Wazuh vs Elastic SIEM – Open Source Security Monitoring Compared
Security Information and Event Management (SIEM) platforms are the backbone of any serious security operation, collecting logs and alerts from across your infrastructure so you can detect and respond to threats. When you begin comparing open source options, two names come up again and again: Wazuh and Elastic SIEM (Elastic Security). Both are powerful, both are heavily used, and both trace deeper roots to the same Elasticsearch ecosystem. But they differ in a way that matters a lot to open source purists: their licensing. This guide breaks down how they compare on price, licensing, features, and ease of deployment.
Wazuh
Wazuh is a free, fully open source security platform that unifies Extended Detection and Response (XDR) and SIEM in a single solution. It is distributed under the GNU General Public License v2 (GPLv2), making it genuinely open source with no license cost and no vendor lock-in.
Wazuh is built from three core components: the Wazuh indexer (a highly scalable full-text search and analysis engine that stores and indexes alerts), the Wazuh server (which manages agents, analyzes data through decoders and rules, and applies threat intelligence), and the Wazuh agent (a lightweight, multi-platform component deployed on endpoints). Its capabilities span log analysis, file integrity monitoring, threat detection and rootkit hunts, vulnerability detection, security configuration assessment, regulatory compliance dashboards (PCI DSS, HIPAA, GDPR), and monitoring for cloud workloads across AWS, Azure, and GCP as well as Docker and Kubernetes environments.
Because everything ships in one unified agent and platform architecture, Wazuh gives small teams a surprisingly complete detection-and-response stack out of the box, with an active-response mechanism that can remediate on the device itself.
Elastic SIEM (Elastic Security)
Elastic SIEM is the security application built on top of the Elastic Stack (Elasticsearch, Kibana, and the Elastic Agent). It is one of the most widely deployed SIEM platforms in the world and offers a generous free tier: the free Basic level includes core SIEM detection rules, the Elastic Common Schema, Elasticsearch, Logstash, and basic Kibana dashboards.
The important caveat is licensing. Since the 7.11 release in 2021, Elastic moved its Elasticsearch and Kibana source code away from Apache 2.0 to a dual license under the Server Side Public License (SSPL) and Elastic License 2.0 (ELv2). Neither is OSI-approved open source, and the default distribution ships under ELv2 — described by Elastic as “source-available” rather than open source. In 2024 Elastic added AGPLv3 as an option for parts of the source code, but the default distribution remains under ELv2.
Beyond the free Basic tier, features are gated behind paid subscriptions: Gold, Platinum, and Enterprise tiers unlock capabilities like advanced alerting, machine learning jobs, and — at the Enterprise level — integrated endpoint security and SOAR. For SIEM users, the free tier is genuinely usable for core detection, but the premium detection logic, alerting connectors, and endpoint agent require an Elastic subscription.
Head-to-Head Comparison
Licensing
- Wazuh: Fully open source under GPLv2. Free to use, modify, and distribute; no license fees.
- Elastic SIEM: Default distribution under Elastic License 2.0 (source-available, not OSI open source); core free, premium features behind Gold/Platinum/Enterprise subscriptions.
Price
- Wazuh: $0 license cost. You pay only for your own infrastructure and engineering. A managed Wazuh Cloud option also exists if you prefer to offload operations.
- Elastic SIEM: Free Basic tier for core SIEM; Gold, Platinum, and Enterprise tiers cost a monthly subscription per cluster (roughly $99–$184+/month depending on tier on Elastic Cloud, plus infrastructure).
Deployment Model
- Wazuh: Single unified agent + server + indexer architecture; self-hosted by default, with an optional managed cloud service.
- Elastic SIEM: Runs on the Elastic Stack with the Elastic Agent / Fleet; can be self-hosted or consumed on Elastic Cloud.
Detection & Response
- Wazuh: Built-in threat detection rules, rootkit detection, file integrity monitoring, security configuration assessment, active response with on-device remediation, threat intelligence and VirusTotal integration.
- Elastic SIEM: Core SIEM detection rules in the free tier; machine learning, advanced alerting connectors, and the integrated endpoint (EDR) agent require paid tiers.
Compliance
- Wazuh: Purpose-built compliance dashboards for PCI DSS, HIPAA, GDPR, and other standards.
- Elastic SIEM: Can support compliance workflows, but the out-of-the-box compliance mapping is less of a headline feature than Wazuh’s dedicated module.
Which One Should You Pick?
Choose Wazuh if: you want a genuinely open source platform (GPLv2) with no license costs, a self-hosted unified agent, built-in compliance dashboards, active response, and cloud/container monitoring without paying for endpoint security as an add-on. It is the better fit if keeping the whole stack free and open is a hard requirement.
Choose Elastic SIEM if: you already run the Elastic Stack for observability, you are comfortable with the Elastic License 2.0 terms, and you are willing to pay for a subscription to unlock machine learning, advanced alerting, and the enterprise endpoint agent. Its free Basic tier is a good starting point for core SIEM detection.
The Bottom Line
For the open source community, Wazuh is the more faithful open source choice — a complete XDR + SIEM platform under GPLv2 with no license fees and no gatekeeping of its response and compliance features. Elastic SIEM is extremely capable and its free tier is genuinely useful, but its default distribution is source-available rather than open source, and the features that truly round out a detection-and-response deployment live behind a paid subscription.
If you are drawn to the Elastic stack’s search and visualization power but want a fully open source stack, look at OpenSearch, the community-driven Apache 2.0 fork of Elasticsearch that keeps the query engine open while Wazuh handles the security layer on top.
Download Wazuh at wazuh.com — free, no subscriptions, no account required.
Looking for more security tooling? Browse our Wazuh listing in the directory, or explore more free software in the Security category.