Try our new research platform with insights from 80,000+ expert users

Fortra's Alert Logic MDR vs Palo Alto Networks Cortex XSOAR comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 2, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortra's Alert Logic MDR
Ranking in SOC as a Service
5th
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
11
Ranking in other categories
Vulnerability Management (29th), Managed Detection and Response (MDR) (20th)
Palo Alto Networks Cortex X...
Ranking in SOC as a Service
2nd
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
46
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (2nd)
 

Mindshare comparison

As of May 2025, in the SOC as a Service category, the mindshare of Fortra's Alert Logic MDR is 5.9%, down from 9.6% compared to the previous year. The mindshare of Palo Alto Networks Cortex XSOAR is 20.8%, up from 11.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
SOC as a Service
 

Featured Reviews

reviewer2191746 - PeerSpot reviewer
It's a highly mature, competitively priced solution that provides total visibility into your ecosystem. FORTRA's Alert Logic has the only Cybersecurity Platform that integrates XDR+WAF+VM+DLP in one.
Alert Logic offers total visibility into the client's IT ecosystem. The solution's intrusion detection system inspects 100 percent of the network packets and installs universal agents on all physical and virtual servers for log collection. Alert Logic also aggregates logs of the client's various 3rd Party security tools into a single pane of glass. All of the analytics from those data feeds got to a 24/7 SOC with sophisticated resources. Alert Logic has massive threat intelligence resources to provide additional context to the incident response declarations. They do all the heavy lifting for clients who lack the technology and resources to operate their own SOC. The client is solely responsible for the incident response component. The macro analytics resides on Alert Logic's cloud. You have the ECM response and business application team on the client side. Everything works in tandem, which is the only way you can deal with the advanced threats we face today, especially the ransomware families. If you don't respond in minutes, you're in trouble.
NikhilSharma2 - PeerSpot reviewer
Ability to multiple playbooks to fetch data from multiple firewalls and utomated several tasks, including vulnerability scans and SOCL (Security Orchestration, Automation
Recently, they started implementing microservices in XSOAR, which has improved quality and addressed previous issues. However, they should focus more on licensing costs. The user licensing fees are quite high. For example, I received a quote for XSOAR, and it was $12,000 per user per year. If you have a SOC team of 30 members/analysts, you're looking at a substantial expense. They should consider reducing these costs since this high pricing seems to be more about profit. So, there is room for improvement in the pricing. Moreover, the reporting and dashboard features are decent but could be improved. The user interface (UI) is quite heavy and takes time to load, which is a major drawback.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The installation and configuration were slick."
"Notifications and the detail of notifications are most valuable. It is a user-friendly solution."
"While I still have on-premises appliances, I can remotely monitor everything from the cloud, and Alert Logic's ease-of-access features have helped me streamline my workflow and reduce implementation time."
"We receive infrastructure security warnings from it. So, we know what is going on and what needs to be addressed."
"The quicker implementation of changes to our infrastructure from Alert Logic tell us if there are any problems."
"It is a very stable product."
"It has the ability to install agents. It is pretty straightforward. You can automate the process pretty easily."
"The initial setup is pretty straightforward."
"The drag-and-drop interface enables analysts with no programming knowledge to create playbooks easily."
"It is a scalable solution."
"The automation part and the playbook creation part are awesome. The way it is responding to the customers and incidents is also very good. In the SOC environment, I guess it will carry out around 50% of the work."
"The most valuable features of Cortex XSOAR include its vast library of plugins, which allow us to integrate various tools and solutions seamlessly."
"The product’s stability is good."
"It has an extensive list of integrations that are available out of the box which makes it easy to start."
"Cortex XSOAR's playbook for incident management and automation is highly valuable."
"The pricing is very good."
 

