Cortex updates about latest defination as per cyber attacks trends. Also knowlege base documents are very good.
It is rather expensive and too many options
The SIEM being open source allows the company to save on license costs on this product. This SIEM tool also allows modification in all rules present or added into the SIEM which makes monitoring easier.
You won't be able to access your environment deployed in the Wazuh cloud using SSH access, unlike AWS EC2 instances. This restricts various customization features at the infrastructure level, and also communications are passed only through Wazuh agents.
Cortex updates about latest defination as per cyber attacks trends. Also knowlege base documents are very good.
The SIEM being open source allows the company to save on license costs on this product. This SIEM tool also allows modification in all rules present or added into the SIEM which makes monitoring easier.
It is rather expensive and too many options
You won't be able to access your environment deployed in the Wazuh cloud using SSH access, unlike AWS EC2 instances. This restricts various customization features at the infrastructure level, and also communications are passed only through Wazuh agents.