Try our new research platform with insights from 80,000+ expert users

Cortex XSIAM vs Vectra AI comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Nov 5, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
4.6
Cortex XSIAM enhances incident management and provides significant financial returns by automating detection and response, reducing staffing needs.
Sentiment score
6.9
Companies using Vectra AI saw increased security efficiency, reduced costs, and improved productivity with faster, effective threat response.
The payback period is roughly six months.
Strategic RAN Lead | Network Transformation & Optimization | Philippines & South Africa at a tech vendor with 10,001+ employees
 

Customer Service

Sentiment score
5.8
Cortex XSIAM support varies; premium service excels, while non-premium experiences depend on distributor expertise and sometimes face delays.
Sentiment score
8.0
Users generally find Vectra AI's support team responsive and knowledgeable, despite occasional delays, rating their experience highly.
With premium support, core Palo Alto technical experts handle issues directly.
Team Lead, Security at seamlessinfotech.com
It is ineffective in terms of responding to basic queries and addressing future requirements.
Associate Director at a financial services firm with 5,001-10,000 employees
The Palo Alto support team is fully responsive and helpful.
SOC Analyst at OVELOSEC
The support is quite reliable depending on the service engineer assigned.
Cyber Security Engineer at a tech services company with 1,001-5,000 employees
When I create tickets, the response is fast, and issues are solved promptly.
Planning& Performance Analyst at National Information Center, Ministry of Interior, Saudi Arabia
Customer support receives a rating of nine out of ten due to being very supportive and responding quite efficiently.
Strategic RAN Lead | Network Transformation & Optimization | Philippines & South Africa at a tech vendor with 10,001+ employees
 

Scalability Issues

Sentiment score
6.5
Cortex XSIAM is scalable for various business sizes with cloud-based integration, but lacks on-premises deployment and mixed reviews.
Sentiment score
7.3
Vectra AI excels in scalable deployments and adaptability across environments, handling diverse network sizes with ongoing feature enhancements.
Without proper integration, scaling up with more servers is meaningless.
Associate Director at a financial services firm with 5,001-10,000 employees
Cortex XSIAM is highly scalable.
SOC Analyst at OVELOSEC
Vectra AI is scalable because it can work through different kinds of solutions and is compatible with all kinds of cloud solutions.
Strategic RAN Lead | Network Transformation & Optimization | Philippines & South Africa at a tech vendor with 10,001+ employees
 

Stability Issues

Sentiment score
7.6
Cortex XSIAM is praised for its stability, rapid issue resolution, and efficient performance despite minor post-update challenges.
Sentiment score
8.0
Vectra AI is reliable and stable with efficient performance, minimal downtime, and swift resolutions for occasional hardware issues.
The product was easy to install and set up and worked right.
Owner at Xelere
Overall, Cortex XSIAM is stable.
SOC Analyst at OVELOSEC
It works really nice and performs really efficiently after configuration.
IT COMMUNICATIONS AND NETWORKS at Américas BPS
 

Room For Improvement

Cortex XSIAM needs improved integration, performance, interface, pricing, support, ASM, AI, onboarding, tagging, and identity management enhancements.
Vectra AI needs improved threat precision, integration, architecture, and expanded threat detection to better support SOC teams.
Obtaining validation for integrations from Palo Alto takes around eight months, which is quite long.
Associate Director at a financial services firm with 5,001-10,000 employees
Cortex XSIAM needs improvements in terms of data onboarding, parsers, and third-party integration supports.
SOC Analyst at OVELOSEC
Cortex XSIAM is on the expensive side and requires substantial improvement in pricing.
Solutions Architect at ostec
ExtraHop's ability to decrypt encrypted data is a feature that Vectra AI lacks.
Planning& Performance Analyst at National Information Center, Ministry of Interior, Saudi Arabia
You need to have a Linux server, and from the Linux server, you must perform AI tasks, and there is a lot to be handled in the back end.
Owner at Fortibits
All threats, including hacking attempts, should be comprehensively addressed.
Consultant at a retailer with 5,001-10,000 employees
 

Setup Cost

Cortex XSIAM is viewed as competitively priced but complex, aligning with market expectations despite some regional variations.
Vectra AI is expensive but competitive, valued for quality despite complex licensing and added cloud solution costs.
The first impression is that XSIAM would be more expensive than others we tried.
Owner at Xelere
The product is very expensive.
Associate Director at a financial services firm with 5,001-10,000 employees
Cortex XSIAM is pretty expensive, and the licensing process is not very comfortable.
Director at MICROLOGIC NETWORKS PRIVATE LIMITED
Vectra is cheaper in terms of pricing and features compared to Darktrace.
Cyber Security Engineer at a tech services company with 1,001-5,000 employees
It is very acceptable when you compare it with Darktrace, for example.
Owner at Fortibits
 

