No more typing reviews! Try our Samantha, our new voice AI agent.

Cortex XSIAM vs CrowdStrike Falcon comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Aug 11, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
4.3
Cortex XSIAM achieved savings over $500,000 by automating over half of detection and response, optimizing incident management.
Sentiment score
6.8
CrowdStrike Falcon boosts security, reduces costs, increases efficiency, and enhances threat response, leading to improved productivity and ROI.
Catching issues early enough saves us from having to disable multiple users, which may be part of a later phishing event or disruption event in our environment.
Director, Information Security Services at a university with 10,001+ employees
We have to have cyber liability insurance, and knowing that we have CrowdStrike Falcon definitely helps when it comes to the bottom line and helping our insurance rates stay at a fair level.
Information Security Manager Iam at ExactCare Pharmacy
CrowdStrike Falcon saves time and offers good value for money, especially for enterprise companies, because it can stop breaches.
IT consultant at Asuransi Ramayana
 

Customer Service

Sentiment score
6.1
Cortex XSIAM technical support experiences vary, with premium support praised for expertise, while distributor-based support quality fluctuates.
Sentiment score
7.1
CrowdStrike Falcon support offers mixed feedback, with praised efficiency and premium service but noted inconsistencies in standard support.
With premium support, core Palo Alto technical experts handle issues directly.
Team Lead, Security at seamlessinfotech.com
It is ineffective in terms of responding to basic queries and addressing future requirements.
Associate Director at a financial services firm with 5,001-10,000 employees
I had a dedicated person allocated for supporting, and even with them, it was very good.
Cybersecurity Architect at a computer software company with 10,001+ employees
On a scale of one to ten, I would rate the technical support as a 10 because they resolve many issues for us.
Cyber Security Architects at VaporVM
Everybody is friendly, knowledgeable, and wants to help, and you can feel that they want to keep your business.
Information Security Manager Iam at ExactCare Pharmacy
The onboarding team deserved a ten.
IT Support Engineer at a media company with 51-200 employees
 

Scalability Issues

Sentiment score
6.6
Cortex XSIAM excels in scalability and cloud deployment, though integration affects performance and some prefer more on-premises functionality.
Sentiment score
7.7
CrowdStrike Falcon offers scalable, cloud-based security, efficiently managing thousands of endpoints, suitable for both large and small enterprises.
Without proper integration, scaling up with more servers is meaningless.
Associate Director at a financial services firm with 5,001-10,000 employees
The SOC team is responsible for fully managing Cortex XSIAM.
Cybersecurity Architect at a computer software company with 10,001+ employees
Cortex XSIAM is highly scalable.
SOC Analyst at OVELOSEC
It has adequate coverage and is easy to deploy.
Senior Principal Information Security Analyst at Veritas Technologies LLC
In terms of scalability, I find CrowdStrike to be stable, and I have not encountered any limitations with it.
Cyber Security Architects at VaporVM
There's no scalability limitation from CrowdStrike itself, as it just requires agent deployment.
Large account Manager at Softcell Technologies Limited
 

Stability Issues

Sentiment score
7.5
Cortex XSIAM is cloud-based, reliable, with minimal maintenance, and occasional update issues are quickly resolved, enhancing performance.
Sentiment score
8.1
CrowdStrike Falcon is highly stable and reliable, with minimal issues, efficient performance, and excellent user ratings.
The product was easy to install and set up and worked right.
Owner at Xelere
With continuous integration that the colleagues probably are doing, it is becoming better and better.
Cybersecurity Architect at a computer software company with 10,001+ employees
Overall, Cortex XSIAM is stable.
SOC Analyst at OVELOSEC
I have not experienced any downtime, crashes, or performance issues with CrowdStrike Falcon.
IT Security Analysts at Royal Business Bank
I have never seen instability in the CrowdStrike tool.
Security Analyst at NTT Ltd
We are following N-1 versions across our environment, which is stable.
Senior Principal Information Security Analyst at Veritas Technologies LLC
 

