No more typing reviews! Try our Samantha, our new voice AI agent.

Cortex XSIAM vs Palo Alto Networks Cortex XSOAR comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
4.3
Cortex XSIAM achieved savings over $500,000 by automating over half of detection and response, optimizing incident management.
Sentiment score
5.0
Palo Alto Networks Cortex XSOAR automates 90% of SOC tasks, enhancing efficiency and providing significant cybersecurity management value.
By implementing Palo Alto Networks Cortex XSOAR playbooks, I automated repetitive SOC tasks such as IOC enrichment, alert triggers, host isolation, and incident ticket creation.
Cybersecurity Senior Analyst
We are positioning Palo Alto Networks Cortex XSOAR, which can be used in the SOC and do a lot of automation for the customer.
Vice President, Technology at Cache Digitech Pvt Ltd.
Palo Alto Networks Cortex XSOAR is a pure and proven technology product and cybersecurity product, customers will get more ROI when compared with others.
Technical Consultant at Vertex Techno Solutions (B) Pvt Ltd
 

Customer Service

Sentiment score
6.1
Cortex XSIAM technical support experiences vary, with premium support praised for expertise, while distributor-based support quality fluctuates.
Sentiment score
6.5
Palo Alto Networks Cortex XSOAR support is praised for expertise and responsiveness, though some experience variability and time zone delays.
With premium support, core Palo Alto technical experts handle issues directly.
Team Lead, Security at seamlessinfotech.com
It is ineffective in terms of responding to basic queries and addressing future requirements.
Associate Director at a financial services firm with 5,001-10,000 employees
I had a dedicated person allocated for supporting, and even with them, it was very good.
Cybersecurity Architect at a computer software company with 10,001+ employees
Eight out of ten times, they provide valuable help.
Lead Application Security Engineer Iv at a financial services firm with 5,001-10,000 employees
I would rate the customer support for Palo Alto Networks Cortex XSOAR as 9 out of 10.
Senior security analyst at a manufacturing company with 10,001+ employees
Have the person that you hire know more about the product than the person on the phone.
Noc Network Engineer at a outsourcing company with 51-200 employees
 

Scalability Issues

Sentiment score
6.6
Cortex XSIAM excels in scalability and cloud deployment, though integration affects performance and some prefer more on-premises functionality.
Sentiment score
7.0
Palo Alto Networks Cortex XSOAR is favored for scalability, seamlessly integrating tools and managing environments, despite minor integration challenges.
Without proper integration, scaling up with more servers is meaningless.
Associate Director at a financial services firm with 5,001-10,000 employees
The SOC team is responsible for fully managing Cortex XSIAM.
Cybersecurity Architect at a computer software company with 10,001+ employees
Cortex XSIAM is highly scalable.
SOC Analyst at OVELOSEC
The scalability of Palo Alto Networks Cortex XSOAR supports our growth and security needs because we can integrate various tools and continuously add more capability.
Enterprise Security Architect V at FirstEnergy
Palo Alto Networks Cortex XSOAR has very good application capabilities and is highly scalable.
Assistant Security Architect at Cloudnomics
The issues with scalability arise from the speed of some integrations, as not all are perfectly tuned by Palo.
Lead Application Security Engineer Iv at a financial services firm with 5,001-10,000 employees
 

Stability Issues

Sentiment score
7.5
Cortex XSIAM is cloud-based, reliable, with minimal maintenance, and occasional update issues are quickly resolved, enhancing performance.
Sentiment score
7.7
Palo Alto Networks Cortex XSOAR is stable and reliable, with minor issues often linked to plugins, updates, and configuration.
The product was easy to install and set up and worked right.
Owner at Xelere
With continuous integration that the colleagues probably are doing, it is becoming better and better.
Cybersecurity Architect at a computer software company with 10,001+ employees
Overall, Cortex XSIAM is stable.
SOC Analyst at OVELOSEC
The system works smoothly even when I navigate deep into the playbook section.
Assistant Security Architect at Cloudnomics
As a leading partner, I do not anticipate any issues with stability or scalability.
Technical Consultant at Vertex Techno Solutions (B) Pvt Ltd
I would rate the stability and reliability of Palo Alto Networks Cortex XSOAR as a nine.
Lead Application Security Engineer Iv at a financial services firm with 5,001-10,000 employees
 

