Indeed, Carbon Black does not seem to offer a centralized log management solution as Wazuh does. Wazuh is a HIDS solution with a focus on security data collection for his posterior treatment and analysis. Along with the collection of data, Wazuh offers an Incident Response system based on events. Aside from the features mentioned earlier, you can check all the capabilities at the following link:
https://documentation.wazuh.com/current/user-manual/capabilities/index.html .
Regarding the methods to extract information from Windows systems, Wazuh makes use of Sysmon as well as Osquery to get different information of the host. You can check all the data channels and systems from where Wazuh collects Windows data:
Could you please explain what are the use cases you need to cover? Maybe this way I can share with you more valuable information.
I hope this helps!