No more typing reviews! Try our Samantha, our new voice AI agent.

Cortex XSIAM vs Deepwatch comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in AI-Powered Cybersecurity Platforms
1st
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
112
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (6th), Extended Detection and Response (XDR) (4th), Ransomware Protection (2nd)
Cortex XSIAM
Ranking in AI-Powered Cybersecurity Platforms
8th
Average Rating
8.6
Reviews Sentiment
6.7
Number of Reviews
15
Ranking in other categories
Security Information and Event Management (SIEM) (15th), Identity Threat Detection and Response (ITDR) (7th)
Deepwatch
Ranking in AI-Powered Cybersecurity Platforms
13th
Average Rating
8.0
Reviews Sentiment
7.7
Number of Reviews
1
Ranking in other categories
Managed Detection and Response (MDR) (25th)
 

Mindshare comparison

As of June 2026, in the AI-Powered Cybersecurity Platforms category, the mindshare of Cortex XDR by Palo Alto Networks is 11.1%, up from 10.6% compared to the previous year. The mindshare of Cortex XSIAM is 7.9%, down from 9.1% compared to the previous year. The mindshare of Deepwatch is 0.4%, up from 0.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
AI-Powered Cybersecurity Platforms Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks11.1%
Cortex XSIAM7.9%
Deepwatch0.4%
Other80.6%
AI-Powered Cybersecurity Platforms
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
JohnTamakloe - PeerSpot reviewer
Solutions Architect at ostec
Efficient coordination improves operations with seamless integration and rapid automation
The typical use cases for Cortex XSIAM are diverse I would describe the impact of Cortex XSIAM's automation on my security operations center as efficient. I use Cortex XSIAM's behavior analytics, and it helps identify unusual activities. I leverage Cortex XSIAM's incident management features for…
Pranay Jain - PeerSpot reviewer
Senior software engineer at Simplifyvms
Continuous monitoring has strengthened payment security and now reduces incident impact quickly
There are specific details that can be improved in Deepwatch. After implementing it, we tracked both response time and threat detection accuracy using the SIEM dashboard. We measured response time using MTTD and MTTR. There are areas that can be improved, such as every alert having a timestamp for detection time and acknowledgment. We observed the MTTR dropping from a few hours to under one hour after using Deepwatch, so baseline metrics can be enhanced. Deepwatch can reduce alert fatigue since sometimes it generates a high volume of alerts that overwhelm our team. This can create too many alerts in a short amount of time, making it hard for our team to understand what to do. Additionally, the dashboard can be improved for better user-friendliness for end-users, requiring better visualization of MTTR, threat trends, and risk scoring. Improvements can also be made in more automated playbooks for automated response to common threats, and there is room for deeper integration capabilities, as integration with some internal tools may require additional effort.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Cortex XDR is a very capable solution for protecting large networks and a lot of endpoints. It's very useful because the automation is very high, and if you combine it with the features on Palo Alto firewalls, it provides very strong protection."
"Cortex XDR by Palo Alto Networks is easy to use and does not consume a lot of hardware resources."
"Stability is one of the features we like the most."
"Automation and playbooks have helped me significantly, as Cortex Xnor's playbooks predefine the workflow of the automation, such as response processes, alert triggering, and enriching the context, efficiently detecting and blocking malicious attacks with firewalls while eliminating workload and speeding responses for next-generation operations."
"The stability of the solution is very good. We have about 100 users on it right now, and we use it twice a week."
"The product is mostly automated, and we do not have to make decisions, because all the decisions are made by the product itself and we are not required to create any custom policies since the policies that are created are well defined in the product itself."
"The most valuable feature of Cortex XDR by Palo Alto Networks is the low consumption of system resources. The solution uses a lot of AI and machine learning."
"Cortex is a very good total solution on the endpoints."
"I would give Cortex XSIAM a rating of ten out of ten."
"One of the valued aspects of the product is its use of artificial intelligence to detect security vulnerabilities."
"It is an effective solution in terms of performance and functionalities."
"The most valuable feature is the integration capability."
"Cortex XSIAM enhances our ability to apply endpoint protection policies, implement restrictions, conduct scans, and engage in sandboxing."
"Its ability to deliver a substantial amount of security intelligence greatly enhances and optimizes our security operations program."
"The most valuable aspect is that Cortex XSIAM doesn't generate excessive alerts, refines all search results effectively, and filters out incidents where SOC intervention isn't necessary, allowing engineers to focus only on what matters."
"The way the solution responds to detections and warnings is really impressive."
"Deepwatch positively impacts our organization by reducing incident response time because previously, there was no mechanism to follow up on incidents, such as any security breach in the payment gateway, and it has reduced response time by 40 to 60 percent while significantly improving threat detection accuracy with 24/7 monitoring even after business hours."
 

