

Splunk SOAR and Cortex XSIAM are key competitors in the threat management and automation domain. Cortex XSIAM emerges as the superior option due to its advanced machine learning and detection capabilities.
Features: Splunk SOAR offers robust integration, allowing for enhanced customization through its playbooks. It provides flexibility with its API connectors and modular structure for comprehensive security orchestration. Cortex XSIAM stands out with its AI-driven threat detection and unified platform, praised for seamless integration with tools and powerful visualization capabilities.
Room for Improvement: Splunk SOAR could benefit from better integration consistency across data sources and enhanced scalability. Enhanced documentation and more intuitive interfaces are also noted. Cortex XSIAM requires broader third-party integration and a more user-friendly interface. Pricing remains an issue for some, and quicker support response is needed.
Ease of Deployment and Customer Service: Splunk SOAR supports diverse deployment models across private, public, and hybrid clouds, with mixed reviews on direct support but reliable community assistance. Cortex XSIAM favors public and hybrid environments, backed by strong documentation, yet faces service responsiveness challenges. Splunk excels in community support, while Cortex provides strong formal documentation.
Pricing and ROI: Splunk SOAR is expensive but offers significant value for large enterprises, though not as flexible for smaller businesses. More competitive pricing could enhance its appeal. Cortex XSIAM offers competitive pricing relative to its features but remains on the higher side compared to others. Its strong ROI is evident through AI capabilities and integration, making it appealing for enterprises focused on advanced security solutions.
We've seen a decrease in false positives and a significant increase in our containment.
Monthly, around 300 hours of effort, it is saving with Splunk SOAR.
With premium support, core Palo Alto technical experts handle issues directly.
It is ineffective in terms of responding to basic queries and addressing future requirements.
The Palo Alto support team is fully responsive and helpful.
Discovering different troubleshooting methods is harder to do with Splunk SOAR than with Enterprise Security or other Splunk services.
We always have a customer support representative who will come in the picture and help us to direct any ticket or any issue that we are facing to the right team.
Splunk's technical support is very good and generally not needed often due to the stable environment.
Without proper integration, scaling up with more servers is meaningless.
Cortex XSIAM is highly scalable.
It can be extended and adapted as necessary.
Splunk SOAR has the ability to scale quite significantly.
The product was easy to install and set up and worked right.
Overall, Cortex XSIAM is stable.
It works really nice and performs really efficiently after configuration.
We have not experienced any downtime, crashes, or performance issues.
We have not seen any impact in the work that we do with Splunk SOAR or the SIEM platform.
Splunk SOAR provides a stable environment and technology.
Obtaining validation for integrations from Palo Alto takes around eight months, which is quite long.
Cortex XSIAM needs improvements in terms of data onboarding, parsers, and third-party integration supports.
Cortex XSIAM is on the expensive side and requires substantial improvement in pricing.
If we start ingesting those data to Splunk SOAR or SIEM with some sort of integration with threat intelligence feed, that will also improve our detection and prediction method or help us with the investigation.
Although it enhances alert handling, it still has a journey to compete with Palo Alto SOAR and FortiSOAR.
Splunk's Unified Platform does help consolidate networking security and IT observability tools.
The first impression is that XSIAM would be more expensive than others we tried.
The product is very expensive.
Cortex XSIAM is pretty expensive, and the licensing process is not very comfortable.
Splunk SOAR is moderately priced, neither cheap nor overly expensive.
I am familiar with the pricing aspect, setup cost, and licensing cost of Splunk SOAR, and it is pretty much similar to what industries are offering these days.
Splunk SOAR is affordable cost-wise only.
The advanced visualization capabilities of the product are important for understanding security trends in an organization.
One of the valued aspects of the product is its use of artificial intelligence to detect security vulnerabilities.
The flexibility for creating manual workflows stands out.
Creating playbooks using the Playbook Editor in Splunk SOAR is easy. The editor is designed to be user-friendly with visual drag and drop features, allowing for easy workflows without writing any code.
Splunk SOAR saves time in threat response, and the time to solve an incident is currently the best in the market.
Splunk SOAR has improved our MTTD and MTTR both with the consolidation with a unified platform with Splunk.
| Product | Market Share (%) |
|---|---|
| Cortex XSIAM | 2.4% |
| Splunk Enterprise Security | 7.4% |
| Wazuh | 7.3% |
| Other | 82.9% |
| Product | Market Share (%) |
|---|---|
| Splunk SOAR | 7.8% |
| Microsoft Sentinel | 13.0% |
| Palo Alto Networks Cortex XSOAR | 8.9% |
| Other | 70.3% |
| Company Size | Count |
|---|---|
| Small Business | 9 |
| Midsize Enterprise | 2 |
| Large Enterprise | 4 |
| Company Size | Count |
|---|---|
| Small Business | 12 |
| Midsize Enterprise | 7 |
| Large Enterprise | 31 |
Cortex XSIAM acts as a critical element for SOC foundations, integrating SIEM and EDR capabilities, valued for threat detection and seamless security orchestration with Palo Alto Networks products.
Organizations find Cortex XSIAM beneficial for SOC foundations due to its capability to integrate SIEM and EDR tools, facilitating data collection, detection, and response. It connects with third-party data sources while reducing management effort and offering cost-effective alternatives to competitors like CrowdStrike and Trend Micro. Featuring automation and integration with Palo Alto Networks products, Cortex XSIAM enhances threat detection. Unified architecture allows a comprehensive view of attacks, further supported by machine learning and integration with existing vendor solutions, ensuring that users gain insights without significant manual log analysis.
What are Cortex XSIAM's key features?
What benefits are evident in Cortex XSIAM reviews?
Industries implement Cortex XSIAM mainly in technology-driven sectors where centralized endpoint protection and automation of forensic investigation are paramount. By integrating several third-party systems for incident response, companies in competitive markets leverage its attributes for heightened operational security efficiency. However, users note areas for improvement, such as Attack Surface Management and integration enhancements, to better suit tech-heavy industries needing extensive connectivity with cybersecurity solutions.
Splunk SOAR offers features like automation and orchestration of manual tasks, speeding up work, detection and response to advanced and emerging threats.
Automate manual tasks. Address every alert, every day. Establish repeatable procedures that allow security analysts to stop being reactive and focus on mission-critical objectives to protect your business.
Orchestrate and automate repetitive tasks, investigation and response to increase efficiency and productivity, and do more with the people you already have. Make a team of three feel like a team of 10.
Work faster with Splunk SOAR. Respond to threats in seconds. Lower your mean time to respond (MTTR) by automating security tasks and workflows across all of your security tools.
Take advantage of Splunk Enterprise Security and Splunk SOAR joining forces to provide a seamless and intuitive SecOps platform to prevent, detect and respond to advanced and emerging threats.
We monitor all Security Information and Event Management (SIEM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.