Comparative Analysis of Wazuh, Graylog, and Elk Stack for Cyber Threat Detection and Response
Student: Ayobami James Alabi (Project, 2025)
Department of Cyber Security
Federal University of Technology Akure, Ondo State
Abstract
The rapid evolution of cyber threats has heightened the need for robust Security Information and Event Management (SIEM) solutions capable of effective detection and response. This study performs a comparative analysis of three open-source SIEM platforms; Wazuh, Graylog, and the ELK Stack focusing on their capabilities in detecting and responding to simulated cyber-attacks, including brute force, data exfiltration, malware infection, port scanning, and SQL injection. Each platform was deployed in a controlled environment, and attack simulations were conducted to generate realistic threat scenarios. Key metrics, such as detection accuracy, false positives, resource utilization, and system efficiency, were employed to evaluate performance. The results reveal that Wazuh demonstrated superior compliance and regulatory capabilities, excelling in anomaly detection with fewer false positives. Graylog offered unparalleled ease of integration and real-time log management, effectively detecting threats through its centralized dashboard. The ELK Stack exhibited exceptional capacity to handle large volumes of data logs and provided detailed visualization and analysis tools. This analysis highlights the distinct strengths and limitations of each SIEM platform. Wazuh is recommended for organizations prioritizing compliance and advanced anomaly detection, Graylog for those requiring efficient log management and user-friendly interfaces, and the ELK Stack for enterprises focusing on comprehensive data processing and insightful analytics. This research provides actionable insights for organizations to select a SIEM solution tailored to their specific cyber security requirements, fostering enhanced threat detection and incident response mechanisms.
Keywords
For the full publication, please contact the author directly at: alabiajcys2018@futa.edu.ng
Filters
Institutions
- Adeseun Ogundoyin Polytechnic, Eruwa, Oyo State 1
- Adeyemi College of Education, Ondo State. (affl To Oau, Ile-Ife) 68
- Ahmadu Bello University, Zaria, Kaduna State 101
- Air Force Institute of Technology (Degree), Kaduna, Kaduna State 11
- Air Force Institute of Technology, Kaduna, Kaduna State 2
- Akanu Ibiam Federal Polytechnic, Unwana, Afikpo, Ebonyi State 6
- Akwa Ibom State University, Ikot-Akpaden, Akwa Ibom State 53
- Akwa Ibom State College of Edu, Afaha-Nsit (Affl To Uni Uyo), Akwa Ibom State 2
- AKWA-IBOM STATE POLYTECHNIC (IEI), IKOT-OSURUA, AKWA IBOM STATE 41
- Akwa-Ibom State Polytechnic, Ikot-Osurua, Akwa Ibom State 32