Room For Improvement

Cortex XSIAM needs better integration, usability, pricing, data management, and support for enhanced performance and flexibility.
Palo Alto Networks Cortex XSOAR struggles with high costs, complex deployment, and limited integrations, prompting calls for improvements.
Obtaining validation for integrations from Palo Alto takes around eight months, which is quite long.
Associate Director at a financial services firm with 5,001-10,000 employees
Cortex XSIAM needs improvements in terms of data onboarding, parsers, and third-party integration supports.
SOC Analyst at OVELOSEC
Cortex XSIAM is on the expensive side and requires substantial improvement in pricing.
Solutions Architect at ostec
The biggest area for improvement is simplifying playbook development and debugging.
Cybersecurity Senior Analyst
The deployment requires integration and the development of integration modules.
Presale Engineer at Westcon-Comstor
One of the significant issues we encounter is system slowdown when we receive an influx of alerts, which inhibits how quickly we can access the information needed for investigation.
Enterprise Security Architect V at FirstEnergy
 

Setup Cost

Cortex XSIAM is expensive with variable pricing, complexity in licensing, and additional costs for functionalities and resources.
Cortex XSOAR is costly but valued for efficiency, best suited for medium to large enterprises with dedicated security teams.
The first impression is that XSIAM would be more expensive than others we tried.
Owner at Xelere
The product is very expensive.
Associate Director at a financial services firm with 5,001-10,000 employees
Cortex XSIAM is pretty expensive, and the licensing process is not very comfortable.
Director at MICROLOGIC NETWORKS PRIVATE LIMITED
For customers, it is zero versus $20 million, which is why they have to make a decision.
Vice President, Technology at Cache Digitech Pvt Ltd.
Being among the market leaders, it is worth the money, though still a bit pricey.
Security Engineer at a financial services firm with 51-200 employees
The price will be high, but the solution is absolutely superb.
VP Of Digital Transformation at Netsys Solutions (Pvt) Ltd
 

Valuable Features

Cortex XSIAM enhances incident response with automation, integration, and machine learning, providing comprehensive network security and threat identification.
Cortex XSOAR by Palo Alto Networks enhances security operations through automation, integration, and reduced response times with advanced analytics.
The advanced visualization capabilities of the product are important for understanding security trends in an organization.
Solutions Architect at ostec
To have Cortex XSIAM available is to basically have integration of all log sources, all alerting, and so on and so forth from firewalls and different tools, to get everything in one place, and afterwards to be able to build on the information that is coming.
Cybersecurity Architect at a computer software company with 10,001+ employees
One of the valued aspects of the product is its use of artificial intelligence to detect security vulnerabilities.
Owner at Xelere
Execution of automatic tasks for collecting, enriching, and correlating security events from hundreds of different technologies.
Presale Engineer at Westcon-Comstor
If I already have an established process, I do not have to change my process to fit into the tool. I can modify the tool to fit into my process, which makes things considerably easier.
Enterprise Security Architect V at FirstEnergy
We have implemented automation features, such as automated responses to email threats and automatic configuration of target devices for blocking specific IPs.
Vice President, Technology at Cache Digitech Pvt Ltd.
 

Categories and Ranking

Cortex XSIAM
Average Rating
8.6
Reviews Sentiment
6.7
Number of Reviews
16
Ranking in other categories
Security Information and Event Management (SIEM) (14th), Identity Threat Detection and Response (ITDR) (6th), AI-Powered Cybersecurity Platforms (8th)
Palo Alto Networks Cortex X...
Average Rating
8.4
Reviews Sentiment
6.5
Number of Reviews
62
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (2nd), SOC as a Service (2nd)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Cortex XSIAM is designed for Security Information and Event Management (SIEM) and holds a mindshare of 1.4%, down 2.8% compared to last year.
Palo Alto Networks Cortex XSOAR, on the other hand, focuses on Security Orchestration Automation and Response (SOAR), holds 8.8% mindshare, down 9.7% since last year.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
Cortex XSIAM1.4%
Splunk Enterprise Security7.8%
IBM Security QRadar5.6%
Other85.2%
Security Information and Event Management (SIEM)
Security Orchestration Automation and Response (SOAR) Mindshare Distribution
ProductMindshare (%)
Palo Alto Networks Cortex XSOAR8.8%
Microsoft Sentinel9.1%
Splunk SOAR7.0%
Other75.1%
Security Orchestration Automation and Response (SOAR)
 

