| Features | Wazuh | Alienvault OSSIM | Alienvault USM | RSA Netwitness |
| Open-source platform | | | | |
| Auditable code | | | | |
| Public roadmap | | | | |
Endpoint / Container oriented solution | | | | |
High Availability / Cluster deployment | | | | |
Horizontal scalability and auto-scaling | | | | |
Lightweight modular components | | | | |
| Log data collection | | | | |
Signed archival data storage | | | | |
Correlation and cross-correlation | | | | |
File integrity monitoring (FIM) | | | | |
| Auditing who-data | | | | |
Anomaly and malware detection | | | | |
Security configuration assessment | | | | |
| Monitoring system calls | | | | with Endpoint component |
| Command monitoring | | | | |
| Active response | | | | with Endpoint component |
Anti-flooding mechanism | | | | |
Automated system inventory | | | | with Endpoint component |
Host-based vulnerability detection | | | | with Endpoint component |
| VirusTotal integration | | | | |
| Osquery | | | | |
| Fluentd forwarder | | | | |
| Native JSON support | | | | |
NIDS Integration (Suricata, Snort, Zeek, etc) | | | | |
| Elastic stack integration | | | | |
Kibana visualizations / Advanced Dashboards | | | | |
| Cloud-based alternative | | | | |
Monitor cloud environments (AWS, Google | | | | |
Orchestration and deployment integration (Ansible, chef, puppet, etc) | | | | |