Elastic Security vs Wazuh: Which SIEM Fits Your SMB in 2026?
Elastic Security vs Wazuh compared on pricing, detection method, MSP fit, and total cost of ownership for a 50-endpoint SMB deployment in 2026.
Long Nguyen
Développeur fullstack · Ingénieur IA · Chercheur
Elastic Security vs Wazuh: The Short Answer
Elastic Security and Wazuh solve the same problem — collecting log and endpoint data, correlating it against threat indicators, and giving a security team a place to investigate — but they start from opposite licensing philosophies. Wazuh is fully open source (GPLv2) with no paid license tier at all; you only pay if you want Wazuh's own managed hosting. Elastic Security is open code wrapped in a commercial subscription: a genuinely free Basic tier exists, but the features most SMBs actually want — machine-learning anomaly detection, Elastic Defend endpoint response actions — sit behind paid tiers.
| Aspect | Elastic Security | Wazuh |
|---|---|---|
| License model | Free self-managed Basic tier; paid tiers (Standard/Gold/Platinum/Enterprise) unlock ML and advanced endpoint features | Fully open source (GPLv2), no paid license, ever |
| Deployment options | Self-managed, Elastic Cloud Hosted, Elastic Cloud Serverless | Self-hosted (on-prem or your own cloud), or managed Wazuh Cloud |
| Underlying data store | Elasticsearch + Kibana | Wazuh indexer — an open-source fork of OpenSearch — plus an OpenSearch Dashboards-based UI |
| Primary detection method | Prebuilt detection rules; ML-based anomaly detection on Platinum/Enterprise | Signature-based rules and decoders correlated against known indicators of compromise |
| Entry-level paid price | From $99/mo, Elastic Cloud Hosted Standard (resource-based, not per-endpoint) | $0 self-hosted; from $571/mo for Wazuh Cloud's Small tier (up to 100 agents) |
| Endpoint agent | Elastic Defend: malware prevention, host data collection, response actions | Wazuh agent: file integrity monitoring, configuration assessment, vulnerability detection, active response |
| Best fit | Teams already standardized on the Elastic Stack, or that need ML-driven behavioral detection | Budget-constrained SMBs and MSPs with the engineering capacity to run open-source infrastructure |
That table is the summary. The rest of this guide works through pricing, small-business fit, MSP considerations, and what "detection rate" claims actually mean before either platform lands on an endpoint.
How Each Platform Is Actually Built
Elastic Security
Elastic Security runs on top of the Elastic Stack: Elasticsearch stores and indexes the data, Kibana is the UI, and the Security app layers a detection engine, case management, and (on paid tiers) an endpoint agent called Elastic Defend on top. The detection engine ships prebuilt rules mapped to MITRE ATT&CK, and — starting at the Platinum tier — unsupervised machine-learning jobs that flag statistical outliers in the indexed data rather than only matching known signatures. You can self-manage the whole stack for free (Basic license), or let Elastic run it for you on Elastic Cloud Hosted or the newer Elastic Cloud Serverless, which bills ingest and storage separately instead of provisioning fixed nodes.
Wazuh
Wazuh is built from three components. The agent installs on the endpoint (Windows, Linux, macOS, plus HP-UX, Solaris, and AIX) and handles local collection: log forwarding, file integrity monitoring, configuration assessment, and active response actions. The server receives that data, runs it through a rule and decoder engine, correlates it against known indicators of compromise, and scales horizontally as a cluster when agent counts grow into the hundreds or thousands. The Wazuh indexer — an open-source fork of OpenSearch, not Elasticsearch — stores the resulting alerts and serves the OpenSearch Dashboards-based web UI. Because Wazuh forked away from the Elastic-owned stack, there's no Elastic license dependency anywhere in a self-hosted Wazuh deployment.
Deploying and tuning either stack well — writing custom decoders, wiring up integrations, or standing up a properly sized Elastic Cloud or self-hosted Wazuh cluster — is full-lifecycle engineering work, not a weekend install, especially once you're feeding it real production log volume.
