Cortex XDR by Palo Alto Networks vs Wazuh comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Ranking in Extended Detection and Response (XDR)
4th
Average Rating
8.4
Number of Reviews
84
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (2nd)
Wazuh
Ranking in Extended Detection and Response (XDR)
3rd
Average Rating
7.4
Number of Reviews
39
Ranking in other categories
Log Management (2nd), Security Information and Event Management (SIEM) (3rd)
 

Mindshare comparison

As of July 2024, in the Extended Detection and Response (XDR) category, the mindshare of Cortex XDR by Palo Alto Networks is 8.7%, down from 12.2% compared to the previous year. The mindshare of Wazuh is 15.6%, up from 1.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Extended Detection and Response (XDR)
Unique Categories:
Endpoint Protection Platform (EPP)
4.4%
Ransomware Protection
20.0%
Log Management
18.6%
Security Information and Event Management (SIEM)
15.3%
 

Featured Reviews

Vikas Gawali - PeerSpot reviewer
Jul 11, 2024
Has valuable AI-driven threat detection capabilities and good technical support services
Our primary use case for Cortex XDR is endpoint detection and response (EDR) across our enterprise environment, which includes over 1000 endpoints distributed globally. We use it to monitor and protect against advanced threats, perform real-time threat hunting, and streamline incident response…
Md Salim Hossain Hossain - PeerSpot reviewer
Jan 31, 2024
An open-source platform to integrate various products
We use Wazuh for the onboarding of both Windows and Linux machines, as well as for firewall and SIM configuration. The IP address is automatically blocked if a server has multiple wrong passwords Wazuh can integrate with various open-source and paid products, allowing for flexibility in…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"From a single pane of glass, you can easily manage all of your endpoints."
"The behavior-based detection feature is valuable."
"The most valuable features are the fact that it was running in the background and it would intercept any weird stuff, and the fact that it would send things directly to the cloud for sandboxing. It's quite practical."
"The most valuable for us is the correlation feature."
"We can visualize and control the activities in the environment from anywhere."
"The integrations are out-of-the-box, as are the playbooks."
"The tool's use cases are relevant to security."
"One of the things that I enjoy the most is using policy extensions. It's like having host firewalls to control USB connections. I think it's a wonderful tool to restrict use when connecting to our computers. Another important tool is Home Insights. That is an add-on to the Cortex solution. I like that because we can see all the vulnerabilities in the environment and control what assets are connected to our network."
"Wazuh's most beneficial features for our security needs are flexibility, built-in rules, integration capabilities, and documentation."
"The log monitoring and analysis tools are great in addition to SIEM file activity monitoring."
"We use it to find any aberration in our endpoint devices. For example, if someone installs a game on their company laptop, Wazuh will detect it and inform us of the unauthorized software or unintended use of the devices provided by the company."
"Good for monitoring, active response, and for vulnerabilities."
"Wazuh offers an enhanced HDR version that outperforms its competitors."
"I find the PCI DSS feature the most valuable, along with the feature that monitors the compliance of Windows and the CIS benchmarks on other devices like Unix or Linux systems."
"The product is easy to customize."
"The most valuable feature of Wazuh is the ELK for doing an investigation."
 

Cons

"The playbooks could be improved to include more functionalities or actions."
"Cortex XDR should have a lightweight agent, and the agent size should not be heavy."
"Cortex XDR could be improved with more GUI features."
"The setup is quite easy. We had appropriate support from the manager. One thing that was missing was the integration part."
"I would like to see them include NDR (Network Detection Response)."
"When it comes to core analysis, and security analysis, Cortex needs to provide more information."
"Managing the product should be easier."
"The solution needs better reports. I think they should let the customer go in and customize the reports."
"We would like to see more improvements on the cloud."
"They could include flexibility and customization capabilities by modifying for customers based on partner agreements."
"The tool does not provide CTI to monitor darknet."
"The support team could be more responsive and provide quicker replies during our working hours in Indonesia, which would be a significant improvement."
"Wazuh doesn't cover sources of events as well as Splunk. You can integrate Splunk with many sources of events, but it's a painful process to take care of some sources of events with Wazuh."
"Scalability is a constraint in the on-prem version of Wazuh in terms of the volume of logs we can manage."
"There could be a hardware monitoring tool for the solution."
"Wazuh is missing many things that a typical SIEM should have."
 

Pricing and Cost Advice

"The return on investment is from the user side because we have seen the performance of it increase the delivery time of the product if we are using too many web-based and on-premise applications. In indirect ways, we saw the return of investment in terms of performance and user satisfaction increase."
"The cost of Cortex XDR by Palo Alto Networks is $55 to $90 USD per endpoint per month."
"It's way too expensive, but security is expensive. You pay for your licensing, and then you pay for someone to monitor the stuff."
"The price of the solution is high for the license and in general."
"Very costly product."
"Every customer has to pay for a license because it doesn't work with what you get from a managed services provider."
"It has a higher cost than other solutions, like CrowdStrike or Microsoft’s EDR tools, but it reduces the cost of our operations because it’s a new generation antivirus tool."
"It is cost-effective compared to similar solutions. It fits for the small businesses through to the big businesses."
"They have a good pricing strategy for market expansion."
"Wazuh is open-source, but you must consider the total cost of ownership. It may be free to acquire, but you spend a lot of time and effort supporting the product and getting it to a point where it's useful."
"Wazuh is open-source, so I think it's an option for a small organization that cannot go for enterprise-grade solutions like Splunk."
"The solution's cost is above the average."
"Wazuh is free and open source."
"The current pricing is open source."
"The solution's pricing is very competitive."
"There is not a license required for Wazuh."
report
Use our free recommendation engine to learn which Extended Detection and Response (XDR) solutions are best for your needs.
793,295 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Government
8%
Financial Services Firm
8%
Manufacturing Company
7%
Computer Software Company
17%
Government
7%
Manufacturing Company
7%
Financial Services Firm
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. The ability to reverse damage caused by ransomware with minimal interruptions to...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions that are very scalable, secure, and user-friendly. Cortex XDR by Palo Alto offers ...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface, applies behavioral-based endpoint protection and response, and includes risk-ba...
What do you like most about Wazuh?
Integrates with various open-source and paid products, allowing for flexibility in customization based on use cases.
What needs improvement with Wazuh?
I have built some rules that produce duplicate alerts two or three times. Therefore, these rules should be consolidated. Alerts should be specific rather than repeatedly triggered by integrating mu...
What is your primary use case for Wazuh?
We use Wazuh for the onboarding of both Windows and Linux machines, as well as for firewall and SIM configuration. The IP address is automatically blocked if a server has multiple wrong passwords.
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
No data available
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Information Not Available
Find out what your peers are saying about Cortex XDR by Palo Alto Networks vs. Wazuh and other solutions. Updated: May 2024.
793,295 professionals have used our research since 2012.