Valuable Features

Cortex XSIAM excels in machine learning threat detection, SOAR features, and advanced automation for efficient security management.
Vectra AI enhances threat management with AI-driven detection, alert reduction, tool integration, user interface, and real-time response.
The advanced visualization capabilities of the product are important for understanding security trends in an organization.
Solutions Architect at ostec
One of the valued aspects of the product is its use of artificial intelligence to detect security vulnerabilities.
Owner at Xelere
The flexibility for creating manual workflows stands out.
Associate Director at a financial services firm with 5,001-10,000 employees
Our company used Vectra AI to detect the malicious threats and viruses before they could cause more damage, and we successfully stopped the threats.
Consultant at a retailer with 5,001-10,000 employees
Alert noise was dramatically reduced by nearly 80%, allowing SOC analysts to focus more on true threats, which made them more productive and resulted in higher operational efficiency.
Strategic RAN Lead | Network Transformation & Optimization | Philippines & South Africa at a tech vendor with 10,001+ employees
There are extensive out-of-box detection capabilities.
Owner at Fortibits
 

Categories and Ranking

Cortex XSIAM
Ranking in Identity Threat Detection and Response (ITDR)
7th
Ranking in AI-Powered Cybersecurity Platforms
8th
Average Rating
8.6
Reviews Sentiment
6.7
Number of Reviews
15
Ranking in other categories
Security Information and Event Management (SIEM) (13th)
Vectra AI
Ranking in Identity Threat Detection and Response (ITDR)
11th
Ranking in AI-Powered Cybersecurity Platforms
6th
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
47
Ranking in other categories
Intrusion Detection and Prevention Software (IDPS) (5th), Network Detection and Response (NDR) (2nd), Extended Detection and Response (XDR) (16th)
 

Mindshare comparison

As of December 2025, in the Identity Threat Detection and Response (ITDR) category, the mindshare of Cortex XSIAM is 5.3%, up from 4.2% compared to the previous year. The mindshare of Vectra AI is 2.4%, up from 1.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Identity Threat Detection and Response (ITDR) Market Share Distribution
ProductMarket Share (%)
Cortex XSIAM5.3%
Vectra AI2.4%
Other92.3%
Identity Threat Detection and Response (ITDR)
 

Featured Reviews

reviewer2666148 - PeerSpot reviewer
Associate Director at a financial services firm with 5,001-10,000 employees
Integration challenges highlight the need for manual workflows
The standard integrations are very limited, and the integrations available are not listed in the marketplace. Obtaining validation for integrations from Palo Alto takes around eight months, which is quite long. The solution would benefit from having more standard playbooks and templates available, as in other partners. Currently, everything must be created from scratch. In terms of incident response automation, it is quite poor due to the lack of integration with all security tools, making manual intervention necessary.
RR
Consultant at a retailer with 5,001-10,000 employees
Threat detection has improved and malicious emails are now identified quickly
Vectra AI offers artificial intelligence capabilities with visibility that can be integrated into our day-to-day operations and other tools, including malware detection tools and cyber threat tools. Vectra AI has positively impacted my organization. Last year while using it, we received many malicious email threats and virus incidents, including a trojan virus that had reportedly been deployed by someone. Our company used Vectra AI to detect the malicious threats and viruses before they could cause more damage, and we successfully stopped the threats. Using Vectra AI, I notice that server downtime has decreased significantly. We now experience only two to three hours of downtime, whereas without Vectra AI and other tools, our downtime would exceed 48 to 72 hours.
report
Use our free recommendation engine to learn which Identity Threat Detection and Response (ITDR) solutions are best for your needs.
879,259 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Financial Services Firm
10%
Manufacturing Company
9%
Government
7%
Computer Software Company
11%
Financial Services Firm
10%
Manufacturing Company
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise2
Large Enterprise4
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise10
Large Enterprise29
 

Questions from the Community

What do you like most about Cortex XSIAM?
It is an effective solution in terms of performance and functionalities.
What is your experience regarding pricing and costs for Cortex XSIAM?
I did not participate in pricing discussions for Cortex XSIAM solutions, so I cannot provide a review regarding prices for this solution.
What needs improvement with Cortex XSIAM?
Cortex XSIAM is on the expensive side and requires substantial improvement in pricing. There are other features that could be improved, including integration with vendors such as CyberArk. I would ...
What is the biggest difference between Corelight and Vectra AI?
The two platforms take a fundamentally different approach to NDR. Corelight is limited to use cases that require the eventual forwarding of events and parsed data logs to a security team’s SIEM or ...
What do you like most about Vectra AI?
The solution is currently used as a central threat detection and response system.
What is your experience regarding pricing and costs for Vectra AI?
It is very acceptable when you compare it with Darktrace, for example.
 

Also Known As

No data available
Vectra Networks, Vectra AI NDR
 

Overview

 

Sample Customers

Information Not Available
Tribune Media Group, Barry University, Aruba Networks, Good Technology, Riverbed, Santa Clara University, Securities Exchange, Tri-State Generation and Transmission Association
Find out what your peers are saying about Cortex XSIAM vs. Vectra AI and other solutions. Updated: December 2025.
879,259 professionals have used our research since 2012.