Elastic Security vs Wazuh Pricing
Neither vendor prices per-endpoint the way commercial EDR tools usually do, which is exactly why pricing comparisons here get confusing.
| Tier | Elastic Security (Elastic Cloud Hosted) | Wazuh (Wazuh Cloud) |
|---|---|---|
| Free / open source | Basic self-managed license: core log ingestion, Kibana dashboards, prebuilt detection rules — no ML, no LDAP/SAML SSO, no cross-cluster replication | Entire platform, self-hosted: agent, server, indexer, dashboard, active response, FIM, vulnerability detection — no feature paywall |
| Entry paid tier | Standard, from $99/mo — resource-based (compute + storage for a small cluster), not headcount-based | Wazuh Cloud Small, from $571/mo flat — up to 100 active agents, one month indexed retention, three months archive |
| Mid tier | Gold (~$114/mo) adds reporting and third-party alerting; Platinum (~$131/mo) adds ML anomaly detection and cross-cluster replication | Wazuh Cloud Medium, from $923/mo — up to 250 agents |
| Top tier | Enterprise (~$184/mo starting) adds Endpoint Security and SOAR workflows | Wazuh Cloud Large, from $1,467/mo — up to 500 agents; custom quotes above that |
The practical difference: Elastic's tiers are a feature gate layered on top of resource-based consumption, so your bill grows with data volume and retention, not seat count. Wazuh Cloud's tiers are agent-count bands — a flat price whether you're running 40 agents or 100, because the ceiling is what's metered, not the volume of logs those agents generate.
Elastic Security vs Wazuh for Small Business
For an SMB with a handful of IT staff and no dedicated security engineer, the honest starting point is Wazuh's free self-hosted tier or Elastic's free Basic tier — both give you real detection coverage at zero license cost. The difference shows up in what you're giving up to stay free:
- Elastic Basic (self-managed, free): full Kibana visualization and prebuilt detection rules, but no ML-based anomaly detection and no Elastic Defend response actions — you're running a SIEM without the EDR half.
- Wazuh (self-hosted, free): the full platform, including active response and vulnerability detection, but you own 100% of the operational burden — patching the indexer, tuning rules, and keeping the cluster healthy.
Once an SMB decides it wants someone else holding the pager for infrastructure, the paid paths diverge sharply in shape: Elastic's Standard Cloud tier at $99/mo is a genuinely low entry point but doesn't include the endpoint response features most buyers actually want (those require Enterprise, ~$184/mo starting, and the bill still climbs with log volume). Wazuh Cloud's Small tier is a flat $571/mo regardless of whether you have 20 endpoints or 100 — more expensive up front, but the number doesn't move as you add hosts within that band.
Elastic Security vs Wazuh for MSPs
MSPs weighing either platform run into the same question from two different angles: how much control do you actually get once someone else is hosting it? Wazuh Cloud documents this explicitly — it's a managed service with intentional guardrails for multi-tenant safety: dashboard-only access, no direct CLI or shell access to the underlying infrastructure, and the Server and Indexer APIs disabled by default (read-only access can be requested through support, but write operations to the indexer API aren't permitted at all). That's a reasonable trade-off for a single client, but MSPs who want to write custom decoders, automate onboarding across many tenants, or integrate deeply with their own tooling usually end up self-hosting Wazuh instead, precisely because the free, fully open-source core comes with no equivalent restriction.
Elastic doesn't publish a distinct MSP multi-tenancy product either — most MSPs running Elastic Security for clients provision separate Elastic Cloud organizations or self-managed clusters per client, since Elastic's resource-based billing means costs are already isolated by cluster. The practical trade-off is the same one SMBs face, just multiplied across accounts: Wazuh keeps license cost at zero no matter how many client deployments you stand up, while Elastic's per-cluster resource billing means margin depends on how tightly you can control ingest volume for every client on the book.
Elastic Security vs Wazuh Detection Rates
Searches for "detection rates" on this comparison usually expect a benchmark percentage, and it's worth being direct about why one doesn't reliably exist: neither Elastic Security nor Wazuh currently publishes results from a standardized, independent efficacy test comparable to the MITRE ATT&CK Evaluations that commercial EDR vendors submit endpoint agents to. What you'll find instead on review sites are user-satisfaction scores (G2, PeerSpot) — useful for gauging day-to-day usability, but not a measure of how many real attack techniques each platform actually catches.
What can be compared honestly is detection method, which drives detection coverage:
- Wazuh is signature- and rule-based end to end: its decoder and rule engine matches collected data against known indicators of compromise and MITRE ATT&CK-mapped rule sets. That's deterministic and auditable — you can read exactly why an alert fired — but it only catches what a rule was written for.
- Elastic Security's Basic tier is architecturally similar: prebuilt, signature-style detection rules. The differentiator only appears on Platinum and Enterprise, where unsupervised ML jobs score behavioral anomalies against a statistical baseline, which can surface novel attack patterns a static rule set would miss — at the cost of more tuning to keep false positives manageable.
The practical takeaway: if your team can write and maintain good detection rules, Wazuh's free rule engine and Elastic Basic perform comparably. The gap opens specifically around behavioral/anomaly detection, and only if you're paying for Elastic's higher tiers to get it.
