No ingestion meter — Wazuh Cloud runs a platform whose core is free under GPLv2, so nothing about your bill discourages you from collecting the log that would have caught the intrusion. What you pay for is operation, not access.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Data residency & processing — two different questions
Where data lives
Wazuh’s cloud — no documented India region
Wazuh does not publicly document an India hosting region for Wazuh Cloud, and we will not assert one exists. If Indian-jurisdiction storage is mandatory, settle this in writing BEFORE you trial. TechBag gets it confirmed as part of the quote.
Where it is processed
Wazuh operates the whole control plane
Decoding, correlation and indexing all run on Wazuh’s infrastructure. Your agents stay yours, but on the managed edition the reading of your logs is not something you host. Air-gap is therefore impossible by definition.
Be precise about which obligation binds you, because the strict reading is routinely oversold — including by vendors selling on-premises platforms, so weigh our incentive too. CERT-In’s April 2022 Directions require a rolling 180 days of ICT logs “within the Indian jurisdiction”, but CERT-In’s own May 2022 FAQ (Q35) permits storage outside India provided logs are producible in reasonable time — the hard in-India duty attaching to financial-transaction records. Where it genuinely bites is sectoral: IRDAI’s 2023 audit annexure asks, as a yes/no, whether ICT infrastructure logs are stored in India. If that is you, take the self-hosted path instead — see Wazuh Professional Support or Elastic Security. Get compliance to state which obligation applies, in writing, before shortlisting.
Quick answer
This page covers Wazuh Cloud — the managed edition. The alternative:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
The managed edition of an open-source SIEM and XDR platform. Agents on your endpoints ship logs, file-integrity events, inventory and configuration state to a manager that correlates them and an indexer that stores them — and Wazuh runs all of that for you.
What consolidation actually replaces, dimension by dimension.
| Dimension | No / separate AI tool | Wazuh Cloud |
|---|---|---|
| Licence model | Per GB ingested, or per agent | GPLv2 — free core, no agent cap |
| What the meter punishes | Collecting more security data | Nothing — there is no meter |
| Feature tiering | Detection held back for higher tiers | Every tier runs the full platform |
| Detection logic | Proprietary correlation language | Plain-text decoders and rules you can read |
| Endpoint breadth | Log forwarding, endpoint sold separately | FIM, SCA, vuln detection in the core |
| Trial | Sales process first | 14 days, no card |
| Deployment | Often cloud-only | Cloud, self-hosted, or fully air-gapped |
| Honest caveat | — | Ops cost is real; no ML detections; tuning required |
The deployment-freedom answer — for the deepest out-of-the-box content, weigh Splunk (TechBag sells it).
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
A single lightweight agent per endpoint, server, container or cloud workload collects logs, file-integrity events, running processes, installed packages, users and groups. Agentless collection covers network devices. You install and control these regardless of where the manager runs.
Wazuh operates the manager that decodes raw logs into fields and correlates them against rules. This is the part you are actually buying — not features, but the fact that cluster sizing, upgrades and 2am failures become someone else's problem.
The search and storage layer holding processed events. Self-hosted, this is the component that consumes the most engineering effort; on Cloud it is invisible to you, which is precisely the value proposition.
Thousands ship out of the box, each mapped to MITRE ATT&CK, with continuous updates included. Both decoders and rules are plain files, so the logic stays inspectable and portable even on the managed edition — no proprietary correlation language you cannot read or take with you.
Indexed retention is hot and directly searchable. Archive is colder, longer and not instantly queryable. Which one your obligation requires decides your tier: retaining logs is a different requirement from investigating across them.
Data sits on Wazuh's cloud in a region Wazuh selects. Wazuh does not publicly document an India region, and this is the question an Indian regulated buyer must settle before trialling rather than after.
One workspace where people meet, make, and share — work moving in one place, not emailed between tools.
Sentinel collects, correlates and stores security telemetry — and the tier each table lands in is what sets your bill. Here are the five pieces that matter. Part of Defender XDR, managed in one portal, with Security Copilot AI.
Windows, Linux, macOS, Solaris, AIX and HP-UX from one agent, plus containers and cloud workloads. For an Indian estate running a Windows domain, a rack of RHEL, some legacy AIX and a growing Kubernetes footprint, one agent covering all of it removes an integration tax that appears in every competitor's implementation quote.
