Try our new research platform with insights from 80,000+ expert users

Exabeam vs Palo Alto Networks Cortex XSOAR comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 5, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.4
Exabeam Fusion SIEM offers financial institutions cost savings, enhanced security, and strong ROI, though specific pricing is unknown.
Sentiment score
6.9
Cortex XSOAR enhances ROI by automating tasks, requiring mature SOC processes for effective use and reduced false positives.
Exabeam offers more machine learning models that detect anomalies.
We are positioning Palo Alto Networks Cortex XSOAR, which can be used in the SOC and do a lot of automation for the customer.
 

Customer Service

Sentiment score
6.3
Exabeam's customer service garners mixed reviews, with varied responses on responsiveness, efficiency, and support quality across regions.
Sentiment score
6.4
Palo Alto Networks Cortex XSOAR support is responsive and skilled, though experiences vary with occasional delays and access issues.
Even with TAM support from Exabeam, many issues go unresolved.
The technical support provided by Palo Alto Networks Cortex XSOAR is good.
Their support has been better than Anomali's and they are more responsive.
 

Scalability Issues

Sentiment score
7.2
Exabeam scales well for enterprise use, despite some latency issues and slowdowns with increased filtering criteria.
Sentiment score
7.3
Palo Alto Networks Cortex XSOAR is praised for scalability and integration, handling enterprise demands with careful large deployment planning.
The scalability of Palo Alto Networks Cortex XSOAR supports our growth and security needs because we can integrate various tools and continuously add more capability.
 

Stability Issues

Sentiment score
7.2
Exabeam is stable with high ratings, though some users face processing delays and downtime affecting SOC monitoring.
Sentiment score
7.5
Palo Alto Networks Cortex XSOAR is stable and reliable, with occasional bugs and performance issues, especially in cloud environments.
These problems were not frequent, and the last six to eight months have been stable.
 

Room For Improvement

Exabeam needs better flexibility, integration, clearer documentation, enhanced dashboards, faster support, improved UI, and reduced false positives.
Cortex XSOAR requires improved documentation, expanded IoT support, enhanced features, and better pricing for streamlined integration and user experience.
I have explored the SaaS version; it offers many new features.
Exabeam needs to improve its documentation and provide more customization for dashboards and case management.
To improve the solution, it needs to have complete features that are low-code, no-code, and should be plug-and-play.
One of the significant issues we encounter is system slowdown when we receive an influx of alerts, which inhibits how quickly we can access the information needed for investigation.
Deployment is not easy, requiring significant tuning and building of integrations over weeks.
 

Setup Cost

Exabeam offers reasonable pricing with flexible models, though not the cheapest, it's competitively priced compared to some competitors.
Palo Alto Networks Cortex XSOAR is costly but offers valuable integration and features, appealing to medium and large enterprises.
For customers, it is zero versus $20 million, which is why they have to make a decision.
 

Valuable Features

Exabeam excels with advanced analytics, intuitive interface, seamless integration, automation, and machine learning for enhanced security and ease of use.
Cortex XSOAR excels in integration, automation, and customization, enhancing security operations with efficient orchestration and high user satisfaction.
Exabeam's AI capabilities, like the natural language mode, convert natural language into Exabeam queries, enhancing ease of use.
The product offers useful features like the dashboard, timeline, and session views, which enhance our security tools.
If I already have an established process, I do not have to change my process to fit into the tool. I can modify the tool to fit into my process, which makes things considerably easier.
We have implemented automation features, such as automated responses to email threats and automatic configuration of target devices for blocking specific IPs.
Execution of automatic tasks for collecting, enriching, and correlating security events from hundreds of different technologies.
 

