02

No ingestion meter changes what you collect

Per-GB SIEM pricing quietly turns every logging decision into a budget decision, and the predictable result is that teams stop collecting the sources that would have caught the intrusion. Removing the meter removes that pressure. This is the strongest argument for Wazuh and it is structural rather than promotional — the incentive simply is not there.

03

Identical capability at every tier

There is no enterprise edition holding back the features you will eventually need. Small runs what Large runs. You size on agents and retention, and you are never upsold a detection capability you had assumed was already yours.

04

A trial that tells you the truth

Fourteen days, no card, no sales process. Point real production log sources at it and measure the alert volume on your actual estate. Very few SIEM vendors let you evaluate honestly before engaging their sales team, and the ones that do tend to be confident in what you will find.

05

Bootstrapped, with no exit pressure

Wazuh has taken no VC funding since 2015. For a platform you are betting your detection stack on, the absence of investor pressure toward a licence change or an acquisition is worth something — buyers who lived through other open-core vendors relicensing will understand exactly why.

In the apps
Where people already work
Bundled in E5
Enterprise EDR, no extra seat
Grounded
In your M365 data
Proof, not promises

The numbers behind the platform

15M+ endpoints
Protected worldwide (vendor-reported)
Wazuh
100000+
Enterprise organisations using Wazuh
Wazuh
$571/mo
Small tier, up to 100 agents (reported)
Pricing
14 days
Free trial, no credit card required
Wazuh
0 agent cap
GPLv2 core — no per-agent licence at any scale
Licensing
365 days archive
Retention on Medium and Large tiers
Wazuh

What your Wazuh Cloud rollout looks like

Week 1Assess

Count agents, then check retention

Total endpoints, servers, containers and cloud workloads needing an agent. Then — before matching that to a tier — write down your retention obligation. Retention forces the tier upward more often than agent count does, and discovering that after budgeting is the commonest sizing mistake on this product.

Week 1Assess

Settle residency before you invest time

If your mandate requires Indian-jurisdiction storage, get Wazuh's hosting region confirmed in writing before the trial. If the answer does not work, the self-hosted path with Professional Support is the same platform under your control — and you have not wasted the evaluation.

Weeks 2–4Trial

Run the 14-day trial on real sources

No card required, so there is no reason to trial against a lab. Point genuine production sources at it and measure two things: how much noise arrives in week one, and whether the detections that fire are the ones you wanted. Both predict tuning effort better than any demo.

Weeks 3–5Evaluate

Price it against self-hosting honestly

Compare the subscription against infrastructure plus the fraction of an engineer self-hosting consumes — not against a hosting bill alone. At 250 agents and Indian salaries the two land close together, so the decision turns on spare platform capacity, not on which is cheaper.

Weeks 6–12Deploy

Tune, with a named owner

Every SIEM is noisy in week one and Wazuh's collection breadth makes it noisier than most. Deployments fail here far more often than on technology. Name the owner and allocate the weeks before you sign, not after the alerts start being ignored.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.5
105+ reviews*
88% would recommend
Value for money4.8
Out-of-the-box completeness4.6
Deployment flexibility4.5
Analytical depth3.7
5
58%
4
30%
3
8%
2
3%
1
1%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Financial Services
It does considerably more out of the box than the price suggests. File integrity and configuration assessment were line items we had budgeted separately and did not need.
Head of Security Operations
Financial Services
IT Services
Week one was noisy — genuinely noisy. Week five, after we gave someone the time to tune it properly, it was the most useful thing in our stack.
SOC Manager
IT Services
Manufacturing
We trialled it against real production sources without talking to a salesperson first. That alone put it ahead of two vendors we had shortlisted.
IT Director
Manufacturing
Healthcare
The documentation gets thin once you are past a standard deployment and into custom decoders. We got there, but it took longer than planned.
Infrastructure Lead
Healthcare
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint-security (EDR/XDR) market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Endpoint-Security (EDR/XDR) Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
WazuhThis page

Free core, air-gap capable, real support behind it.

Grid 02 · The architecture

In-App Integration × Estate Breadth

The grid nobody publishes — detection efficacy & agent maturity vs Microsoft-estate fit and TCO.

