Palo Alto Networks Cortex XSOAR and LogPoint are both contenders in the security automation and orchestration space. Palo Alto Networks Cortex XSOAR appears to have the upper hand due to its sophisticated automation and integration capabilities, making it more appealing for organizations seeking extensive security orchestration features.
Features: Palo Alto Networks Cortex XSOAR stands out for its automation features, extensive playbook library, and machine learning capabilities, supporting advanced security orchestration through diverse integrations. LogPoint, on the other hand, is known for its strong log management, user-friendly search capabilities, and analytics features, coupled with cost-effective pricing strategies.
Room for Improvement: LogPoint needs to enhance its log parsing efficiency, integration options, and user interface aesthetics. It also lacks SaaS deployment capabilities. Palo Alto Networks Cortex XSOAR faces challenges with licensing costs, setup complexity, and its integration processes need more streamlining. Improvements in administrative tasks related to licensing are also desired by users.
Ease of Deployment and Customer Service: Palo Alto Networks Cortex XSOAR provides flexible deployment options, including public, private, and hybrid clouds, while LogPoint primarily offers on-premises deployments, possibly limiting flexibility. LogPoint's technical support is responsive but sometimes lacks proficiency, whereas Cortex XSOAR users report issues with service responsiveness and support complexity. Both solutions require better customer service offerings.
Pricing and ROI: LogPoint features a straightforward pricing model with predictable, fixed costs, appealing to smaller and medium-sized businesses. Palo Alto Networks Cortex XSOAR, while more expensive with hefty licensing fees, potentially offers substantial ROI for larger enterprises that utilize its full capabilities effectively. In contrast, LogPoint suits clients seeking cost-effective, predictable spending.
Since we started working with Torq, I am handling much fewer alerts. It is becoming really easy for me to handle an alert.
We have seen a return on investment, targeting a $600,000 ROI for the year.
I have seen a return on investment with Torq, as the automation reduces the number of employees needed and significantly saves both time and resources.
By implementing Palo Alto Networks Cortex XSOAR playbooks, I automated repetitive SOC tasks such as IOC enrichment, alert triggers, host isolation, and incident ticket creation.
We are positioning Palo Alto Networks Cortex XSOAR, which can be used in the SOC and do a lot of automation for the customer.
Palo Alto Networks Cortex XSOAR is a pure and proven technology product and cybersecurity product, customers will get more ROI when compared with others.
My impression of their technical support during the initial setup was that they were helpful, responded within a reasonable timeframe, and provided exactly what we needed.
The speed and quality of their answers have been pretty good, as I usually get a response within 24 hours, and they follow up well.
We can always get an answer, and the support team are experts in their own system.
Logpoint's customer support is not sufficient with only one engineer in the US.
The technical support for Logpoint is very good, and I would rate it as nine out of ten.
I recommend a submission to Logpoint because I worked with it before.
Eight out of ten times, they provide valuable help.
I would rate the customer support for Palo Alto Networks Cortex XSOAR as 9 out of 10.
Have the person that you hire know more about the product than the person on the phone.
Its scalability is good because it has a cloud-native architecture and it expands dynamically to handle thousands of alerts at the same time.
Our case management is super scalable.
In terms of scalability, you can do as long as you can build it, and they can support it.
It is web-based and accommodates the expansion of our organization.
Logpoint is scalable and capable of expanding.
The scalability of Palo Alto Networks Cortex XSOAR supports our growth and security needs because we can integrate various tools and continuously add more capability.
Palo Alto Networks Cortex XSOAR has very good application capabilities and is highly scalable.
The issues with scalability arise from the speed of some integrations, as not all are perfectly tuned by Palo.
We have been using Torq for one and a half years, but we have experienced no downtime.
Most of the time, the system is stable as long as the components that they integrate with are stable.
I have never faced any downtime or issues.
I have received reports indicating glitches and downtimes with Logpoint.
The system works smoothly even when I navigate deep into the playbook section.
As a leading partner, I do not anticipate any issues with stability or scalability.
I would rate the stability and reliability of Palo Alto Networks Cortex XSOAR as a nine.
Torq should offer default templates that can directly scan firewall data and automate actions.
The AI value depends on maturity. Real value depends heavily on telemetry, integration depth, and workflow design, all of which rely on how mature customers are in their SOC department.
It was able to capture data but was unable to differentiate between the agent hostname we are using and the hostname that resides on the back end of the Internet.
Dealing with foreign entities for support was a challenge, leading us to switch providers due to lack of adequate support.
Logpoint needs to be cloud-native, as currently, it is not.
Logpoint's UEBA is a weak point, while Exabeam's UEBA has extra AI through automation.
The biggest area for improvement is simplifying playbook development and debugging.
The deployment requires integration and the development of integration modules.