Continuous watching of critical files and registry keys for unauthorised change, in the free core rather than sold as a module. PCI-DSS requirement 11.5 asks for exactly this, and buyers routinely budget separately for it before discovering it is already included.
Decoders parse raw log lines into named fields; rules turn those fields into alerts with a severity and a MITRE ATT&CK mapping. Both are plain text you can open, audit and edit. When an auditor asks how an alert was produced, you can show them the file.
The agent maintains a package inventory per endpoint and correlates it against CVE feeds, so you get vulnerability visibility without authenticated network scanning and without a separate scanner licence.
Scans endpoints against hardening benchmarks continuously and reports drift, rather than telling you once a year at audit time that a server had been misconfigured for eleven months.
Automated action on the endpoint when a rule fires — blocking an IP, disabling an account, quarantining a file. Included in the core, with the usual caveat that automated response should be staged carefully before it acts on production.
PCI-DSS, HIPAA, NIST 800-53, GDPR and TSC mappings with dashboards to evidence them. Read these as reporting aids rather than a compliance guarantee — no product makes you compliant.
Endpoint protection, XDR and Security Copilot.
The platform, explained by Wazuh.
What a major Wazuh release brings.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets Elastic Security apart (and where Splunk or Sentinel may fit better).
This is not a trial, a community edition or a crippled tier. GPLv2 covers the whole platform: no per-agent charge, no ingestion metering, no feature paywall. You could run Wazuh across ten thousand endpoints and pay Wazuh nothing, legitimately and with the vendor's blessing. Cloud exists because operating a distributed indexer well is a real job, not because the software is being withheld from you.
Per-GB SIEM pricing quietly turns every logging decision into a budget decision, and the predictable result is that teams stop collecting the sources that would have caught the intrusion. Removing the meter removes that pressure. This is the strongest argument for Wazuh and it is structural rather than promotional — the incentive simply is not there.
There is no enterprise edition holding back the features you will eventually need. Small runs what Large runs. You size on agents and retention, and you are never upsold a detection capability you had assumed was already yours.
Fourteen days, no card, no sales process. Point real production log sources at it and measure the alert volume on your actual estate. Very few SIEM vendors let you evaluate honestly before engaging their sales team, and the ones that do tend to be confident in what you will find.
Wazuh has taken no VC funding since 2015. For a platform you are betting your detection stack on, the absence of investor pressure toward a licence change or an acquisition is worth something — buyers who lived through other open-core vendors relicensing will understand exactly why.
Total endpoints, servers, containers and cloud workloads needing an agent. Then — before matching that to a tier — write down your retention obligation. Retention forces the tier upward more often than agent count does, and discovering that after budgeting is the commonest sizing mistake on this product.
If your mandate requires Indian-jurisdiction storage, get Wazuh's hosting region confirmed in writing before the trial. If the answer does not work, the self-hosted path with Professional Support is the same platform under your control — and you have not wasted the evaluation.
No card required, so there is no reason to trial against a lab. Point genuine production sources at it and measure two things: how much noise arrives in week one, and whether the detections that fire are the ones you wanted. Both predict tuning effort better than any demo.
Compare the subscription against infrastructure plus the fraction of an engineer self-hosting consumes — not against a hosting bill alone. At 250 agents and Indian salaries the two land close together, so the decision turns on spare platform capacity, not on which is cheaper.
Every SIEM is noisy in week one and Wazuh's collection breadth makes it noisier than most. Deployments fail here far more often than on technology. Name the owner and allocate the weeks before you sign, not after the alerts start being ignored.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“It does considerably more out of the box than the price suggests. File integrity and configuration assessment were line items we had budgeted separately and did not need.”
“Week one was noisy — genuinely noisy. Week five, after we gave someone the time to tune it properly, it was the most useful thing in our stack.”
“We trialled it against real production sources without talking to a salesperson first. That alone put it ahead of two vendors we had shortlisted.”
“The documentation gets thin once you are past a standard deployment and into custom decoders. We got there, but it took longer than planned.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint-security (EDR/XDR) market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Free core, air-gap capable, real support behind it.
The grid nobody publishes — detection efficacy & agent maturity vs Microsoft-estate fit and TCO.
