No more typing reviews! Try our Samantha, our new voice AI agent.

Deepwatch vs Exabeam comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in AI-Powered Cybersecurity Platforms
2nd
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
109
Ranking in other categories
Endpoint Protection Platform (EPP) (5th), Endpoint Detection and Response (EDR) (7th), Extended Detection and Response (XDR) (6th), Ransomware Protection (2nd)
Deepwatch
Ranking in AI-Powered Cybersecurity Platforms
19th
Average Rating
8.0
Reviews Sentiment
8.2
Number of Reviews
1
Ranking in other categories
Managed Detection and Response (MDR) (45th)
Exabeam
Ranking in AI-Powered Cybersecurity Platforms
9th
Average Rating
7.8
Reviews Sentiment
6.6
Number of Reviews
20
Ranking in other categories
Security Information and Event Management (SIEM) (15th), User Entity Behavior Analytics (UEBA) (1st), Security Incident Response (4th), Threat Intelligence Platforms (TIP) (9th), Security Orchestration Automation and Response (SOAR) (11th)
 

Mindshare comparison

As of April 2026, in the AI-Powered Cybersecurity Platforms category, the mindshare of Cortex XDR by Palo Alto Networks is 9.9%, down from 10.9% compared to the previous year. The mindshare of Deepwatch is 0.4%, up from 0.1% compared to the previous year. The mindshare of Exabeam is 3.6%, up from 2.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
AI-Powered Cybersecurity Platforms Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks9.9%
Exabeam3.6%
Deepwatch0.4%
Other86.1%
AI-Powered Cybersecurity Platforms
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
Shivam Dhang - PeerSpot reviewer
IT Infrastructure & Cloud Manager at Softcell Technologies Limited
Continuous monitoring has improved threat detection and reduces incident response time
Deepwatch could improve with more granular customization of detection rules and alert tuning to better fit specific cloud workloads and use cases. Additionally, it can be improved by enhancing the dashboarding. It should also support deeper cloud-native integrations such as AWS, Azure, and GCP, which would further improve operational efficiency and control. Regarding the support, I would say that the support team should be more responsive because ideally, the response time of the support is quite long, which is sometimes frustrating. However, I do agree that for easy issues, they respond within the expected time, but for complex issues, they do take time to respond.
DH
Solution Architect at CTC
Improved threat detection has provided clear user risk insights and streamlined incident response
Exabeam's UEBA is the most valuable feature that I have found so far. Exabeam's UEBA displays the type of description that it could show in a console regarding one particular user, the rating that it shows, and how vulnerable the user is, which is very good. Exabeam's automation for incident response is very good. The machine learning capabilities of Exabeam are also good.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The stability of the solution is very good. We have about 100 users on it right now, and we use it twice a week."
"The best feature of Cortex XDR by Palo Alto Networks is that it collects logs from different sections such as the endpoint, the network, and the cloud, making it easy to investigate alerts, collect some of the investigation packages related to the infected machines, and provide live response."
"It blocks malicious files. It prevents attacks. It doesn't require many updates, it's a very light application."
"The anti-exploit is impenetrable. We chose Traps because it is the only product that we were not able to get anything past."
"What I like about Cortex XDR by Palo Alto Networks is that it is a comprehensive solution that contains everything the organization may need when using endpoints."
"On a scale from one to ten, I would rate Cortex XDR by Palo Alto Networks a nine."
"Cortex XDR by Palo Alto Networks saves time in various ways, although the user interface is fairly standard."
"But overall, when we speak about security and protection, they are one of the top providers."
"With Deepwatch, I have seen a 40 to 50% reduction in MTTR due to faster detection and guided response playbooks, and false positives have also dropped significantly by 40 to 50% through better correlation and risk scoring, which significantly reduced SOC workload and improved analyst efficiency."
"The user interface and the timelines they use are the most valuable features, and the price model is very simple so that one can understand it easily and there are no surprises within it."
"Exabeam is very easy to use, with a straightforward platform and workflow, unlike other tools that require more expertise."
"The setup is not difficult. It was easy."
"The platform is not extremely expensive compared to its direct competitors; I would rate its pricing around six out of ten."
"Exabeam Fusion SIEM has a good performance and more advantages than traditional solutions."
"The UI was very clean."
"Valuable features are its timeline based analysis and that it's user friendly."
"The most valuable feature of Exabeam Fusion SIEM is the easy-to-use user interface."
 