Categories and Ranking

Exabeam
Ranking in Security Orchestration Automation and Response (SOAR)
14th
Average Rating
7.8
Reviews Sentiment
6.7
Number of Reviews
19
Ranking in other categories
Security Information and Event Management (SIEM) (20th), User Entity Behavior Analytics (UEBA) (2nd), Security Incident Response (6th), Threat Intelligence Platforms (13th), AI-Powered Cybersecurity Platforms (11th)
Palo Alto Networks Cortex X...
Ranking in Security Orchestration Automation and Response (SOAR)
2nd
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
48
Ranking in other categories
SOC as a Service (2nd)
 

Mindshare comparison

As of September 2025, in the Security Orchestration Automation and Response (SOAR) category, the mindshare of Exabeam is 2.1%, up from 1.9% compared to the previous year. The mindshare of Palo Alto Networks Cortex XSOAR is 9.7%, down from 12.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Orchestration Automation and Response (SOAR) Market Share Distribution
ProductMarket Share (%)
Palo Alto Networks Cortex XSOAR9.7%
Exabeam2.1%
Other88.2%
Security Orchestration Automation and Response (SOAR)
 

Featured Reviews

Stephen-Armstrong - PeerSpot reviewer
The SIEM provides a user-friendly UI experience
When events come into the system, the dashboard categorizes them by the highest risk score, not when they appear on the system. When you've got multiple ongoing incidents you can only see the highest risk score at the top of the list rather than the most recent detection. Exabeam's reporting dashboard could have included a filtering option to filter by the most recent detection.
DayaramGoyal - PeerSpot reviewer
Offers automation but requires enhancements for intuitive configuration
Palo Alto Networks Cortex XSOAR is a good product with enhanced and efficient playbooks, as demonstrated during our use case simulations. We have implemented automation features, such as automated responses to email threats and automatic configuration of target devices for blocking specific IPs. The analytics feature in Palo Alto Networks Cortex XSOAR is impressive. The solution is quite exhaustive regarding integrations, with many pre-integrations available, especially for market-leading products. There might be challenges with make-in-India products, as they tend not to build the necessary connectors. This depends on whether you are selling to enterprises or other customers. For government customers, you might encounter many Indian products, such as firewalls, which could pose integration challenges unless you have open APIs. However, for market-leading products, there are ready-made integrations available.
report
Use our free recommendation engine to learn which Security Orchestration Automation and Response (SOAR) solutions are best for your needs.
867,370 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
12%
Computer Software Company
12%
Manufacturing Company
8%
Government
7%
Financial Services Firm
15%
Computer Software Company
11%
Manufacturing Company
9%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business12
Midsize Enterprise3
Large Enterprise7
By reviewers
Company SizeCount
Small Business19
Midsize Enterprise8
Large Enterprise24
 

Questions from the Community

What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
It mostly depends on your use-cases and environment. Exabeam and Securonix have a stronger UEBA feature set, friendlier GUI and are not licensed based on capacity (amount of logs and information in...
What is your experience regarding pricing and costs for Exabeam Fusion SIEM?
I do not have much information about the pricing. However, I am aware that Exabeam is cheaper than Palo Alto based on discussions in meetings.
What needs improvement with Exabeam Fusion SIEM?
We use the on-prem Exabeam product and face limitations using the web UI and administration of custom models and rules. I have explored the SaaS version; it offers many new features. We are conside...
What is your experience regarding pricing and costs for Palo Alto Networks Cortex XSOAR?
Comparing pricing to Micro Focus, they were offering bundles, making it free with their SIEM. For customers, it is zero versus $20 million, which is why they have to make a decision.
What needs improvement with Palo Alto Networks Cortex XSOAR?
To improve the solution, it needs to have complete features that are low-code, no-code, and should be plug-and-play. We need to see improvements in that area to facilitate cyber analysts.
 

Also Known As

No data available
Demisto Enterprise, Cortex XSOAR, Demisto
 

Overview

 

Sample Customers

Hulu, ADP, Safeway, BBCN Bank
Cellcom Israel, Blue Cross and Blue Shield of Kansas City, esri, Cylance, Flatiron Health, Veeva, ADT Cybersecurity
Find out what your peers are saying about Exabeam vs. Palo Alto Networks Cortex XSOAR and other solutions. Updated: July 2025.
867,370 professionals have used our research since 2012.