SIEM and XDR as one architecture, not two acquisitions.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
The SIEM field — honest lanes; the edge is deployment freedom and one agent for logs and endpoint. Deepest content and talent pool? Splunk. We say so (and sell it).
| Dimension | Wazuh | Elastic Security | ManageEngine Log360 | Microsoft Sentinel | Splunk Enterprise Security |
|---|---|---|---|---|---|
| Position | Open-source SIEM + XDR, free core | The closest relative — open-source-rooted | India-built commercial SIEM | SIEM for Microsoft estates | The reference SIEM |
| Pricing axis | Free licence; pay for Cloud tier or support | Subscription tier + resources | Per log source — predictable | Per GB ingested per day | Ingest or workload — historically costly |
| Does the meter discourage collecting? | No meter at all | Indirectly, via resource sizing | Only if you add sources | Directly — every GB costs | Directly, and expensively |
| Out-of-the-box completeness | FIM, SCA, vuln detection, active response in core | Split across tiers; free tier lacks endpoint agent | Strong on AD auditing, narrower elsewhere | Broad, but assembled from Azure services | Deepest content library in the category |
| Analytical depth | No ML detections; simpler query model | ML detections, powerful query language | UEBA included, moderate depth | KQL and strong ML | SPL — the deepest, if you invest |
| Air-gapped deployment | Documented offline install and offline CVE feeds | Fully self-managed | On-premises available | Microsoft-operated, cloud-only | Fully self-hosted available |
| India data residency | Self-hosted: yours to place. Cloud: no documented India region | Self-managed: yours to place | India-built; on-premises or India hosting | Azure India regions available | Self-hosted: yours to place |
| The thing to plan around | Ops cost is real; tuning effort in week one | You operate it unless you buy Cloud | Windows-centric strengths | Azure portal retires 31 Mar 2027 | Cisco integration reshaping roadmap |
| Best fit | Air-gap or residency mandates, high agent counts, mixed estates | Teams who will invest in analytical depth | Indian mid-market, Windows-heavy, minimal engineering | Microsoft-standardised estates | Engineers who will build with it |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Wazuh Cloud is one of 30 SIEM & log management products TechBag carries. The SIEM & Log Management guide narrows them to a shortlist and shows the reasoning. →
Wazuh has no ingestion meter, so the question is never how much you collect. It is who operates this. The Cloud subscription is all-in — infrastructure and operations both sit inside it — so the only fair comparison is against your own infrastructure plus the fraction of an engineer self-hosting actually consumes. Anyone who compares the subscription to a hosting bill alone concludes self-hosting saves lakhs; it does not, at this scale. Move the second slider honestly, and note that 0% is not an available answer — a distributed indexer cluster does not run itself. Indicative Indian-market rates, not a quote.
The slider people get wrong is the second one. 0.3 to 0.5 of an engineer is the honest steady state at a few hundred agents — cluster health, upgrades, storage growth, rule tuning and being reachable when it breaks — and year one runs heavier. If you cannot name the person who will spend that time, you do not have the capacity, and the self-hosted column is fiction. Engineering costed at ₹15 lakh CTC; adjust for your market.
Reported pricing, indicative and worth confirming at quote. The structural point most buyers miss: there is no feature difference between the tiers. Small runs exactly what Large runs. You are sizing on agent capacity and retention, and nothing else — there is no enterprise edition holding back the detection you will need later. The trap is that retention forces the tier more often than agent count does: a 90-agent organisation fits Small on headcount but gets one month of indexed data, so a 180-day obligation pushes it up regardless. Read the retention column first. Every tier includes Standard support, PCI-DSS and SOC 2 attestation, threat intelligence and continuous updates. TechBag quotes in INR with GST.
Up to 100 agents
Up to 250 agents — ₹9.2 lakh/yr
Up to 500 agents
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
What is your agent count today, and realistically in eighteen months? Tiers cap at 100, 250 and 500.
How many days must you hold — and must they be searchable, or merely retained and producible on request?
Which tier does that retention force, independent of your agent count?
Is Indian-jurisdiction storage mandatory for you, and do you have Wazuh's region answer in writing?
Does any regulator or contract rule out SaaS entirely? If so, price Professional Support instead.
What is your genuine spare platform-engineering capacity, counted in FTE fractions rather than good intentions?
Who is the named owner for detection tuning, and how many weeks have they been given?
Which production log sources will you point at the trial? A lab tells you nothing about your real noise.
What do you spend on the SIEM this would replace, including its ingestion overages?
Do you need someone watching your alerts and responding? Wazuh does not sell MDR at all.
Find out what you already run, work out which tier you actually need above the free one, or get an honest Elastic-vs-Splunk comparison — in INR/GST.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.