Share your experience using Threat Stack Oversight

The easiest route - we'll conduct a 15 minute phone interview and write up the review for you.

Use our online form to submit your review. It's quick and you can post anonymously.

Your review helps others learn about this solution
The PeerSpot community is built upon trust and sharing with peers.
It's good for your career
In today's digital world, your review shows you have valuable expertise.
You can influence the market
Vendors read their reviews and make improvements based on your feedback.
Examples of the 84,000+ reviews on PeerSpot:

Sara Qafa - PeerSpot reviewer
Systems Engineer at Exclusive Networks
Reseller
Helps understand user behavior, automates security tasks, and enables threat hunting
Pros and Cons
  • "The product can automate security tasks."
  • "The solution is complicated to learn."

What is our primary use case?

The SOC team needs the tool to understand the network and determine why an incident happens. The tool helps understand user behavior and helps with threat hunting.

What is most valuable?

The solution has a lot of information, like playbooks and incidents. It goes really deep. The vendor provides training, knowledge bases, workshops, and webinars. The product can automate security tasks. Playbooks are the most beneficial feature. We can create a playbook. We can get visibility on incidents.

We can also analyze user behavior and understand whether it is a true positive or a false positive. We have so many false positives these days in security, so it's nice when we can put things in the block list. We can perform investigations. The product can be integrated with third-party tools.

What needs improvement?

The solution is complicated to learn. Customers find it difficult to learn how the solution works. We need professionals to learn and understand how the tool works to expand it further. Our customers want to see more use cases. They want to have more facilitations and more visibility on how it works. We need more skilled people inside and outside the team to understand how it works. It’s difficult to find skilled people to understand how the tool works.

What do I think about the scalability of the solution?

The solution is suitable for enterprise businesses.

How are customer service and support?

We can send an email to the online support portal. We can contact Palo Alto engineers immediately and open a ticket. The engineers will take care of the issue depending on the severity level of the ticket.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is really easy. We just have to order it. When we have the tool, someone from Palo Alto will provide us with the account information. After that, we must set up the users, customers, and resellers. We can do onboarding immediately. The deployment takes one or two days.

What's my experience with pricing, setup cost, and licensing?

Whether the product is cheap or expensive depends on the company and how much they are willing to spend on security. Nowadays, security is important. The solution is not suitable for small businesses. It is better suited for medium and enterprise businesses because it starts with 200 endpoints.

Which other solutions did I evaluate?

SentinelOne is an endpoint protection tool. However, Palo Alto gives us more security features.

What other advice do I have?

I work with a distributor. I recommend the product to my customers. I'm really satisfied with the tool. It's a very nice tool. It can work and give us what we need. We just need to be patient and learn how it works. The incidents can be handled very easily. Overall, I rate the product a nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Flag as inappropriate
Henok Tsegaye - PeerSpot reviewer
BDM/Chief Information Officer at Afcor PLC
Real User
Top 10
A user-friendly solution simplifying security with easy configuration
Pros and Cons
  • "The solution is user-friendly and easy to configure."
  • "Palo Alto needs to develop more AI-centric products."

What is most valuable?

The solution is user-friendly and easy to configure.

What needs improvement?

Palo Alto needs to develop more AI-centric products. Also, the price could be cheaper. It doesn’t have infinite connectors.

For how long have I used the solution?

I have been using Palo Alto Networks Cortex XSOAR for a couple of years.

What do I think about the stability of the solution?

The product is very stable.

What do I think about the scalability of the solution?

5,000-7,000 users are using this solution.

How are customer service and support?

Technical support is knowledgeable.

Which solution did I use previously and why did I switch?

We used to work on the IBM XSOAR product, which was well-developed and competitive. The IBM component was strong, but Palo Alto Networks Cortex XSOAR performed well. The main difference lies in the level of suggestions provided by the playbooks when analyzing logs. IBM's suggestions to be better.

How was the initial setup?

The initial setup is simple. Your level of understanding significantly impacts the effectiveness of implementation. People may learn the hard way, especially post-implementation, highlighting the importance of a comprehensive experience.

What other advice do I have?

I recommended Palo Alto Networks Cortex XSOAR to a friend, and they have been using it to access and respond to issues in their data center. So far, there have been no complaints, not even worth mentioning. They also requested repairs through the platform.

The playbook is very good and user-friendly compared to IBM.

There are always things missing in some of the boxes. In some instances, there appears to be a leak. There are inconsistencies. Solutions like Palo Alto Networks Cortex XSOAR or similar products are necessary.

Overall, I rate the solution an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate