No more typing reviews! Try our Samantha, our new voice AI agent.

Alert Logic MDR vs Palo Alto Networks Cortex XSOAR comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 11, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Alert Logic MDR
Ranking in SOC as a Service
3rd
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
11
Ranking in other categories
Vulnerability Management (32nd), Managed Detection and Response (MDR) (17th)
Palo Alto Networks Cortex X...
Ranking in SOC as a Service
2nd
Average Rating
8.4
Reviews Sentiment
6.5
Number of Reviews
51
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (3rd)
 

Mindshare comparison

As of March 2026, in the SOC as a Service category, the mindshare of Alert Logic MDR is 5.7%, down from 5.9% compared to the previous year. The mindshare of Palo Alto Networks Cortex XSOAR is 5.6%, down from 22.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
SOC as a Service Mindshare Distribution
ProductMindshare (%)
Palo Alto Networks Cortex XSOAR5.6%
Fortra's Alert Logic MDR5.7%
Other88.7%
SOC as a Service
 

Featured Reviews

reviewer2191746 - PeerSpot reviewer
President at a tech services company with 11-50 employees
It's a highly mature, competitively priced solution that provides total visibility into your ecosystem. FORTRA's Alert Logic has the only Cybersecurity Platform that integrates XDR+WAF+VM+DLP in one.
Alert Logic offers total visibility into the client's IT ecosystem. The solution's intrusion detection system inspects 100 percent of the network packets and installs universal agents on all physical and virtual servers for log collection. Alert Logic also aggregates logs of the client's various 3rd Party security tools into a single pane of glass. All of the analytics from those data feeds got to a 24/7 SOC with sophisticated resources. Alert Logic has massive threat intelligence resources to provide additional context to the incident response declarations. They do all the heavy lifting for clients who lack the technology and resources to operate their own SOC. The client is solely responsible for the incident response component. The macro analytics resides on Alert Logic's cloud. You have the ECM response and business application team on the client side. Everything works in tandem, which is the only way you can deal with the advanced threats we face today, especially the ransomware families. If you don't respond in minutes, you're in trouble.
CC
Enterprise Security Architect V at FirstEnergy
Customization supports seamless workflow while data influx challenges response time
What I appreciate most about Palo Alto Networks Cortex XSOAR is that it is very open, even more so than Anomali. I can create various custom automations and custom fields. There is significant customization ability in this platform. If I already have an established process, I do not have to change my process to fit into the tool. I can modify the tool to fit into my process, which makes things considerably easier. All of our alerts from different tools come into this central place as we have multiple SIEMs. We have items coming from Anomali and other platforms that are not SIEM tools. This serves as our central location where our SOC analysts can work and determine if incident response is needed. The platform provides data enrichment capabilities, offering information upfront so analysts do not have to search for it. They can access details such as username, phone number, email address, and workplace information. For malware files, they can retrieve details from VirusTotal, including file names and environment presence. We have built substantial automation around these features, which also helps us track case metrics, investigation time, and threat mitigation duration.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It has the ability to install agents, it is pretty straightforward, and you can automate the process pretty easily."
"It has the ability to install agents. It is pretty straightforward. You can automate the process pretty easily."
"Technical support is pretty decent with Alert Logic."
"It's been a positive experience for us overall."
"My advice would be to go ahead with the product because it really is a very good tool that adds a lot of value."
"The solution was consistently available, and I cannot recall any instances where it was down."
"It is a very stable product."
"It improves our security; before, we didn't have anything scanning our containers, but with Alert Logic we can now scan them for vulnerabilities."
"The solution has very good integration capabilities; it's really the best at integration, with commands inside every integration that make it very useful as a product, and the automation is excellent."
"I have found the solution very useful, it integrates well with other platforms."
"It was useful as a ticketing tool."
"The installation is very easy to set up; it’s not overly complex or difficult, and the deployment took less than a week as we had it up and running within a couple of days."
"The solution is easy to deploy."
"The solution is very reliable."
"Palo Alto is easy to use."
"It is quite scalable. I would rate it a ten out of ten."
 

Cons

"The documentation, especially with the initial setup, needs improvement."
"The setup process was complex."
"This product needs to mature more. While it is a good product, there are some areas where it needs work."
"One pain point we have, for example, is if the search keyword is related inside an XML, we will get an XML; if it is a normal log, however, you will get a null pointer exception or something, and we don't get the complete trace."
"I would like more data on the alert payload. It would be good to have the ability to customize the alert payload to add whatever data that we want on there."
"The documentation, especially with the initial setup, needs improvement."
"This product needs to mature more. While it is a good product, there are some areas where it needs work."
"As a user involved with the user interface, I believe there is a need to continue improving it based on feedback from our customers."
"It doesn't offer automatic internet reports out of the box."
"There should be an on-premise version available for customers to have different choices."
"It's only one cloud right now. It might be helpful for some companies to have an on-premies option."
"The dashboard could be better."
"It's quite lagging and not very fast."
"The price of the solution could be improved."
"The user interface could be a bit better."
"The integration could be better. Cortex, for example, does not work with iPhone."
 

Pricing and Cost Advice

"Alert Logic has better competitive pricing than some of its competitors."
"Almost any product that is on the AWS Marketplace is super easy to subscribe to."
"Price of the solution was very reasonable considering the size of our organization at the time, and so it worked out perfectly."
"Our ROI would probably be zero. We don't even use it. It sits in there. We get emails and just delete them. Around the world, we don't even use it."
"Its pricing is very reasonable considering what you get for what you pay. There is quite a good value there. Its licensing is also very logical. They've got the licensing price points at a reasonable level. It is on a monthly license but a yearly contract. There are no additional costs to the standard licensing fees."
"The solution's pricing needs improvement."
"The price of Palo Alto Networks Cortex XSOAR is expensive."
"From the cost perspective, I have heard that its price is a bit high as compared to other similar products."
"It is approx $10,000 or $20,000 per year for two user licenses."
"The pricing is fair. The pricing reflects the value and feature set it offers."
"It is expensive."
"The solution's cost is reasonable."
"There is a yearly license required for this solution and it is expensive."
report
Use our free recommendation engine to learn which SOC as a Service solutions are best for your needs.
885,311 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Manufacturing Company
10%
Outsourcing Company
7%
Comms Service Provider
6%
Financial Services Firm
12%
Computer Software Company
10%
Manufacturing Company
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise2
Large Enterprise6
By reviewers
Company SizeCount
Small Business20
Midsize Enterprise9
Large Enterprise26
 

Questions from the Community

Ask a question
Earn 20 points
What is your experience regarding pricing and costs for Palo Alto Networks Cortex XSOAR?
Comparing pricing to Micro Focus, they were offering bundles, making it free with their SIEM. For customers, it is zero versus $20 million, which is why they have to make a decision.
What needs improvement with Palo Alto Networks Cortex XSOAR?
Regarding areas for improvement in Palo Alto Networks Cortex XSOAR, I want to highlight one concern about playbook creation. While I personally appreciate this approach, I have observed that junior...
 

Also Known As

Alert Logic Managed Detection and Response, Alert Logic Threat Manager, Alert Logic Cloud Defender, Critical Watch FusionVM
Demisto Enterprise, Cortex XSOAR, Demisto
 

Overview

 

Sample Customers

Information Not Available
Cellcom Israel, Blue Cross and Blue Shield of Kansas City, esri, Cylance, Flatiron Health, Veeva, ADT Cybersecurity
Find out what your peers are saying about Alert Logic MDR vs. Palo Alto Networks Cortex XSOAR and other solutions. Updated: March 2026.
885,311 professionals have used our research since 2012.