

Cortex XSIAM and Huntress Managed SIEM compete in the cybersecurity sector, providing threat detection and response solutions. Cortex XSIAM seems to have the upper hand with competitive pricing and strong customer support, while Huntress Managed SIEM's edge lies in its robust features.
Features: Cortex XSIAM enhances threat detection accuracy with its automated incident response, AI-driven analytics, and efficiency in managing security operations. Huntress Managed SIEM's strengths include a user-friendly dashboard, advanced threat hunting capabilities, and proactive threat management.
Ease of Deployment and Customer Service: Cortex XSIAM offers an efficient deployment process supported by comprehensive integration assistance. Huntress Managed SIEM provides a straightforward deployment with active customer support that reduces onboarding time, focusing on accessibility.
Pricing and ROI: Cortex XSIAM offers a competitive initial cost structure, enhancing ROI through advanced automation. Huntress Managed SIEM has a higher perceived cost, justified by its comprehensive threat detection features over time.
I can expect an estimated five to twenty times return on investment with this solution.
The value is not just the time saved; it also allows the team to spend more of its capacity on higher-priority security investigations and other proactive security work.
Faster threat detection and investigation can potentially reduce the financial impact of security incidents.
With premium support, core Palo Alto technical experts handle issues directly.
It is ineffective in terms of responding to basic queries and addressing future requirements.
I had a dedicated person allocated for supporting, and even with them, it was very good.
You are communicating to tier one and tier two people who are then communicating on the back end, so you are not getting updates as frequently.
For a managed security platform, having responsive support is important, and our experience has been positive.
Having access to the managed SOC also gives us confidence that we have expert support available when needed.
Without proper integration, scaling up with more servers is meaningless.
The SOC team is responsible for fully managing Cortex XSIAM.
Cortex XSIAM is highly scalable.
It struggles with scalability when dealing with high logs, multi-site, multi-tenant setups, and large volumes of endpoints.
The managed approach is particularly helpful in this regard because the security team does not have to spend a lot of time maintaining the underlying SIEM infrastructure.
The centralized log collection and smart filtering also help keep data volume and alert noise manageable as workload increases.
The product was easy to install and set up and worked right.
With continuous integration that the colleagues probably are doing, it is becoming better and better.
Overall, Cortex XSIAM is stable.
From an operational standpoint, it has been dependable enough that the team can use it as a part of our regular security monitoring without having to worry about frequent service interruptions or maintenance issues.
Huntress Managed SIEM is very stable.
Huntress Managed SIEM is stable and reliable for our day-to-day SOC operations.
Obtaining validation for integrations from Palo Alto takes around eight months, which is quite long.
Cortex XSIAM needs improvements in terms of data onboarding, parsers, and third-party integration supports.
Cortex XSIAM is on the expensive side and requires substantial improvement in pricing.
It would be helpful to have more flexibility for creating custom detection rules, dashboards, and alert workflows based on specific organizational requirements.
It is very important for our organization that Huntress Managed SIEM offers security and compliance solutions without complexity because we do not want a product that is generally too difficult to use.
I would like Huntress Managed SIEM to integrate with EDRs like SentinelOne to combine that level of intelligence and information into their stack.
The first impression is that XSIAM would be more expensive than others we tried.
The product is very expensive.
Cortex XSIAM is pretty expensive, and the licensing process is not very comfortable.
I believe most competitors charge by the data slightly differently compared to how this solution does, as it is per data source rather than data size in gigabytes.
I did not have to spend more than what I initially budgeted for.
My experience with pricing, setup cost, and licensing is that everything was pretty easy to do
The advanced visualization capabilities of the product are important for understanding security trends in an organization.
To have Cortex XSIAM available is to basically have integration of all log sources, all alerting, and so on and so forth from firewalls and different tools, to get everything in one place, and afterwards to be able to build on the information that is coming.
One of the valued aspects of the product is its use of artificial intelligence to detect security vulnerabilities.
Huntress Managed SIEM combines machine detection with human investigation, which adds context and helps confirm if something is actually a threat rather than just noise.
Regarding the feature that requires no alert tuning, we are using the advanced filtering so we only see actionable events and not lots of noise, which filters out any false positives or areas of no concern.
Huntress Managed SIEM has helped in both angles, improving efficiency in SOC operations where the mean time to detect is drastically reduced.
| Product | Mindshare (%) |
|---|---|
| Huntress Managed SIEM | 1.1% |
| Cortex XSIAM | 1.4% |
| Other | 97.5% |
| Company Size | Count |
|---|---|
| Small Business | 8 |
| Midsize Enterprise | 3 |
| Large Enterprise | 5 |
| Company Size | Count |
|---|---|
| Small Business | 11 |
| Midsize Enterprise | 3 |
| Large Enterprise | 7 |
Cortex XSIAM acts as a critical element for SOC foundations, integrating SIEM and EDR capabilities, valued for threat detection and seamless security orchestration with Palo Alto Networks products.
Organizations find Cortex XSIAM beneficial for SOC foundations due to its capability to integrate SIEM and EDR tools, facilitating data collection, detection, and response. It connects with third-party data sources while reducing management effort and offering cost-effective alternatives to competitors like CrowdStrike and Trend Micro. Featuring automation and integration with Palo Alto Networks products, Cortex XSIAM enhances threat detection. Unified architecture allows a comprehensive view of attacks, further supported by machine learning and integration with existing vendor solutions, ensuring that users gain insights without significant manual log analysis.
What are Cortex XSIAM's key features?
What benefits are evident in Cortex XSIAM reviews?
Industries implement Cortex XSIAM mainly in technology-driven sectors where centralized endpoint protection and automation of forensic investigation are paramount. By integrating several third-party systems for incident response, companies in competitive markets leverage its attributes for heightened operational security efficiency. However, users note areas for improvement, such as Attack Surface Management and integration enhancements, to better suit tech-heavy industries needing extensive connectivity with cybersecurity solutions.
Huntress Managed SIEM delivers advanced threat detection and response capabilities tailored for Security Information and Event Management. It addresses cybersecurity challenges with automated monitoring and actionable insights.
Huntress Managed SIEM stands out by offering comprehensive security event monitoring designed for modern cybersecurity landscapes. It identifies potential threats and vulnerabilities, ensuring actionable data for quicker response. Its integration capabilities with existing security infrastructure make it a reliable choice for enhancing cyber defenses and incident resolution.
What are the key features of Huntress Managed SIEM?Huntress Managed SIEM is widely used across industries such as finance, healthcare, and retail, where it is critical to protect sensitive information. Its adaptability to different enterprise needs makes it an ideal choice for strengthening security frameworks in diverse sectors.
We monitor all Security Information and Event Management (SIEM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.