Overview
Wazuh is an open-source security platform where endpoint agents collect logs, file changes, software inventory, and configuration data for centralized analysis. Wazuh Indexer and Dashboard provide unified views for SIEM/XDR, file-integrity monitoring, vulnerability detection, configuration assessment, and compliance-oriented monitoring.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Collect logs, file changes, and inventory from endpoint agents
Agents gather operating-system and application logs, file-integrity events, software inventory, and configuration information for centralized rule-based analysis.
Unify SIEM/XDR, vulnerability, and compliance views
Security events are indexed and exposed through dashboards for vulnerability, FIM, configuration-assessment, and compliance-oriented investigations.
Sources: [2]
For centralized security monitoring across endpoints and cloud workloads
Wazuh fits organizations that want common telemetry and alert operations across servers, workstations, containers, and cloud instances.
Plan the multi-component architecture and major-version migrations
The solution includes agents plus manager/indexer/dashboard components. Current docs state that 4.x managers cannot be upgraded in place to 5.0, requiring fresh installation and restoration, so backups and migration planning matter.
Official sources
- [1]wazuh/wazuh repository(2026-09-20)
- [2]Wazuh README(2026-09-20)
- [3]Wazuh GPLv2 license and OpenSSL exception(2026-09-20)
- [4]Wazuh documentation(2026-09-20)
- [5]Wazuh 4.x to 5.x migration guide(2026-09-20)
Supplemental curator note
Wazuh is not a single-host scanner; endpoint agents feed a central management and indexing/dashboard stack. Current repository documentation states there is no in-place manager upgrade from 4.x to 5.0, requiring a fresh installation and restoration of customizations, so major-version migration planning is essential.
Try it in 3 steps
- 1
Review the official installation guide
Review server/indexer/dashboard and agent architecture, supported systems, and resource requirements.
https://documentation.wazuh.com/current/installation-guide/index.html - 2
Deploy a single-node lab instance
Start with an isolated VM rather than deploying immediately to production endpoints.
Follow the single-node installation path in the official guide - 3
Enroll one test agent
Add one endpoint you manage and verify logs, FIM, software inventory, and vulnerability views before wider rollout.
Enroll one test agent and verify it in the Wazuh Dashboard
Growth
Growth trends · Last 30 days
16,937 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 948
- Open PRs
- 194
- Issues opened
- 1,546
- Issues closed
- 1,362
- PRs opened
- 805
- PRs merged
- 683
Issues
1,546 / 1,362
Pull requests
805 / 683
Maintenance
- Median first response
- 3.6 hr
- Issue response rate
- 50% (25/50)
Based on up to the 100 newest issues opened by external users in the last 90 days. A first comment from an OWNER, MEMBER, or COLLABORATOR counts as a response; issues whose full comment history cannot be checked are excluded. The median and response rate update weekly.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- security
- compliance
- log-analysis
- vulnerability-detection
- cybersecurity
- file-integrity-monitoring
- infosec
- malware-detection
- cloud-security
- container-security
- security-automation
- security-tools
- Stars
- 16,937
- Forks
- 2,490
- Watchers
- 231
- Open issues
- 2,905
- Contributors
- 214
- Primary language
- C++
- License
- GPL-2.0-only
- Repository last updated
- Sep 20, 2026
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- Sherlock92,144 Stars
A Python OSINT CLI that checks username-based account candidates across social networks.
Python - Uptime Kuma91,570 Stars
A self-hosted monitoring tool for HTTP/TCP/DNS/Ping checks, notifications, and status pages.
JavaScript - Elasticsearch77,937 Stars
A distributed engine for full-text and vector search, analytics, logs, and metrics.
Java - Grafana76,812 Stars
An observability platform for visualizing metrics, logs, and traces from multiple sources and connecting them to alerts.
TypeScript - Prometheus66,130 Stars
A monitoring platform that pulls labeled time-series metrics and combines PromQL, rules, alerts, and service discovery.
Go
Report incorrect information
Tell us if any listing information is incorrect or outdated.