WAZUH VS SPLUNK
Wazuh vs Splunk: Which SIEM to Learn and Run in 2026
Wazuh and Splunk compared for analysts and small SOCs: what each free tier really allows, a worked lab sizing against Splunk Free's 500 MB cap, the same hunt in both tools, and which one to learn first.

Wazuh vs Splunk comes down to cost, scale and what you are learning for: Wazuh is a free, open source security platform with agents, detection rules, file integrity monitoring, vulnerability detection and active response built in, so a small SOC or a home lab can run a full SIEM without a licence bill; Splunk is a commercial data platform whose free licence is capped at 500 MB of indexed data a day, on a single instance, with alerting, users and roles switched off. For hands-on threat hunting and detection engineering in your own lab, Wazuh gives you more for nothing. For a job whose advert names Splunk, learn Splunk's Search Processing Language (SPL) as well. The good news is that the analyst skills underneath, from rule logic to ATT&CK mapping and hunting method, carry over between them.
Facts about Wazuh and Splunk Free were read on each vendor's documentation in October 2026. Wazuh and Splunk are their owners' trademarks, used here only to describe the products.
The two products in one page
Wazuh has four parts, set out on its architecture page. Agents on Windows, Linux and macOS endpoints collect logs, file changes and inventory and send them to the Wazuh server on TCP 1514 (enrolment uses 1515). The server decodes events and matches them against rules. The Wazuh indexer stores and searches the results, and the Wazuh dashboard is where analysts search, hunt and build views. Detection rules are XML files; the custom rules guide reserves IDs 100000 to 120000 for your own rules so upgrades never overwrite them.
Splunk Enterprise is a general data platform: it indexes almost any machine data and you search it with SPL. Security content, correlation searches and case management come from Splunk's security products on top. Splunk's own pricing page describes activity-based, workload or ingest pricing for its paid platform, so cost grows with the data and the work you put through it.
Splunk Free: what the free licence really allows
Splunk's documentation page About Splunk Free is clear about the limits, and they matter for anyone planning a lab:
- You can index 500 MB a day, which the page estimates at around 7 GB of storage a month.
- It is for a standalone, single-instance installation only. Distributed search, indexer clustering and deployment management are not available.
- Alerting is not available, and there are no users or roles: anyone who reaches the instance is logged straight in as an administrator.
- Exceed the daily volume and you get a licence warning; three warnings in a rolling 30-day window disable search (indexing continues) until you drop back below three.
- A new installation starts on a 60-day Enterprise Trial licence, which you can switch to Free at any time.
So Splunk Free is fine for learning SPL and practising searches on a modest data set. It cannot fire an alert, which is half of what a SOC analyst practises.
Side by side
| Point | Wazuh | Splunk (Free licence) |
|---|---|---|
| Licence cost | Free and open source | Free, capped at 500 MB indexed a day |
| Alerting | Built in, rule levels decide alerts | Not available on Free |
| Users and roles | Supported | None; everyone is admin |
| Endpoint agent | Wazuh agent with FIM, inventory, vulnerability detection | Universal Forwarder ships data; detection is your search content |
| Detection logic | XML rules, decoders, frequency and timeframe correlation | SPL searches and, in paid security products, correlation searches |
| ATT&CK mapping | mitre block on each rule, dashboard module | Tags in your content, more in paid security products |
| Active response | Built in, with location, trigger and timeout | Through apps and paid automation |
| Scale path | Add indexer and server nodes yourself | Paid licence, Splunk Cloud or Enterprise |

Worked example: will the lab fit?
You plan a lab with 25 Windows endpoints running Sysmon with a tuned configuration. Each forwards about 1,200 events an hour, and an average event is about 500 bytes once stored (measure your own; untuned Sysmon can be ten times noisier).
- Events a day: 25 x 1,200 x 24 = 720,000.
- Volume a day: 720,000 x 500 bytes = 360,000,000 bytes, about 360 MB.
- Against Splunk Free: 360 MB is under the 500 MB cap, a margin of 140 MB. Grow to 40 endpoints and the volume becomes 40 x 1,200 x 24 x 500 = 576 MB, over the cap every day, and three such days in 30 disable search.
- Against Wazuh: the quickstart sizes an all-in-one server for 1 to 25 agents at 4 vCPU, 8 GiB of RAM and 50 GB of storage for 90 days of indexed alerts. Alerts are a slice of events: 20 agents x 3,000 alerts a day x 1.5 KB x 90 days = 8.1 GB, well inside 50 GB. Keeping full archives for hunting multiplies that, so size from your own measured volume.
The point is not that one product is cheaper in every case. It is that the free tier of each has a different ceiling: Splunk Free caps data and removes alerting, while Wazuh caps nothing but asks you to supply and run the hardware.
What carries over between them
Employers hire analysts, not product clicks. The habits below work the same in Wazuh, Splunk, Microsoft Sentinel or any other SIEM:
- Decode first, then detect: no field-based rule or search can match an event that was never parsed into fields.
- Write each detection with a sample that must fire and a sample that must not, and tag it with an ATT&CK technique ID.
- Measure precision. A rule raising 300 alerts a day with 4% true positives drops to 45 alerts at 26.7% precision once one known-good tool is excluded by its exact path, with no true positives lost.
- Hunt from a hypothesis, check the data exists, stack-count rare values and end with a written outcome.
- Keep attack simulations inside an isolated lab you own, from a snapshot you revert afterwards.
The same hunt in each tool
Take one hypothesis: a phishing document on a workstation started PowerShell (ATT&CK T1204.002 followed by T1059.001), which would show as a Sysmon process-creation event (event ID 1) with winword.exe as the parent.
- In Wazuh, open the threat hunting view, filter on the Sysmon process-creation rule group (sysmon_event1), add a filter where data.win.eventdata.parentImage ends with winword.exe, and build a data table split by image and agent name for the last seven days. Turn archives on in a lab, because Wazuh's base Sysmon rules are level 0 and do not raise alerts by themselves.
- In Splunk, with Sysmon data onboarded through a Sysmon add-on, a search such as index=sysmon EventCode=1 | where like(ParentImage, "%winword.exe") | stats count by host, Image does the same job.
Either way the next steps are identical: pivot on the process GUID, the user and a few minutes either side, decide whether it is malicious, and end with an incident, a new rule or a written clean result.
Which to choose
| Your situation | Better first pick | Why |
|---|---|---|
| Building a home lab to learn detection and hunting | Wazuh | Alerts, rules and endpoint features with no data cap |
| Target job advert names Splunk | Splunk, then Wazuh | Learn SPL for the interview, show a Wazuh lab as proof of skill |
| Small organisation with no SIEM budget | Wazuh | Full SIEM and XDR features without a licence bill |
| Large estate, many data sources, paid support needed | Splunk or another commercial SIEM | Vendor support and a wide app ecosystem |
| Studying for SC-200 | Neither first | Microsoft Sentinel and KQL are what that exam tests |