Cons

"The price could be a little lower."
"There are some default policies which sometimes affect our applications and cause them to run around. In the hotel industry, we use a different type of data versus Oracle and SQL. By default, there are some policies which stop us from running properly. Because of this, the support level is also not that strong. We have to wait to get a results."
"Technology evolves every day, so it would be nice if it gets more secure. It can also have more integration with other platforms."
"Dashboards do not allow everyone to see what's happening."
"It's not an ideal choice for smaller businesses, as you need a minimum of 200 endpoints to even use the solution at all."
"When it comes to malware files, it should be a little quick because, at times, it would give a wrong result in the sense of what it might be on malware, even if it still might be a normal one."
"Currently, we are monitoring all USB drives and ports but we would like to improve our device control capabilities."
"Cortex XDR by Palo Alto Networks is not only pricey; it is extremely expensive."
"The standard integrations are very limited, and the integrations available are not listed in the marketplace. Obtaining validation for integrations from Palo Alto takes around eight months, which is quite long."
"The platform isn't very developer-friendly and it should provide more flexibility and ease."
"I am not sure if any improvements are needed right now."
"There is room for improvement in expanding integrations to include more cybersecurity solutions."
"Cortex could improve the detection and online resolution of security vulnerabilities."
"Cortex XSIAM is on the expensive side and requires substantial improvement in pricing."
"The support could be a bit faster."
"It could provide more integration with a large variety of products."
"Deepwatch can reduce alert fatigue since sometimes it generates a high volume of alerts that overwhelm our team."
 

Pricing and Cost Advice

"I am using the Community edition."
"The price was fine."
"It is present, but when compared to other competitive products, I would say it is not less expensive; however, when all of the other added values are considered, the price is reasonable."
"The pricing seems fair, and I do like the licensing model. You use wherever they are, and it is elastic."
"If one wishes to work with another team or large number of users at a future point, he must purchase a license for them."
"The pricing is okay, although direct support can be expensive."
"This is an expensive solution."
"Cortex XDR’s pricing is very reasonable."
"The product cost could be considered value for money compared to other solutions in the market, though it is quite high."
"In terms of pricing, we found Cortex XSIAM to offer a very reasonable and competitive rate."
"Since Palo Alto is trying to get as many new customers as possible, they're offering very competitive pricing."
"The solution comes at a significant cost."
"The solution is expensive compared to its competitors."
Information not available
report
Use our free recommendation engine to learn which AI-Powered Cybersecurity Platforms solutions are best for your needs.
899,125 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
12%
Financial Services Firm
11%
Manufacturing Company
11%
Comms Service Provider
9%
Computer Software Company
11%
Manufacturing Company
10%
Financial Services Firm
9%
Government
6%
Construction Company
30%
Manufacturing Company
13%
Media Company
9%
Healthcare Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise20
Large Enterprise51
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise2
Large Enterprise4
No data available
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What is your experience regarding pricing and costs for Cortex XSIAM?
I did not participate in pricing discussions for Cortex XSIAM solutions, so I cannot provide a review regarding price...
What needs improvement with Cortex XSIAM?
Cortex XSIAM is on the expensive side and requires substantial improvement in pricing. There are other features that ...
What is your primary use case for Cortex XSIAM?
With Cortex XSIAM, we installed an agent on Active Directory on-premise. We connected our Firewalls to the Data Lake ...
What needs improvement with Deepwatch?
There are specific details that can be improved in Deepwatch. After implementing it, we tracked both response time an...
What is your primary use case for Deepwatch?
Deepwatch provides continuous rest monitoring, detection, and response to protect our organization from cyberattacks....
What advice do you have for others considering Deepwatch?
My advice for others considering using Deepwatch is that if someone has an application where security threats are com...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
No data available
No data available
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Information Not Available
Premise Health, Dover, Follett, Genuine Parts Company
Find out what your peers are saying about Palo Alto Networks, CrowdStrike, SentinelOne and others in AI-Powered Cybersecurity Platforms. Updated: May 2026.
899,125 professionals have used our research since 2012.