Point appsBest-of-breed suiteLegacy office suitesHeavy enterprise platforms
WazuhThis page

SIEM and XDR as one architecture, not two acquisitions.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Wazuh Cloud vs the field

The SIEM field — honest lanes; the edge is deployment freedom and one agent for logs and endpoint. Deepest content and talent pool? Splunk. We say so (and sell it).

DimensionWazuhElastic SecurityManageEngine Log360Microsoft SentinelSplunk Enterprise Security
PositionOpen-source SIEM + XDR, free coreThe closest relative — open-source-rootedIndia-built commercial SIEMSIEM for Microsoft estatesThe reference SIEM
Pricing axisFree licence; pay for Cloud tier or supportSubscription tier + resourcesPer log source — predictablePer GB ingested per dayIngest or workload — historically costly
Does the meter discourage collecting?No meter at allIndirectly, via resource sizingOnly if you add sourcesDirectly — every GB costsDirectly, and expensively
Out-of-the-box completenessFIM, SCA, vuln detection, active response in coreSplit across tiers; free tier lacks endpoint agentStrong on AD auditing, narrower elsewhereBroad, but assembled from Azure servicesDeepest content library in the category
Analytical depthNo ML detections; simpler query modelML detections, powerful query languageUEBA included, moderate depthKQL and strong MLSPL — the deepest, if you invest
Air-gapped deploymentDocumented offline install and offline CVE feedsFully self-managedOn-premises availableMicrosoft-operated, cloud-onlyFully self-hosted available
India data residencySelf-hosted: yours to place. Cloud: no documented India regionSelf-managed: yours to placeIndia-built; on-premises or India hostingAzure India regions availableSelf-hosted: yours to place
The thing to plan aroundOps cost is real; tuning effort in week oneYou operate it unless you buy CloudWindows-centric strengthsAzure portal retires 31 Mar 2027Cisco integration reshaping roadmap
Best fitAir-gap or residency mandates, high agent counts, mixed estatesTeams who will invest in analytical depthIndian mid-market, Windows-heavy, minimal engineeringMicrosoft-standardised estatesEngineers who will build with it
Strong Partial / add-on Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Does Wazuh Cloud fit you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Wazuh Cloud if…

  • You want the platform without running a distributed indexer cluster yourself
  • An ingestion meter is currently shaping what you collect, and you want that pressure gone
  • Your estate is genuinely mixed — Windows, Linux, AIX, containers — and one agent covering all of it saves real integration work
  • You would otherwise have to hire the platform engineer self-hosting needs

Choose Wazuh Professional Support instead if…

  • Your mandate rules out SaaS, or you need a genuine air-gap
  • You are above roughly 500 agents and per-agent tiers have stopped making sense
  • You already run the platform capability and want accountability, not operation

Choose Elastic Security if…

  • You want machine-learning-driven detections, which Wazuh does not have
  • Your team will invest in a more powerful query language and go deeper
  • You want an open-source-rooted platform with a paid tier that scales analytically

Choose ManageEngine Log360 if…

  • You are Indian mid-market, mostly Windows, with no platform engineer to spare
  • Per-log-source pricing is more predictable for you than anything volume-based
  • Indian support, Indian invoicing and Indian time zones matter operationally

Choose Microsoft Sentinel if…

  • You are standardised on Microsoft 365 E5 and Defender
  • First-party Microsoft logs arriving free changes your economics

Wazuh Cloud is one of 30 SIEM & log management products TechBag carries. The SIEM & Log Management guide narrows them to a shortlist and shows the reasoning. →

Do the math

Cloud, or self-hosted? Count the engineer.

Wazuh has no ingestion meter, so the question is never how much you collect. It is who operates this. The Cloud subscription is all-in — infrastructure and operations both sit inside it — so the only fair comparison is against your own infrastructure plus the fraction of an engineer self-hosting actually consumes. Anyone who compares the subscription to a hosting bill alone concludes self-hosting saves lakhs; it does not, at this scale. Move the second slider honestly, and note that 0% is not an available answer — a distributed indexer cluster does not run itself. Indicative Indian-market rates, not a quote.

