No more typing reviews! Try our Samantha, our new voice AI agent.

Cortex XSIAM vs Expel comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XSIAM
Average Rating
8.6
Reviews Sentiment
6.7
Number of Reviews
15
Ranking in other categories
Security Information and Event Management (SIEM) (13th), Identity Threat Detection and Response (ITDR) (6th), AI-Powered Cybersecurity Platforms (7th)
Expel
Average Rating
9.0
Reviews Sentiment
7.6
Number of Reviews
1
Ranking in other categories
SOC as a Service (4th), Managed Detection and Response (MDR) (16th)
 

Mindshare comparison

Cortex XSIAM and Expel aren’t in the same category and serve different purposes. Cortex XSIAM is designed for Security Information and Event Management (SIEM) and holds a mindshare of 2.0%, down 2.6% compared to last year.
Expel, on the other hand, focuses on Managed Detection and Response (MDR), holds 1.8% mindshare, down 1.8% since last year.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
Cortex XSIAM2.0%
Splunk Enterprise Security7.2%
Wazuh5.8%
Other85.0%
Security Information and Event Management (SIEM)
Managed Detection and Response (MDR) Mindshare Distribution
ProductMindshare (%)
Expel1.8%
CrowdStrike Falcon Complete MDR6.9%
Huntress Managed EDR6.6%
Other84.7%
Managed Detection and Response (MDR)
 

Featured Reviews

JohnTamakloe - PeerSpot reviewer
Solutions Architect at ostec
Efficient coordination improves operations with seamless integration and rapid automation
The typical use cases for Cortex XSIAM are diverse I would describe the impact of Cortex XSIAM's automation on my security operations center as efficient. I use Cortex XSIAM's behavior analytics, and it helps identify unusual activities. I leverage Cortex XSIAM's incident management features for…
reviewer2578461 - PeerSpot reviewer
MDR Specialist at a tech services company with 201-500 employees
Rapid threat management and diverse technology integration for effective monitoring
Expel has made it easier for companies to monitor and manage various log sources. With its vast integration portfolio, customers can efficiently monitor diverse environments. Time to value is quick, as Expel can turn their service up very rapidly. They have both automated active responses and human processes that quicken threat resolution.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I would give Cortex XSIAM a rating of ten out of ten."
"It does a better job of identifying anomalies that are more likely to be incidents of compromise without as many false positives or false negatives."
"The flexibility for creating manual workflows stands out."
"The automation capabilities significantly improve response times by allowing us to respond to incidents from a single dashboard rather than navigating multiple dashboards."
"The most valuable feature is the integration capability."
"It is an effective solution in terms of performance and functionalities."
"The most valuable aspect is that Cortex XSIAM doesn't generate excessive alerts, refines all search results effectively, and filters out incidents where SOC intervention isn't necessary, allowing engineers to focus only on what matters."
"It operates on a single, extensive database which enables it to excel in detecting threats and anomalies across the network and endpoints, delivering a highly effective and comprehensive security solution."
"Their threat hunting protocol and process with AI and machine learning are strong, allowing for active and rapid responses."
 

Cons

"There is room for improvement in expanding integrations to include more cybersecurity solutions."
"Cortex XSIAM needs improvements in terms of data onboarding, parsers, and third-party integration supports."
"Cortex XSIAM is on the expensive side and requires substantial improvement in pricing."
"The standard integrations are very limited, and the integrations available are not listed in the marketplace."
"The support could be a bit faster."
"Cortex XSIAM is pretty expensive, and the licensing process is not very comfortable compared to CrowdStrike."
"It could provide more integration with a large variety of products."
"Cortex XSIAM is on the expensive side and requires substantial improvement in pricing."
"The one area where Expel may not measure up is if a customer requires a managed SIEM as part of their overall solution. There's a gap there, and solutions might require third-party assistance for management."
 

Pricing and Cost Advice

"Since Palo Alto is trying to get as many new customers as possible, they're offering very competitive pricing."
"The solution comes at a significant cost."
"The product cost could be considered value for money compared to other solutions in the market, though it is quite high."
"The solution is expensive compared to its competitors."
"In terms of pricing, we found Cortex XSIAM to offer a very reasonable and competitive rate."
Information not available
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
885,789 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
11%
Financial Services Firm
10%
Manufacturing Company
10%
Government
6%
Financial Services Firm
14%
Computer Software Company
11%
Construction Company
10%
Retailer
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise2
Large Enterprise4
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Cortex XSIAM?
I did not participate in pricing discussions for Cortex XSIAM solutions, so I cannot provide a review regarding prices for this solution.
What needs improvement with Cortex XSIAM?
Cortex XSIAM is on the expensive side and requires substantial improvement in pricing. There are other features that could be improved, including integration with vendors such as CyberArk. I would ...
What is your primary use case for Cortex XSIAM?
With Cortex XSIAM, we installed an agent on Active Directory on-premise. We connected our Firewalls to the Data Lake and the Active Directory, and protected the Firewalls with another authenticatio...
What is your experience regarding pricing and costs for Expel?
Expel's pricing has adapted as the market evolved and has become competitive over the past twelve months.
What needs improvement with Expel?
The one area where Expel may not measure up is if a customer requires a managed SIEM as part of their overall solution. There's a gap there, and solutions might require third-party assistance for m...
What is your primary use case for Expel?
I have experience reselling Expel. Customers often come to me wanting to evaluate multiple providers to make a choice based on their specific use cases, requirements, technology investments, and so...
 

Also Known As

No data available
Workbench, Expel SOC-as-a-Service
 

Overview

 

Sample Customers

Information Not Available
Amanda Fennell CSO
Find out what your peers are saying about Splunk, Wazuh, IBM and others in Security Information and Event Management (SIEM). Updated: March 2026.
885,789 professionals have used our research since 2012.