Cons

"There are some limitations on the Traps agents."
"We had a problem with getting our older endpoints up to date, but their newest updates have been really good. I've been pleased with it in terms of what our needs are. It's doing what we want it to do."
"The MAC agent is not as robust feature-wise as the PC version."
"This is a very costly product."
"A little bit more automation would be nice."
"I feel that it should not be a licensed activity because a feature should allow us to see applications running on end devices."
"While using Cortex, I noticed some aspects that could be improved, such as increasing the synchronization speed between XDR and Xnor."
"The deployment is pretty hard."
"Regarding the support, I would say that the support team should be more responsive because ideally, the response time of the support is quite long, which is sometimes frustrating."
"One area for the solution's improvement is integration capabilities, particularly out-of-the-box integration which sometimes requires additional professional services."
"Exabeam needs to improve its adaptive nature towards rules and its capability to understand the entire client environment faster."
"Exabeam needs to improve its documentation and provide more customization for dashboards and case management."
"The organzation is rigid and not flexible in the way they operate"
"Adding to the number of certifications that they have, for example, ISO 27001, would be helpful."
"There is a lack of Indonesian support, it would benefit us to have more support for the customers."
"We had a large volume right from the beginning and they weren't quite prepared for that. That's something that they should think about when it comes to customers that have a large volume to start off with."
"They should provide detailed information about detecting phishing emails."
 

Pricing and Cost Advice

"I don't have any issues with the pricing. We are satisfied with the price."
"The cost depends on your chosen license type, like Pro or other licenses."
"Very costly product."
"The tool's price is moderate."
"Cortex XDR's pricing is ok."
"The pricing seems fair, and I do like the licensing model. You use wherever they are, and it is elastic."
"The price of the product is not very economical."
"It's the most expensive solution, but features-wise, it's quite strong. It's very good for protection, so the results are very good in the case of protection. I would rate it a two out of ten in terms of pricing."
Information not available
"They have a great model for pricing that can be based either on user count or gigabits per day."
"The solution is expensive."
"Exabeam Fusion SIEM's pricing is reasonable."
"Exabeam is not a cheap solution."
"There is an annual license required to use Exabeam Fusion SIEM. The price of the solution should be reduced."
"The platform is not extremely expensive compared to its direct competitors; I would rate its pricing around six out of ten."
report
Use our free recommendation engine to learn which AI-Powered Cybersecurity Platforms solutions are best for your needs.
885,789 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
14%
Financial Services Firm
12%
Comms Service Provider
7%
Manufacturing Company
7%
Construction Company
29%
Manufacturing Company
12%
Healthcare Company
8%
Media Company
8%
Financial Services Firm
11%
Manufacturing Company
8%
Computer Software Company
8%
Construction Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business44
Midsize Enterprise20
Large Enterprise48
No data available
By reviewers
Company SizeCount
Small Business12
Midsize Enterprise4
Large Enterprise7
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
Ask a question
Earn 20 points
What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
It mostly depends on your use-cases and environment. Exabeam and Securonix have a stronger UEBA feature set, friendli...
What is your experience regarding pricing and costs for Exabeam Fusion SIEM?
I do not have much information about the pricing. However, I am aware that Exabeam is cheaper than Palo Alto based on...
What needs improvement with Exabeam Fusion SIEM?
Exabeam's integration capabilities are not good, as Exabeam has a very limited number of integrations and no out-of-b...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
No data available
No data available
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Premise Health, Dover, Follett, Genuine Parts Company
Hulu, ADP, Safeway, BBCN Bank
Find out what your peers are saying about CrowdStrike, Palo Alto Networks, TrendAI and others in AI-Powered Cybersecurity Platforms. Updated: March 2026.
885,789 professionals have used our research since 2012.