When the platform must stay on your infrastructure — Wazuh Professional Support keeps the deployment yours, on-premises or fully air-gapped, and makes the vendor contractually accountable for helping you run it. You keep the cluster. You stop being alone with it.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Data residency & processing — two different questions
Where data lives
Wherever you put it — including air-gapped
Manager, indexer and dashboard all run on your hardware, in your data centre or your own cloud account. You choose the jurisdiction and you can evidence it to an auditor. Offline installation and offline CVE feeds are documented, so a disconnected deployment stays genuinely supported.
The honest caveat
Control is not the same as compliance
Self-hosting lets you place the indexer correctly; it does not do it for you. Plenty of self-hosted deployments sit in a foreign cloud region because that is where the team already had capacity. Control is a precondition, not a substitute — and support does not audit your placement.
Processing follows storage here: decoding, correlation and indexing all happen on infrastructure you operate, so no third party reads your security telemetry. That is what makes this the answer for an IRDAI-regulated insurer, whose 2023 audit annexure asks as a yes/no whether ICT infrastructure logs are stored in India, and for RBI-regulated entities facing payment-data localisation. Note the nuance most vendors skip: CERT-In’s own May 2022 FAQ (Q35) does permit offshore storage where logs remain producible, so CERT-In alone rarely forces your hand — the sectoral rules do. If SaaS is acceptable to you, price Wazuh Cloud too; under 250 agents it is frequently the better answer.
Quick answer
This page covers Wazuh Professional Support — the self-hosted path. The alternative:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A support contract, not a product. You run the open-source Wazuh platform on your own infrastructure — on-premises, your own cloud tenancy, or fully air-gapped — and Wazuh becomes contractually accountable for helping you run it well.
What consolidation actually replaces, dimension by dimension.
| Dimension | No / separate AI tool | Wazuh (self-hosted) |
|---|---|---|
| Licence model | Per GB ingested, or per agent | GPLv2 — free core, no agent cap |
| What the meter punishes | Collecting more security data | Nothing — there is no meter |
| Feature tiering | Detection held back for higher tiers | Every tier runs the full platform |
| Detection logic | Proprietary correlation language | Plain-text decoders and rules you can read |
| Endpoint breadth | Log forwarding, endpoint sold separately | FIM, SCA, vuln detection in the core |
| Trial | Sales process first | 14 days, no card |
| Deployment | Often cloud-only | Cloud, self-hosted, or fully air-gapped |
| Honest caveat | — | Ops cost is real; no ML detections; tuning required |
The deployment-freedom answer — for the deepest out-of-the-box content, weigh Splunk (TechBag sells it).
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Every component runs on your hardware, in your data centre or your own cloud account, with no dependency on Wazuh's infrastructure and no mandatory vendor telemetry. That is the point of this product: nothing leaves your control, so the residency answer is yours to give rather than a vendor's to promise.
Packages and dependencies are downloaded on a connected host, transferred physically and installed from local storage. Wazuh documents this properly rather than treating it as an unsupported edge case, which matters because half-supported air-gap paths are where disconnected deployments quietly rot.
The vulnerability module can be fed CVE data offline, so detection continues in a disconnected network. This detail matters more than it sounds: a vulnerability module that silently stops updating gives false assurance, which is worse than having none at all.
SLAs, health checks, architecture and sizing guidance, upgrade planning, custom decoder, rule and dashboard development, and a named customer success manager. Wazuh helps you run it well. Wazuh does not run it, and does not watch it.
A structured review of cluster health, sizing headroom, retention posture and rule effectiveness. For teams whose Wazuh expertise sits with one or two people, this is often the most valuable line in the contract — it catches the drift nobody internally has time to look for.
You own upgrades, capacity, storage growth, availability and the 2am failure. Support shortens the time to an answer; it does not remove the job. Buyers who expected otherwise are the ones who end up unhappy, and it is entirely avoidable by reading this paragraph.
One workspace where people meet, make, and share — work moving in one place, not emailed between tools.
Sentinel collects, correlates and stores security telemetry — and the tier each table lands in is what sets your bill. Here are the five pieces that matter. Part of Defender XDR, managed in one portal, with Security Copilot AI.
Standard is 8/5 with an eight-hour response target; Premium is 24/7 on critical issues with a four-hour target. The distinction that matters operationally is not the hours but the coverage window — if your business runs outside 8/5 and an indexer failure at 2am is a real scenario, Standard's clock does not start until morning.