Total Cost of Ownership for a 50-Endpoint SMB Deployment
Fifty endpoints is a common inflection point for SMBs — too many to eyeball manually, not yet big enough for a dedicated security hire. Here's how the real cost drivers stack up, not just list price:
| Cost driver | Wazuh (self-hosted) | Wazuh Cloud | Elastic Security (Cloud Hosted) |
|---|---|---|---|
| License/subscription | $0 | $571/mo flat (Small tier covers up to 100 agents — you don't save money for having fewer than 100) | From $99/mo (Standard) to ~$184/mo+ (Enterprise, for Elastic Defend response actions) — resource-based, not agent-based |
| Infrastructure | You provision and pay for the server/indexer hosts directly | Included in the subscription | Included, but scales with data volume and retention — the biggest lever on the actual bill |
| Engineering/ops time | Highest — you own cluster health, patching, and rule tuning | Low — Wazuh manages infra; you still tune rules and triage alerts | Low-to-moderate — Elastic manages infra; ML tuning adds ongoing work if you're on Platinum/Enterprise |
| What moves the bill up | Nothing (license is fixed at $0); only your infra spend grows | Crossing the 100-agent ceiling into the Medium tier ($923/mo) | Log volume, retention window, and adding the endpoint-response tier |
For 50 endpoints specifically, self-hosted Wazuh is the cheapest path on paper, but that's only true if someone on the team has the platform-engineering time to keep a production cluster healthy — otherwise the "free" license gets absorbed by hours nobody budgeted for. Wazuh Cloud's flat $571/mo is straightforward to forecast because it doesn't move with log volume. Elastic Security's real cost for 50 endpoints depends entirely on how much you log and for how long you retain it — the $99/mo headline price is honest for a small Standard-tier cluster, but it doesn't include the endpoint response capability most buyers actually came for.
So, Which Is Better: Elastic Security or Wazuh?
Neither wins outright — the honest answer depends on which resource is scarcer for you: budget, or engineering time.
- Choose Wazuh if you have (or can build) the in-house capacity to run open-source infrastructure and want to keep license cost at zero indefinitely, regardless of how many endpoints or client deployments you add.
- Choose Elastic Security if you're already running the Elastic Stack for logging or observability and want security folded into the same platform, or if ML-based behavioral detection is worth paying Enterprise-tier pricing for.
- Choose a managed option over self-hosting either one if your team's time is worth more than the subscription — Wazuh Cloud's flat agent-band pricing is easier to forecast than Elastic's volume-based bill, but Elastic's entry price is lower if you can keep data volume and retention tight.
If you're still weighing which shape of that trade-off actually fits your environment, a short, no-cost conversation is usually faster than another week of spec-reading — get a free AI-visibility and infrastructure consultation from Netalith to talk through the real numbers for your setup.
FAQ
Questions fréquentes
What is the main difference between Elastic Security and Wazuh?
Wazuh is fully open source (GPLv2) with no paid license tier, ever — you only pay if you use Wazuh's managed cloud hosting. Elastic Security has a free self-managed Basic tier, but machine-learning-based anomaly detection and the Elastic Defend endpoint agent's response actions sit behind paid subscription tiers.
Is Wazuh really free?
The core platform — agent, server, indexer, and dashboard — is genuinely free and open source under GPLv2 with no feature paywall. The only cost for self-hosting is your own infrastructure and the engineering time to run it. Wazuh Cloud, the managed hosting option, is a separate paid subscription starting at $571/month.
Can I run Elastic Security for free?
Yes, using Elastic's self-managed Basic license, which includes log ingestion, Kibana dashboards, and prebuilt detection rules at no cost. It excludes machine-learning anomaly detection, LDAP/SAML single sign-on, and cross-cluster replication, which require a paid tier.
Which is better for a 50-endpoint SMB, Elastic Security or Wazuh?
It depends on which resource is scarcer: self-hosted Wazuh is cheapest on paper but requires in-house platform-engineering time; Wazuh Cloud is a predictable flat $571/month for up to 100 agents; Elastic Security starts cheaper at $99/month but that price excludes endpoint response features and grows with log volume and retention.
Do MSPs prefer Elastic Security or Wazuh?
MSPs that want deep customization across many tenants — custom decoders, automated onboarding — tend to prefer self-hosting Wazuh, since it carries no license cost regardless of client count. Wazuh Cloud intentionally restricts CLI and API access for multi-tenant safety, and Elastic doesn't publish a distinct MSP multi-tenancy product, so most MSPs on Elastic provision separate clusters per client instead.