OSSEC is smaller and does less. If you want file integrity monitoring and log analysis on a set of servers and nothing else, it still does that and you can read the whole thing in an afternoon.
Wazuh is OSSEC plus a lot: dashboard, agent management, compliance mapping, an Elasticsearch stack underneath. If you want those, take them, that is what it is for.
Honest version is that most people asking this want Wazuh and are checking they are not missing something.
Biased, obviously, since I wrote the first one.
OSSEC is smaller and does less. If you want file integrity monitoring and log analysis on a set of servers and nothing else, it still does that and you can read the whole thing in an afternoon.
Wazuh is OSSEC plus a lot: dashboard, agent management, compliance mapping, an Elasticsearch stack underneath. If you want those, take them, that is what it is for.
Honest version is that most people asking this want Wazuh and are checking they are not missing something.