Featured Reviews

reviewer2541030 - PeerSpot reviewer
Cybersecurity Architect at a computer software company with 10,001+ employees
Unified security monitoring has simplified incident response and improved automated threat handling
The firewall side can make some improvements. I know the firewall on Cortex XSIAM is based on Windows. From what I have experienced so far, I have seen that the policies you can create are actually very in-depth. I mean, you can do most of the things and a lot of integration that you actually want. So if I want to choose to send things to WildFire, for example, I can choose to send it, I can choose to not send it. This basically offers flexibility to implement Cortex XSIAM in more standardized places where you maybe have a certification. I would say that the thing that maybe needs a bit more improvement is the fact that the one with the firewall because I have seen some things there that are kind of hard to manage. You do not really have a very easy way to manage those, unless you actually know where you have put them. So it is very inflexible. In the rest, you have a lot of playbooks that you can do and you can do lots of automation, which is actually easy to manage from what I have seen from my colleagues.
EricRise - PeerSpot reviewer
Noc Network Engineer at a outsourcing company with 51-200 employees
Automation playbooks have reduced soc noise and now streamline daily incident response
To improve Palo Alto Networks Cortex XSOAR, there can be a learning curve to it. It is not a very user-friendly product; it is complex. It handles debugs and automation playbooks. You have to really spend some time dedicated to learning the product, scripting, and acquiring your certifications on it. Cost is another item as well. That can be quite significant; it does depend on other tools for EDR, whether you are using Palo Alto's XDR system or any number of third-party products for that. There are some reporting and logging restrictions and limitations. Some of those are going to be constraints, including window size limits. Database use with it has limited scalability for that type of application.
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
912,006 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
10%
Manufacturing Company
10%
Computer Software Company
9%
Government
6%
Financial Services Firm
13%
Manufacturing Company
8%
Computer Software Company
7%
Comms Service Provider
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise2
Large Enterprise5
By reviewers
Company SizeCount
Small Business27
Midsize Enterprise9
Large Enterprise32
 

Questions from the Community

What is your experience regarding pricing and costs for Cortex XSIAM?
I did not participate in pricing discussions for Cortex XSIAM solutions, so I cannot provide a review regarding prices for this solution.
What needs improvement with Cortex XSIAM?
The firewall side can make some improvements. I know the firewall on Cortex XSIAM is based on Windows. From what I have experienced so far, I have seen that the policies you can create are actually...
What is your experience regarding pricing and costs for Palo Alto Networks Cortex XSOAR?
We can quantify the reduction. It is more than sixty to seventy percent reduction in the MTTR, as per documents from Palo Alto, and with proper implementation, we can improve MTTR by up to sixty-fi...
What needs improvement with Palo Alto Networks Cortex XSOAR?
The negative aspect of Palo Alto Networks Cortex XSOAR is the price; cost-wise, it is a bit higher. Other than enterprise clients, they might need to push their management to get additional approva...
What is your primary use case for Palo Alto Networks Cortex XSOAR?
We are a partner for Palo Alto as a service provider. Palo Alto Networks Cortex XSOAR is used as a SIEM solution or XDR-type solutions.
 

Also Known As

No data available
Demisto Enterprise, Cortex XSOAR, Demisto
 

Overview

 

Sample Customers

Information Not Available
Cellcom Israel, Blue Cross and Blue Shield of Kansas City, esri, Cylance, Flatiron Health, Veeva, ADT Cybersecurity
Find out what your peers are saying about Splunk, IBM, Microsoft and others in Security Information and Event Management (SIEM). Updated: September 2026.
912,006 professionals have used our research since 2012.