Cluster health, sizing headroom, retention posture and rule effectiveness, reviewed by people who do this daily. For teams where Wazuh knowledge sits with one or two individuals, this is frequently the highest-value item in the contract and the one buyers most underweight when comparing quotes.
Wazuh builds detection content for log sources your estate has and the out-of-the-box content does not cover — bespoke line-of-business applications, unusual appliances, India-specific systems. This is real engineering work included in the contract rather than a professional-services line item.
Getting indexer sizing and shard strategy right at the start avoids the most expensive class of self-hosted mistake, which is discovering at month nine that your cluster cannot hold the retention your regulator expects. Guidance up front is cheaper than a re-architecture later.
Major version upgrades on a distributed indexer cluster carrying live security data are the operation teams most often defer, and deferred upgrades are how you end up several versions behind with a CVE in your own SIEM. Having the vendor plan the path removes the excuse.
Offline installation and offline CVE feeds, documented and supported rather than tolerated. If you are air-gapped, this is the entire reason this product exists for you — and the reason the cloud-only SIEMs are not on your shortlist at any price.
One person who knows your environment, rather than a queue. Modest-sounding, and disproportionately useful the first time you have an incident and do not want to re-explain your architecture from scratch to whoever picks up the ticket.
Endpoint protection, XDR and Security Copilot.
The platform, explained by Wazuh.
What a major Wazuh release brings.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets Elastic Security apart (and where Splunk or Sentinel may fit better).
If your mandate rules out SaaS — RBI, SEBI or IRDAI expectations, contractual prohibitions on offshore security telemetry, or a genuine air-gap — then Cloud is not an expensive option, it is not an option. This is the same platform, under your control, with the vendor contractually accountable. That combination is rare: most SIEMs that go on-premises are expensive, and most that are cheap are cloud-only.
Self-hosting does not automatically satisfy a residency obligation — you still have to place the indexer in the right jurisdiction and be able to prove it. But it makes that answer yours rather than a vendor's promise. When IRDAI's audit annexure asks whether ICT infrastructure logs are stored in India, a self-hosted deployment lets you answer yes and show why.
Cloud tiers cap at 500 agents and price per agent. Self-hosted, your infrastructure grows with data volume and your engineering cost grows barely at all — the same person runs 500 agents or 5,000. Below roughly 250 agents the two paths cost about the same; well above 500, self-hosting pulls clearly ahead. Buy on where you will be in two years.
The most common self-hosted failure is not a dramatic outage. It is slow drift: retention quietly falling short of the obligation, shard strategy that stopped fitting the data, rules that stopped firing after a source changed format. Two or four structured reviews a year by people who do this daily is how that gets caught.
Worth restating because it reframes the negotiation: the licence remains GPLv2 and free. You are buying SLAs, expertise and accountability. If you conclude the support contract is not worth its price, you do not lose the platform — you keep running it, unsupported, exactly as before. Very few enterprise purchases leave you that fallback.
Write down precisely why SaaS is off the table — regulator, contract, or air-gap. If it turns out the objection is preference rather than obligation, price Wazuh Cloud too, because at under 250 agents it is frequently the better answer and you should know that before committing to run a cluster.
Infrastructure plus 0.3 to 0.5 FTE is the realistic steady state at 250 agents, heavier in year one. At ₹15 lakh CTC that is ₹4.5 to 7.5 lakh a year on top of ₹3.5 lakh of infrastructure. If you cannot name the person, you do not have the capacity, and no support contract substitutes for it.
Not on price. If a 2am indexer failure is a real scenario for your business, Standard's 8/5 clock does not start until morning and the four-hour Premium SLA is what you are actually buying. If your estate genuinely runs business hours, Standard is honest value.
Indexer sizing, shard strategy and retention posture set at the start are far cheaper than a re-architecture at month nine when the cluster cannot hold what your regulator expects. This guidance is in the contract — use it before deployment, not after.
Twice or four times a year, walk the reviewer through your retention obligation and your evidence for it. Teams that treat health checks as a compliance rehearsal rather than a technical courtesy get considerably more out of the contract.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We are air-gapped and that ruled out every cloud SIEM we looked at. This was the only shortlist entry that could go where we had to go and still had a vendor behind it.”
“The health checks found our retention was two weeks short of what our auditor expected. Nobody internally had the time to notice that.”
“Be clear with yourself that this is not managed. We still run the cluster and still carry the pager. Once we accepted that, the value was obvious.”
“Custom decoders for two of our line-of-business applications came as part of the contract rather than a separate services quote. That was not what we expected.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint-security (EDR/XDR) market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Free core, air-gap capable, real support behind it.