One of the significant issues we encounter is system slowdown when we receive an influx of alerts, which inhibits how quickly we can access the information needed for investigation.
When they bring more and more value into the platform, it makes more sense to pay that price, but still, it is expensive.
Before deciding to implement Torq, I considered that compared to our old case management platform, Torq was a much better price and had a lot better value for what you get out of the platform, which was a key consideration for the company.
It is an expensive solution, not an inexpensive solution, but we get through the flexibility.
I rate the pricing at eight, suggesting it's relatively good or affordable.
For customers, it is zero versus $20 million, which is why they have to make a decision.
Being among the market leaders, it is worth the money, though still a bit pricey.
The price will be high, but the solution is absolutely superb.
Torq's unified platform approach to AI SOC automation and case management has significantly benefited us by integrating the case management platform with the automation, which saves time compared to managing multiple point solutions across our security stack.
The fact that I can build whatever I want within my own imagination and skills without relying on code is the best thing about Torq.
You can copy and paste a cURL command. If you have documentation or APIs, you usually have an example on the side. You basically have all the information on how the API call should be. You can just copy that and paste it into a step, and it will just build the step for you.
The UEBA enables us to monitor at the device level, and SOAR provides playbooks and templates that we can modify and incorporate into the platform.
It effectively facilitates logging and log storage and assists in security event management by ingesting security events.
The most valuable feature, which is endpoint security, is included in Logpoint, and an extra feature is the integration.
Execution of automatic tasks for collecting, enriching, and correlating security events from hundreds of different technologies.
If I already have an established process, I do not have to change my process to fit into the tool. I can modify the tool to fit into my process, which makes things considerably easier.
We have implemented automation features, such as automated responses to email threats and automatic configuration of target devices for blocking specific IPs.
| Product | Mindshare (%) |
|---|---|
| Palo Alto Networks Cortex XSOAR | 8.9% |
| Torq | 3.6% |
| Logpoint | 2.0% |
| Other | 85.5% |


| Company Size | Count |
|---|---|
| Small Business | 4 |
| Midsize Enterprise | 5 |
| Large Enterprise | 11 |
| Company Size | Count |
|---|---|
| Small Business | 18 |
| Midsize Enterprise | 3 |
| Large Enterprise | 4 |
| Company Size | Count |
|---|---|
| Small Business | 27 |
| Midsize Enterprise | 9 |
| Large Enterprise | 32 |
Torq is the enterprise AI SOC solution that effectively combines adaptive insights and automation to handle critical threats efficiently. It manages threat lifecycles, swiftly moving from triage to response, ensuring effective risk management.
Torq is designed to streamline security operations by aggregating telemetry across your security stack. It investigates significant risks and manages threats from triage to containment and remediation. This AI-driven tool enhances the capabilities of your SecOps team, allowing them to achieve more impactful results without introducing complicated processes.
What are the key features of Torq?In industries like finance and healthcare, Torq shows effectiveness by adapting to specific risk scenarios often encountered in these fields. Its integration with existing infrastructures makes it a valuable asset for maintaining stringent security standards, essential for protecting critical data and operations in diverse high-stakes environments.
Logpoint offers a robust SIEM system tailored for compliance with regulations like PCI DSS and GDPR, enhancing security monitoring and enabling efficient incident response.
Logpoint strengthens cybersecurity by offering essential tools for log collection, security monitoring, and forensic analysis. Its features include an intuitive dashboard, a powerful correlation engine, and extensive third-party integrations, making it a versatile asset for security operations centers. Despite its advantages, areas for improvement include ransomware protection, cloud-native deployment, and more flexible pricing. Improvements in features like SOAR and UEBA functionality can boost its competitiveness.
What are the most important features of Logpoint?Many organizations utilize Logpoint across industries as part of their security infrastructure. It supports standard compliance, orchestrating incident responses and security threat monitoring. Logpoint empowers businesses by integrating and correlating security data, improving cybersecurity posture in varied environments.
Palo Alto Networks Cortex XSOAR enhances security operations automation and integration. Users rely on its incident management capabilities and machine learning to improve response times and efficiency.
Cortex XSOAR stands out for its capability to automate and orchestrate security tasks through customizable playbooks and robust third-party integrations. Its analytics offer insights into incidents, while machine learning prioritizes alerts and reduces false positives. Despite its powerful features, users note room for improvement in documentation, interface design, and integration capabilities. Cost and complexity in setup and deployment are also concerns. Users in security operations centers benefit significantly from automated data enrichment, streamlined incident response, and efficient handling of threats like phishing and endpoint management.
What are the key features of Cortex XSOAR?Cortex XSOAR is implemented across industries for automating and streamlining security operations. Organizations use it to create playbooks, integrate with security tools, and automate repetitive tasks, thereby improving the efficiency of their security operations centers and incident management processes.
We monitor all Security Orchestration Automation and Response (SOAR) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.