Cons

"Its menu is not very intuitive. I would like to see the user menu expanded a bit. The user menu is very layered, and because of the layers, you have to go down a path that is not very intuitive."
"This product needs to mature more. While it is a good product, there are some areas where it needs work."
"I would like to see it do initial scans and start capturing data, which it will truly analyze, not just be a reporting system saying, "Here is an email. Here is an email. Here is an email.""
"I would like more data on the alert payload. It would be good to have the ability to customize the alert payload to add whatever data that we want on there. Right now, it is a bit limited."
"We'd like to have triggered alerts sent to us so we see errors quicker."
"Could be more of an endpoint protector."
"Alert Logic needs to expand its SOCs to serve more markets, such as the Middle East and Asia. There should be infrastructure that covers more time zones. The company should also develop an EDR that is natively integrated into their solution. Currently, a client must buy another EDR solution like CrowdStrike or Sophos. I think Alert Logic is developing this. Built-in email security could also be developed and integrated."
"They have ideas and email you whatever they find, but they don't have a dedicated security team who will work on an attack or a specific security instance."
"With Palo Alto Networks Cortex XSOAR, managing its setup phase can be a complicated task."
"The user interface (UI) is quite heavy and takes time to load, which is a major drawback."
"Corex XSOAR could be improved by reducing the time it takes to process large amounts of data and increasing the number of integrations."
"The solution's correlation rules and playbooks should be improved."
"Implementing this solution requires a lot of involvement from the vendor and it should be made easier for the partners."
"In terms of improvement, it needs to be more modular. It's not. When you're working in layouts and you create specific apps within layouts, there's no portability right now in order to reuse that code across multiple layouts. I can't take a tab and say I want to use this tab on these other layouts. I have to physically go in there and recreate it from scratch, which is maddening."
"When Palo Alto bought the solution, the pricing increased by 1.5 times. There's been a 50% increase, which is a lot."
"The configuration of the solution could improve it is difficult."
 

Pricing and Cost Advice

"Alert Logic has better competitive pricing than some of its competitors."
"Our ROI would probably be zero. We don't even use it. It sits in there. We get emails and just delete them. Around the world, we don't even use it."
"Almost any product that is on the AWS Marketplace is super easy to subscribe to."
"Its pricing is very reasonable considering what you get for what you pay. There is quite a good value there. Its licensing is also very logical. They've got the licensing price points at a reasonable level. It is on a monthly license but a yearly contract. There are no additional costs to the standard licensing fees."
"Price of the solution was very reasonable considering the size of our organization at the time, and so it worked out perfectly."
"On a scale of one to ten, where one is a low price, and ten is a high price, I rate the pricing a nine."
"When I first looked at Demisto, it had a price tag of $250,000 but when we finally purchased it, it was $345,000."
"The solution's cost is high."
"It is approx $10,000 or $20,000 per year for two user licenses."
"The price of Palo Alto Networks Cortex XSOAR is comparable to other solutions in the market."
"The price of Palo Alto Networks Cortex XSOAR is expensive."
"There is a yearly license required for this solution and it is expensive."
"There is a perception that it is priced very high compared to other solutions."
report
Use our free recommendation engine to learn which SOC as a Service solutions are best for your needs.
849,963 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
18%
Financial Services Firm
14%
Manufacturing Company
9%
Healthcare Company
9%
Financial Services Firm
15%
Computer Software Company
12%
Manufacturing Company
9%
Government
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Alert Logic?
The most valuable aspect of Alert Logic is its technology platform. They have SOCs in the US and Europe, giving them global visibility of the threat landscape. They detect and respond to threats in...
What is your experience regarding pricing and costs for Alert Logic?
Alert Logic's license is one of the most competitive. They deliver a high-quality service for a competitive price.
What needs improvement with Alert Logic?
Alert Logic should also develop an EDR that is natively integrated into their solution. Currently, a client must buy another EDR solution like SentinelOne, CrowdStrike, or Sophos. I think Alert Log...
What is your experience regarding pricing and costs for Palo Alto Networks Cortex XSOAR?
Even though customers often comment on the price, the potential savings come from managing a large number of security events with a limited number of analysts. This leads to economic advantages des...
What needs improvement with Palo Alto Networks Cortex XSOAR?
The complexity of Cortex XSOAR has a trade-off with its versatility. The product can be tailored for each deployment to respond to specific customer needs, and this complexity may be seen as a down...
 

Also Known As

Alert Logic MDR, Alert Logic Managed Detection and ResponseAlert Logic Threat Manager, Alert Logic Cloud Defender, Critical Watch FusionVM
Demisto Enterprise, Cortex XSOAR, Demisto
 

Overview

 

Sample Customers

Information Not Available
Cellcom Israel, Blue Cross and Blue Shield of Kansas City, esri, Cylance, Flatiron Health, Veeva, ADT Cybersecurity
Find out what your peers are saying about Fortra's Alert Logic MDR vs. Palo Alto Networks Cortex XSOAR and other solutions. Updated: April 2025.
849,963 professionals have used our research since 2012.