No more typing reviews! Try our Samantha, our new voice AI agent.

Cortex XSIAM vs NetWitness Platform comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XSIAM
Ranking in Security Information and Event Management (SIEM)
13th
Average Rating
8.6
Reviews Sentiment
6.7
Number of Reviews
16
Ranking in other categories
Identity Threat Detection and Response (ITDR) (6th), AI-Powered Cybersecurity Platforms (8th)
NetWitness Platform
Ranking in Security Information and Event Management (SIEM)
35th
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
36
Ranking in other categories
Log Management (36th)
 

Mindshare comparison

As of October 2026, in the Security Information and Event Management (SIEM) category, the mindshare of Cortex XSIAM is 1.4%, down from 2.8% compared to the previous year. The mindshare of NetWitness Platform is 1.2%, up from 0.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
Cortex XSIAM1.4%
NetWitness Platform1.2%
Other97.4%
Security Information and Event Management (SIEM)
 

Featured Reviews

reviewer2541030 - PeerSpot reviewer
Cybersecurity Architect at a computer software company with 10,001+ employees
Unified security monitoring has simplified incident response and improved automated threat handling
The firewall side can make some improvements. I know the firewall on Cortex XSIAM is based on Windows. From what I have experienced so far, I have seen that the policies you can create are actually very in-depth. I mean, you can do most of the things and a lot of integration that you actually want. So if I want to choose to send things to WildFire, for example, I can choose to send it, I can choose to not send it. This basically offers flexibility to implement Cortex XSIAM in more standardized places where you maybe have a certification. I would say that the thing that maybe needs a bit more improvement is the fact that the one with the firewall because I have seen some things there that are kind of hard to manage. You do not really have a very easy way to manage those, unless you actually know where you have put them. So it is very inflexible. In the rest, you have a lot of playbooks that you can do and you can do lots of automation, which is actually easy to manage from what I have seen from my colleagues.
reviewer1130436 - PeerSpot reviewer
Information Technology Security and Infrastructure Expert at a government with 201-500 employees
Helps to deal with potential attacks and is available at a reasonable price
My company has had many benefits from the use of the product in the last eight years. The tool has streamlined our company's incident response process since it serves as a log repository, which allows us to correlate events and access different technology stacks. In our company, we were able to actually find some potential attacks, so it has been very helpful. The tool's integration capability isn't so great. In my company, we managed to integrate it with our Microsoft Azure Subscription, after which we managed to integrate it with other tools. You will face a lot of difficulties if you want to integrate it with your database monitoring tool, PAM solutions, or IAM products. The product has done well overall for my company's teams to deal with their workflow efficiency. I would not recommend the product to others. I rate the tool a seven out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"One of the valued aspects of the product is its use of artificial intelligence to detect security vulnerabilities."
"The flexibility for creating manual workflows stands out."
"The automation capabilities significantly improve response times by allowing us to respond to incidents from a single dashboard rather than navigating multiple dashboards."
"I would give Cortex XSIAM a rating of ten out of ten."
"It does a better job of identifying anomalies that are more likely to be incidents of compromise without as many false positives or false negatives."
"The most valuable features of Cortex XSIAM are the machine learning used to identify threats, the complexity of the environment of products, and efficiency."
"The most valuable feature is the integration capability."
"For me, to have Cortex XSIAM available is to basically have integration of all log sources, all alerting, and so on and so forth from firewalls and different tools, to get everything in one place, and afterwards to be able to build on the information that is coming."
"The most valuable feature is the security that it provides."
"The most valuable features are the packet inspection and the automated incident response."
"The product has a user-friendly interface and a valuable feature for threat intelligence integration."
"Alerting Module: It provides real-time event processing language on all the logs/packets stream for advanced alerting, i.e., using SQL LIKE statements."
"Since the solution has been under way we have seen a large decrease of threats and proactive reactions to incidents."
"Thanks to this tool, we have a small SOC running in our company."
"Possibility to investigate incidents based on logs and raw packets, such as extracting files sent over the network"
"Overall, it is easy to implement."
 

Cons

"Cortex could improve the detection and online resolution of security vulnerabilities."
"I am not sure if any improvements are needed right now."
"The support could be a bit faster."
"At the beginning, we experienced some difficulties setting up the product with connectivity and infrastructure, but ultimately it functioned really effectively."
"Cortex XSIAM needs improvements in terms of data onboarding, parsers, and third-party integration supports."
"There is room for improvement in expanding integrations to include more cybersecurity solutions."
"Cortex XSIAM is pretty expensive, and the licensing process is not very comfortable compared to CrowdStrike."
"I would rate the overall stability a six or seven, as we have only used it for a few months and need a year of experience to provide a full assessment."
"The implementation needs assistance."
"More customizability is required, which is something that they need to improve on."
"The multi-tenant capabilities are lagging compared to IBM QRadar."
"An area for improvement would be better automation and more inbuilt use cases."
"The tool's integration capability isn't so great."
"The initial setup is complex. There are other solutions that are easier to implement."
"I believe they could improve their support, there are often delays."
"Lots of competing products have vulnerability protection built into their products, and this solution would be improved by including that support."
 

Pricing and Cost Advice

"The product cost could be considered value for money compared to other solutions in the market, though it is quite high."
"The solution is expensive compared to its competitors."
"The solution comes at a significant cost."
"In terms of pricing, we found Cortex XSIAM to offer a very reasonable and competitive rate."
"Since Palo Alto is trying to get as many new customers as possible, they're offering very competitive pricing."
"The new pricing and licensing mechanisms are fair. I would advise always to get the full solution (i.e., not only Logs)."
"The NetWitness Platform may be affordable only for enterprise-level customers, as it may not be within the budget of small and medium-sized businesses."
"RSA NetWitness Logs and Packets do not have a subscription model, it's a one-time purchase. There is only a perpetual license."
"It’s cheaper to run virtual machines in a VMware environment."
"Our license is for one year."
"It provides tools to assist in selecting the appropriate license and usage scenarios."
"In comparison to other SIEM solutions such as Splunk, NetWitness is less costly."
"This is a pricey solution; it's not cheap."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
915,341 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
11%
Manufacturing Company
10%
Computer Software Company
9%
Outsourcing Company
6%
Construction Company
12%
Financial Services Firm
11%
Comms Service Provider
10%
Outsourcing Company
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise3
Large Enterprise5
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise7
Large Enterprise20
 

Questions from the Community

What is your experience regarding pricing and costs for Cortex XSIAM?
I did not participate in pricing discussions for Cortex XSIAM solutions, so I cannot provide a review regarding prices for this solution.
What needs improvement with Cortex XSIAM?
The firewall side can make some improvements. I know the firewall on Cortex XSIAM is based on Windows. From what I have experienced so far, I have seen that the policies you can create are actually...
What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem ), though there could be potential enhancements by integrating with AI.
What is your primary use case for NetWitness Platform?
I use NetWitness Platform ( /products/netwitness-platform-reviews ) in the financial industry as a good product with excellent capabilities and integration with various devices.
 

Also Known As

No data available
RSA Security Analytics
 

Overview

 

Sample Customers

Information Not Available
Los Angeles World Airports, Reply
Find out what your peers are saying about Cortex XSIAM vs. NetWitness Platform and other solutions. Updated: September 2026.
915,341 professionals have used our research since 2012.