Room For Improvement

Cortex XSIAM needs better integration, usability, pricing, data management, and support for enhanced performance and flexibility.
Users seek enhanced compatibility, user-friendliness, AI, support, and flexible pricing for CrowdStrike Falcon, emphasizing deployment complexity and cost.
Obtaining validation for integrations from Palo Alto takes around eight months, which is quite long.
Associate Director at a financial services firm with 5,001-10,000 employees
Cortex XSIAM needs improvements in terms of data onboarding, parsers, and third-party integration supports.
SOC Analyst at OVELOSEC
Cortex XSIAM is on the expensive side and requires substantial improvement in pricing.
Solutions Architect at ostec
Documentation is abysmal and needs to be improved dramatically.
Senior Security Engineer at a financial services firm with 10,001+ employees
If I bring up a device, I want a quick button there to contain it because if I'm clicking on that device, there's something I'm looking into and most likely I've been alerted of something, so I should probably contain it first and then ask questions later.
Network Security Engineers at Silver State Schools Credit Union
Simplifying the querying process, such as using double quote queries or directly obtaining logs based on IP addresses or usernames, would be beneficial.
Security Analyst at NTT Ltd
 

Setup Cost

Cortex XSIAM is expensive with variable pricing, complexity in licensing, and additional costs for functionalities and resources.
CrowdStrike Falcon pricing reflects endpoint volume and modules, offering strong security value for $60-$100 per user annually.
The first impression is that XSIAM would be more expensive than others we tried.
Owner at Xelere
The product is very expensive.
Associate Director at a financial services firm with 5,001-10,000 employees
Cortex XSIAM is pretty expensive, and the licensing process is not very comfortable.
Director at MICROLOGIC NETWORKS PRIVATE LIMITED
It is approximately 60 dollars per endpoint at MSRP.
Senior Secops Engineer at a program development consultancy with 1,001-5,000 employees
It is expensive compared to SentinelOne, but as the market leader, it is worth it.
Senior Principal Information Security Analyst at Veritas Technologies LLC
The licensing cost and setup costs are affordable.
Computer Engineer at OIC, Alshirawi
 

Valuable Features

Cortex XSIAM enhances incident response with automation, integration, and machine learning, providing comprehensive network security and threat identification.
CrowdStrike Falcon excels with real-time threat detection, integration, scalability, reducing workloads, and enhancing security through its unified platform.
The advanced visualization capabilities of the product are important for understanding security trends in an organization.
Solutions Architect at ostec
To have Cortex XSIAM available is to basically have integration of all log sources, all alerting, and so on and so forth from firewalls and different tools, to get everything in one place, and afterwards to be able to build on the information that is coming.
Cybersecurity Architect at a computer software company with 10,001+ employees
One of the valued aspects of the product is its use of artificial intelligence to detect security vulnerabilities.
Owner at Xelere
I can investigate by accessing the customer's host based on the RTR environment and utilize host search to know details for the past seven days, including logins, processes, file installations, malicious processes, and network connections.
Security Analyst at NTT Ltd
The real-time analytics aspect of CrowdStrike performs well because we get all logs in real-time, with no delay, allowing us to take action immediately.
Cyber Security Architects at VaporVM
Being an EDR solution, it helps us identify attacks in real-time.
Information Security Specialist at Arab Open University
 

