# Splunk Enterprise Security vs Wazuh

| Attribute | Splunk Enterprise Security | Wazuh |
|---|---|---|
| **Vioscale score** | 53.9 (30% (low)) | 43 (64% (medium)) |
| activity.commits_last_30d | - | 100 |
| adoption.dependent_repos | - | 0 |
| adoption.github_stars | - | 16,689 |
| deployment.options | `{"cloud":true,"hybrid":true,"self_hosted":true}` | `{"cloud":true,"hybrid":true,"on_prem":true,"self_hosted":true}` |
| description.long | An integrated security operations platform combining SIEM, SOAR, and behavior analytics capabilities with AI-driven threat detection and automated response. It enables security teams to reduce false alerts, accelerate investigations, and respond faster to threats across their infrastructure. | Unified XDR and SIEM platform that analyzes security data across endpoints, clouds, and networks to detect threats, respond to incidents, and ensure compliance. |
| features.capabilities | `{"siem":true,"soar":true,"ueba":true,"deployment":"hybrid","ml_detection":true,"threat_intel":false,"case_management":true,"connector_breadth":"2,000+ integrations via Splunkbase","open_core_available":false,"mitre_attack_mapping":false}` | `{"siem":true,"soar":true,"deployment":"hybrid","threat_intel":true,"case_management":true,"connector_breadth":"Cloud and endpoint integrations including AWS services and threat intelligence f","open_core_available":true,"mitre_attack_mapping":true}` |
| integrations.count | 2,000 | 3 |
| integrations.list | - | `[{"name":"Amazon Security Lake"},{"name":"AWS Inspector"},{"name":"AWS SQS"}]` |
| language.primary | - | C++ |
| market.availability | `{"primaryMarkets":["US"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` | `{"hqCountry":"US","primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | `{"web":true}` | `{"cli":true,"mac":true,"web":true,"linux":true,"windows":true}` |
| pricing | `{"type":"subscription","summary":"Multiple pricing models available (entity-based per host, workload-based per compute, or ingest-based per GB/day). 9% annual uplift on renewals. Contact sales for rates.","currency":"USD","freeTier":false,"sourceUrl":"https://www.splunk.com/en_us/products/pricing/faqs.html","retrievedAt":"2026-08-14T13:42:56.059Z","freeTrialDays":14,"billingPeriods":["year"]}` | `{"type":"open_source","freeTier":true,"sourceUrl":"https://wazuh.com","retrievedAt":"2026-08-14T12:14:25.915Z"}` |
| pricing.free_tier | no | yes |
| pricing.model | commercial | commercial |
| pricing.price_level | unknown | free |
| pricing.transparent | no | no |
| release.cadence_days | - | 27 |
| release.history | - | `[{"url":"https://github.com/wazuh/wazuh/releases/tag/v4.14.7","date":"2026-07-30T16:32:45Z","type":"stable","version":"v4.14.7"},{"url":"https://github.com/wazuh/wazuh/releases/tag/v5.0.0-beta4","date":"2026-07-21T12:27:04Z","type":"prerelease","version":"v5.0.0-beta4"},{"url":"https://github.com/wazuh/wazuh/releases/tag/v5.0.0-beta3","date":"2026-07-02T15:48:47Z","type":"prerelease","version":"v5.0.0-beta3"},{"url":"https://github.com/wazuh/wazuh/releases/tag/v4.14.6","date":"2026-07-03T08:50:24Z","type":"stable","version":"v4.14.6"},{"url":"https://github.com/wazuh/wazuh/releases/tag/v5.0.0-beta2","date":"2026-05-21T14:10:11Z","type