The grid nobody publishes — detection efficacy & agent maturity vs Microsoft-estate fit and TCO.
SIEM and XDR as one architecture, not two acquisitions.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
The SIEM field — honest lanes; the edge is deployment freedom and one agent for logs and endpoint. Deepest content and talent pool? Splunk. We say so (and sell it).
| Dimension | Wazuh | Elastic Security | ManageEngine Log360 | Microsoft Sentinel | Splunk Enterprise Security |
|---|---|---|---|---|---|
| Position | Open-source SIEM + XDR, free core | The closest relative — open-source-rooted | India-built commercial SIEM | SIEM for Microsoft estates | The reference SIEM |
| Pricing axis | Free licence; pay for Cloud tier or support | Subscription tier + resources | Per log source — predictable | Per GB ingested per day | Ingest or workload — historically costly |
| Does the meter discourage collecting? | No meter at all | Indirectly, via resource sizing | Only if you add sources | Directly — every GB costs | Directly, and expensively |
| Out-of-the-box completeness | FIM, SCA, vuln detection, active response in core | Split across tiers; free tier lacks endpoint agent | Strong on AD auditing, narrower elsewhere | Broad, but assembled from Azure services | Deepest content library in the category |
| Analytical depth | No ML detections; simpler query model | ML detections, powerful query language | UEBA included, moderate depth | KQL and strong ML | SPL — the deepest, if you invest |
| Air-gapped deployment | Documented offline install and offline CVE feeds | Fully self-managed | On-premises available | Microsoft-operated, cloud-only | Fully self-hosted available |
| India data residency | Self-hosted: yours to place. Cloud: no documented India region | Self-managed: yours to place | India-built; on-premises or India hosting | Azure India regions available | Self-hosted: yours to place |
| The thing to plan around | Ops cost is real; tuning effort in week one | You operate it unless you buy Cloud | Windows-centric strengths | Azure portal retires 31 Mar 2027 | Cisco integration reshaping roadmap |
| Best fit | Air-gap or residency mandates, high agent counts, mixed estates | Teams who will invest in analytical depth | Indian mid-market, Windows-heavy, minimal engineering | Microsoft-standardised estates | Engineers who will build with it |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Wazuh Professional Support is one of 30 SIEM & log management products TechBag carries. The SIEM & Log Management guide narrows them to a shortlist and shows the reasoning. →
Support pricing is bespoke and unpublished, so this does not guess at it. It sizes the number buyers systematically understate instead: what running Wazuh yourself costs before any support contract. The licence is genuinely zero. The infrastructure and the engineer are not, and the engineer is the line that decides this. Move the second slider honestly — 0.3 to 0.5 of an FTE is the realistic steady state, heavier in year one.
If you cannot name the person who will spend that time, you do not have the capacity, and no support contract substitutes for it. The worst outcome on this product is the organisation that self-hosted to save money, has nobody to run the cluster, and now pays for accountability while accumulating operational debt. Engineering costed at ₹15 lakh CTC; support is additional and quoted per environment.
There is no published list price and no per-agent rate card, which is a genuine structural disadvantage for you: you negotiate one of these perhaps every three years, and Wazuh negotiates them constantly. Two things worth holding onto. First, the licence underneath remains GPLv2 and free — you are pricing expertise and accountability, and if you walk away you keep the platform. Very few enterprise purchases leave you that fallback, and it is real leverage. Second, this contract is not your total cost: add infrastructure and the engineering fraction above. TechBag models the whole thing and quotes in INR with GST.
Business-hours operations
24/7 operations
Not optional extras
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Is SaaS ruled out by a regulator, a contract or an air-gap — or only by preference?
Have you confirmed this is support, not a managed service, and not MDR? You still carry the pager.
Can you name the person who will run the cluster, and the FTE fraction they can actually give it?
Is a 2am failure a real scenario? If so, Standard's 8/5 clock will not start until morning.
What is your agent count in two years? Above ~500, self-hosting economics pull clearly ahead.
Which jurisdiction will hold the indexer, and can you evidence that to an auditor?
Does your planned storage hold the full obligation, indexed where it must be searchable?
If disconnected, have you planned the offline CVE feed as well as the offline install?
There is no published price — who is negotiating this for you, and how often do they do it?
Understood that if you drop support you keep the platform? The licence is free either way.
Find out what you already run, work out which tier you actually need above the free one, or get an honest Elastic-vs-Splunk comparison — in INR/GST.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.