Categories and Ranking

Cortex XSIAM
Average Rating
8.6
Reviews Sentiment
6.7
Number of Reviews
16
Ranking in other categories
Security Information and Event Management (SIEM) (14th), Identity Threat Detection and Response (ITDR) (6th), AI-Powered Cybersecurity Platforms (8th)
CrowdStrike Falcon
Average Rating
8.8
Reviews Sentiment
7.2
Number of Reviews
173
Ranking in other categories
Endpoint Protection Platform (EPP) (3rd), Endpoint Detection and Response (EDR) (2nd)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Cortex XSIAM is designed for Security Information and Event Management (SIEM) and holds a mindshare of 1.4%, down 2.8% compared to last year.
CrowdStrike Falcon, on the other hand, focuses on Endpoint Protection Platform (EPP), holds 5.7% mindshare, down 8.2% since last year.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
Cortex XSIAM1.4%
Splunk Enterprise Security7.8%
IBM Security QRadar5.6%
Other85.2%
Security Information and Event Management (SIEM)
Endpoint Protection Platform (EPP) Mindshare Distribution
ProductMindshare (%)
CrowdStrike Falcon5.7%
Microsoft Defender for Endpoint6.5%
SentinelOne Singularity Endpoint4.5%
Other83.3%
Endpoint Protection Platform (EPP)
 

Featured Reviews

reviewer2541030 - PeerSpot reviewer
Cybersecurity Architect at a computer software company with 10,001+ employees
Unified security monitoring has simplified incident response and improved automated threat handling
The firewall side can make some improvements. I know the firewall on Cortex XSIAM is based on Windows. From what I have experienced so far, I have seen that the policies you can create are actually very in-depth. I mean, you can do most of the things and a lot of integration that you actually want. So if I want to choose to send things to WildFire, for example, I can choose to send it, I can choose to not send it. This basically offers flexibility to implement Cortex XSIAM in more standardized places where you maybe have a certification. I would say that the thing that maybe needs a bit more improvement is the fact that the one with the firewall because I have seen some things there that are kind of hard to manage. You do not really have a very easy way to manage those, unless you actually know where you have put them. So it is very inflexible. In the rest, you have a lot of playbooks that you can do and you can do lots of automation, which is actually easy to manage from what I have seen from my colleagues.
JW
Senior Security Engineer at a financial services firm with 10,001+ employees
Centralized endpoint protection has strengthened compliance and accelerated incident response
There are a number of areas that I only touch a handful of times, but when I get in there, I realize why I don't do that. The main area would be within the support area. The support bot is not really as smart as you would expect it, especially in this day and age of LLM and other capabilities that I know CrowdStrike Falcon is already capable of doing. Additionally, I would appreciate a little bit more easy to read insights of some of the dashboards or maybe manipulation of the dashboards. It is still a little cumbersome to build custom dashboards and it's not as intuitive as you would think. Documentation is abysmal and needs to be improved dramatically. I know that there's a big effort to do this, however, even the new effort is honestly worse than it was before. Those are definitely major areas of improvement, just more in the usability of the features.
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
913,806 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
10%
Manufacturing Company
10%
Computer Software Company
9%
Government
6%
Financial Services Firm
10%
Outsourcing Company
9%
Manufacturing Company
9%
Computer Software Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise2
Large Enterprise5
By reviewers
Company SizeCount
Small Business58
Midsize Enterprise46
Large Enterprise83
 

Questions from the Community

What is your experience regarding pricing and costs for Cortex XSIAM?
I did not participate in pricing discussions for Cortex XSIAM solutions, so I cannot provide a review regarding prices for this solution.
What needs improvement with Cortex XSIAM?
The firewall side can make some improvements. I know the firewall on Cortex XSIAM is based on Windows. From what I have experienced so far, I have seen that the policies you can create are actually...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions that are very scalable, secure, and user-friendly. Cortex XDR by Palo Alto offers ...
How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing user interface that makes setup easy and seamless. CrowdStrike Falcon offers a cl...
How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
The CrowdStrike solution delivers a lot of information about incidents. It has a very light sensor that will never push your machine hardware to "test", you don't have the usual "scan now" feature ...
 

Also Known As

No data available
CrowdStrike Falcon XDR, CrowdStrike Falcon Threat Intelligence, CrowdStrike Identity Protection, CrowdStrike Falcon Surface, CrowdStrike Falcon Platform
 

Overview

Find out what your peers are saying about Splunk, IBM, Microsoft and others in Security Information and Event Management (SIEM). Updated: September 2026.
913,806 professionals have used our research since 2012.