Choose Wazuh when you want a complete, alerting SIEM in a home lab or a small organisation without licence costs, when you need endpoint features such as file integrity monitoring and vulnerability detection in the same tool, or when you are learning detection engineering and want to write and tune rules freely. Choose Splunk when your target employer runs it, when you need its very wide app ecosystem, or when you are practising SPL for a role that will give you a paid environment to work in. Many analysts learn both: Splunk's search language for the interview, Wazuh for the hands-on lab that shows what you can do.
If certificates are part of your plan, read our guide on how to verify a training certificate and our look at what free courses with certificates really cost before you pay anyone.
Learn both, free
The free SOC Analyst Level 2: Threat Hunting with Wazuh course builds a Wazuh 4.14 lab with Windows and Linux agents and Sysmon, then teaches decoders, rules and tuning, ATT&CK v19 mapping, hunts for persistence, LSASS access and lateral movement, file integrity monitoring and active response, and incident handling on NIST SP 800-61 Rev. 3, finishing with a scored Atomic Red Team simulation in an isolated lab. For SPL and Level 1 triage, take SOC Analyst Level 1 with Splunk first.
It is a free course with a verifiable certificate of completion, and anyone can check a certificate on our verification page. It is not affiliated with Wazuh Inc., Splunk, MITRE or NIST. Start the Wazuh threat hunting course in your own lab.
Take the free course
Questions
Is Wazuh better than Splunk?
Neither is better for everyone. Wazuh is free and open source with alerting, file integrity monitoring and vulnerability detection built in, which suits labs and small SOCs. Splunk is a commercial platform with a large app ecosystem; its free licence is capped at 500 MB a day and has no alerting.
Is Wazuh really free?
Yes. Wazuh is free and open source; you pay only for the hardware or cloud capacity it runs on. Its quickstart sizes an all-in-one server for up to 25 agents at 4 vCPU, 8 GiB of RAM and 50 GB of storage for 90 days of alerts.
What are the limits of Splunk Free?
Splunk's documentation says the Free licence indexes up to 500 MB a day on a single standalone instance, with no alerting, no users or roles and no clustering. Three licence warnings in a rolling 30 days disable search until you drop below three.
Which SIEM should a beginner learn first?
Learn the analyst method on whichever tool you can run fully, which for most people is Wazuh in a home lab. If the jobs you want name Splunk, learn its Search Processing Language too. Rule logic, ATT&CK mapping and hunting method transfer between SIEMs.
Can I do threat hunting with Wazuh?
Yes. With Sysmon on Windows endpoints and archives enabled, you can run hypothesis-led hunts in the Wazuh dashboard, stack-count rare parent and child processes, and turn findings into custom rules with IDs between 100000 and 120000.
Is there a free Wazuh course with a certificate?
Yes. SOC Analyst Level 2: Threat Hunting with Wazuh on EDWartens is a free course with a verifiable certificate of completion, issued after the modules and a 15-question final passed at 60 percent. It is not affiliated with Wazuh Inc. or Splunk.
Sources
- Splunk: About Splunk Free, Splunk Enterprise admin manual 10.6 (read 11 October 2026)
- Splunk: Pricing (read 11 October 2026)
- Wazuh documentation: Architecture (read 11 October 2026)
- Wazuh documentation: Custom rules (read 11 October 2026)
- Wazuh documentation: Quickstart (read 11 October 2026)
Written by the EDWartens engineering team for general education. Product names are trademarks of their owners; mentioning them does not imply endorsement. Prices and terms of other providers were checked on the date shown and can change.

KQL Queries for Threat Hunting: 8 Patterns With Examples

Is ISC2 CC Worth It in 2026, Now the Free Exam Has Ended?

ISO 27001 Annex A Controls Explained: All 93 by Theme

Controls Engineer Certifications: CAP, CCST and More

Do Online Courses Count as CPD or PDH for Engineers?

Electrical QA/QC Engineer: Duties, ITPs and Certifications