":"prerelease","version":"v5.0.0-beta2"},{"url":"https://github.com/wazuh/wazuh/releases/tag/v4.10.4","date":"2026-07-30T16:32:16Z","type":"stable","version":"v4.10.4"},{"url":"https://github.com/wazuh/wazuh/releases/tag/v4.14.5","date":"2026-04-23T11:46:46Z","type":"stable","version":"v4.14.5"},{"url":"https://github.com/wazuh/wazuh/releases/tag/v5.0.0-beta1","date":"2026-04-15T13:40:27Z","type":"prerelease","version":"v5.0.0-beta1"},{"url":"https://github.com/wazuh/wazuh/releases/tag/v4.14.4","date":"2026-03-17T08:51:22Z","type":"stable","version":"v4.14.4"},{"url":"https://github.com/wazuh/wazuh/releases/tag/v4.14.3","date":"2026-02-11T15:04:36Z","type":"stable","version":"v4.14.3"},{"url":"https://github.com/wazuh/wazuh/releases/tag/v4.14.2","date":"2026-01-15T11:19:35Z","type":"stable","version":"v4.14.2"},{"url":"https://github.com/wazuh/wazuh/releases/tag/v4.14.1","date":"2025-11-12T18:11:43Z","type":"stable","version":"v4.14.1"},{"url":"https://github.com/wazuh/wazuh/releases/tag/v4.14.0","date":"2025-10-23T17:45:30Z","type":"stable","version":"v4.14.0"},{"url":"https://github.com/wazuh/wazuh/releases/tag/v4.13.1","date":"2025-09-25T15:43:49Z","type":"stable","version":"v4.13.1"},{"url":"https://github.com/wazuh/wazuh/releases/tag/v4.13.0","date":"2025-09-19T07:02:27Z","type":"stable","version":"v4.13.0"},{"url":"https://github.com/wazuh/wazuh/releases/tag/v4.10.3","date":"2025-08-19T18:51:00Z","type":"stable","version":"v4.10.3"},{"url":"https://github.com/wazuh/wazuh/releases/tag/v4.10.2","date":"2025-05-23T11:56:41Z","type":"stable","version":"v4.10.2"},{"url":"https://github.com/wazuh/wazuh/releases/tag/v4.12.0","date":"2025-05-08T13:27:46Z","type":"stable","version":"v4.12.0"},{"url":"https://github.com/wazuh/wazuh/releases/tag/v4.11.2","date":"2025-04-02T13:40:18Z","type":"stable","version":"v4.11.2"},{"url":"https://github.com/wazuh/wazuh/releases/tag/v4.11.1","date":"2025-03-13T11:01:26Z","type":"stable","version":"v4.11.1"}]` |
| reliability.status_page | yes | - |
| security.disclosure_policy | yes | - |
| security.gdpr | - | yes |
| security.pci | - | yes |
| security.scorecard | - | 4.9 |
| security.vulnerabilities | - | `{"count":1,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=go&package_name=github.com%2Fwazuh%2Fwazuh&per_page=100","last_12m":0,"max_severity":"CRITICAL"}` |

## Capabilities (SIEM & SOAR Software)

| Capability | Splunk Enterprise Security | Wazuh |
|---|:--:|:--:|
| **Core** |  |  |
| SIEM (log correlation & detection) | ✓ | ✓ |
| SOAR (playbooks / automated response) | ✓ | ✓ |
| **Detection** |  |  |
| UEBA (behavioural analytics) | ✓ | - |
| Built-in threat intelligence | ✗ | ✓ |
| ML / anomaly detection | ✓ | - |
| MITRE ATT&CK detection mapping | ✗ | ✓ |
| **Ops** |  |  |
| Case / incident management | ✓ | ✓ |
| **Pricing** |  |  |
| Pricing basis | - | - |
| **Deployment** |  |  |
| Deployment | Hybrid | Hybrid |
| **Integration** |  |  |
| Connector / content-pack breadth | 2,000+ integrations via Splunkbase | Cloud and endpoint integrations including AWS services and threat intelligence f |
| **Licensing** |  |  |
| Open-core available | ✗ | ✓ |

*Source: Vioscale. Generated 2026-09-01T15:09:54.698Z. "-" = undocumented, not absent.*