250
252,000
40%
10% of an FTEa full FTE

The slider people get wrong is the second one. 0.3 to 0.5 of an engineer is the honest steady state at a few hundred agents — cluster health, upgrades, storage growth, rule tuning and being reachable when it breaks — and year one runs heavier. If you cannot name the person who will spend that time, you do not have the capacity, and the self-hosted column is fiction. Engineering costed at ₹15 lakh CTC; adjust for your market.

Wazuh Cloud, per year
₹9,19,308
All-in: infrastructure and operations included
Self-hosted, per year
₹11,00,000
₹5,00,000 infrastructure + ₹6,00,000 engineering
Cloud is cheaper by ₹1,80,692 a year on these inputs.
Turn this into a real quote →
Pricing & plans

Three tiers, one platform

Reported pricing, indicative and worth confirming at quote. The structural point most buyers miss: there is no feature difference between the tiers. Small runs exactly what Large runs. You are sizing on agent capacity and retention, and nothing else — there is no enterprise edition holding back the detection you will need later. The trap is that retention forces the tier more often than agent count does: a 90-agent organisation fits Small on headcount but gets one month of indexed data, so a 180-day obligation pushes it up regardless. Read the retention column first. Every tier includes Standard support, PCI-DSS and SOC 2 attestation, threat intelligence and continuous updates. TechBag quotes in INR with GST.

Small

~$571/month

Up to 100 agents

  • 1 month indexed, 3 months archive
  • The full platform — no features held back
  • Watch this: one month indexed is tight for a real retention obligation

Medium

~$923/month

Up to 250 agents — ₹9.2 lakh/yr

  • 3 months indexed, 1 year archive
  • Identical capability to Small and Large
  • Where most retention obligations actually land you

Large

~$1,467/month

Up to 500 agents

  • Same retention as Medium
  • Above 500 agents the terms are custom
  • Past this point, self-hosting economics start to win

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every SIEM vendor

Take this into your next vendor call — including ours.

1
Sizing

What is your agent count today, and realistically in eighteen months? Tiers cap at 100, 250 and 500.

2
Retention

How many days must you hold — and must they be searchable, or merely retained and producible on request?

3
Tier

Which tier does that retention force, independent of your agent count?

4
Residency

Is Indian-jurisdiction storage mandatory for you, and do you have Wazuh's region answer in writing?

5
Deployment

Does any regulator or contract rule out SaaS entirely? If so, price Professional Support instead.

6
Capacity

What is your genuine spare platform-engineering capacity, counted in FTE fractions rather than good intentions?

7
Ownership

Who is the named owner for detection tuning, and how many weeks have they been given?

8
Trial

Which production log sources will you point at the trial? A lab tells you nothing about your real noise.

9
Baseline

What do you spend on the SIEM this would replace, including its ingestion overages?

10
Scope

Do you need someone watching your alerts and responding? Wazuh does not sell MDR at all.

FAQ

Questions buyers ask

No, and this is the most common misunderstanding about Wazuh, so it is worth being blunt. The free core is not a limited edition. There is no per-agent charge, no ingestion metering and no feature paywall — the detection engine, compliance mappings, vulnerability detection, file integrity monitoring, configuration assessment and active response are all in the GPLv2 core. You can deploy Wazuh across ten thousand endpoints and pay Wazuh nothing, legitimately and with the vendor's blessing. Cloud is not an unlock. What Cloud sells is operation: Wazuh runs the manager, the indexer, the storage, the upgrades and the availability, so you deploy agents and use a console instead of running a distributed search cluster. That is why the pricing is structured around agent count and retention rather than features or data volume — you are buying the removal of a job, not access to software. Every tier runs identical capability; Small and Large differ only in agent capacity and how long data is kept. The practical consequence is that your decision is never 'free version or paid version'. It is 'who operates this'. If you have a platform team with genuine spare capacity, self-hosting the free core is a legitimate answer that we will happily tell you to take. If you do not, Cloud is what you are actually buying, and the honest question is whether its price beats the engineer you would otherwise need.

Ready to evaluate Wazuh Cloud?

Find out what you already run, work out which tier you actually need above the free one, or get an honest Elastic-vs-Splunk comparison — in INR/GST.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.