NetWitness XDR vs Palo Alto Networks Cortex XSOAR comparison

Cancel
You must select at least 2 products to compare!
Comparison Buyer's Guide
Executive Summary

We performed a comparison between NetWitness XDR and Palo Alto Networks Cortex XSOAR based on real PeerSpot user reviews.

Find out in this report how the two Security Orchestration Automation and Response (SOAR) solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI.
To learn more, read our detailed NetWitness XDR vs. Palo Alto Networks Cortex XSOAR Report (Updated: October 2022).
656,474 professionals have used our research since 2012.
Featured Review
Quotes From Members
We asked business professionals to review the solutions they use.
Here are some excerpts of what they said:
Pros
"The interface of this solution is very flexible and easy to use.""The most valuable feature of RSA NetWitness Network is the single unified dashboard from which you can manage all the different products of RSA. Additionally, the integration with native applications is good.""The stability of the RSA NetWitness Endpoint is very good.""They have recently updated the features and the most valuable ones are the instant threat response, ease of use, web interface, integration, and easy access. RSA NetWitness Endpoint is very compatible with other solutions and technologies. However, they do not rely on third-party solutions and have most features built-in.""Ability to isolate the machine when there are malicious files.""It's a scalable solution. We have around five to eight customers using RSA NetWitness Endpoint, and we hope to increase the number of users.""NetWitness Endpoint's most valuable features are its interoperability across many different operating systems and the ease of pivoting from network to endpoint via a single console.""Technical support is knowledgeable."

More NetWitness XDR Pros →

"Cortex XSOAR's most valuable features are the playbooks, custom integration, the machine-learning model, and the layout, classifier, and mapper.""Palo Alto has gotten the investigators more presence to actually go in the report because being that the platform will email the investigator that it's been assigned to, now the investigators will jump in there and start going through the review process a lot quicker.""It’s easy to install.""I have found the solution very useful, it integrates well with other platforms.""The pricing is very good.""The most valuable feature is automation.""The solution is very reliable.""The most valuable features are the orchestration because of the way in which it coordinates the loss from all the devices and it provides us with a high-level overview of the critical log information."

More Palo Alto Networks Cortex XSOAR Pros →

Cons
"The solution lacks a reporting engine.""The deployment process is complex. I don't know why, but this solution will suddenly stop working. Logs stop coming. Often, one thing or another stops working. Most of the time, one of my team members is working with troubleshooting and working with technical support. Log passing is also one of the biggest challenge.""The integration of the solution needs to be improved. The dashboard needs lots of updates as well. In the next release, we would like to see advanced fraud detection features.""The threat intelligence could improve in RSA NetWitness Endpoint.""RSA NetWitness Network could improve on integration with non-native application integration.""We would like to see the hunting and investigation features of this solution improved, in order to provide better visibility of issues.""NetWitness Endpoint's blocking feature does not work properly - if there's a malicious process, it's not possible to kill it via a custom rule unless and until it's flagged as malicious.""Threat detection could be better."

More NetWitness XDR Cons →

"The solution requires DV but does not support open-source DV elastic searches.""Corex XSOAR could be improved by reducing the time it takes to process large amounts of data and increasing the number of integrations.""The integration could be better. Cortex, for example, does not work with iPhone.""When Palo Alto bought the solution, the pricing increased by 1.5 times. There's been a 50% increase, which is a lot.""Palo Alto Networks Cortex XSOAR could improve the look, feel, and management of the cloud console. Additionally, the user could be more easily integrated.""It is been decommissioned by Palo Alto.""The solution is very expensive.""The user interface could be a bit better."

More Palo Alto Networks Cortex XSOAR Cons →

Pricing and Cost Advice
  • "It is an expensive product."
  • "The price of the solution depends on the environment. If the environment is large then it will cost more. However, the larger the environment with more endpoints, you will receive an increased discount. If the environment is very small, then you might think it is expensive. It is always better to buy in bulk to receive a discount. The minimum number of assets is usually 500, with discounts on 1000 and 2000."
  • "The pricing is not very economical. It is a quite costly product for India. One thing is that when you purchase it, you have to purchase a module separately."
  • "We are on a three-year contract to use RSA NetWitness Network."
  • "NetWitness Endpoint is less costly than its competitors, but it offers fewer features."
  • More NetWitness XDR Pricing and Cost Advice →

  • "There is a yearly license required for this solution and it is expensive."
  • "It is approx $10,000 or $20,000 per year for two user licenses."
  • "When I first looked at Demisto, it had a price tag of $250,000 but when we finally purchased it, it was $345,000."
  • "The price of Palo Alto Networks Cortex XSOAR is expensive."
  • "The price of Palo Alto Networks Cortex XSOAR could be reduced. We are always looking for a discount. There is an annual license needed to use this solution."
  • "Cortex XSOAR's price could be lower."
  • "The price of Palo Alto Networks Cortex XSOAR is comparable to other solutions in the market."
  • "The solution is based on an annual licensing model that is expensive."
  • More Palo Alto Networks Cortex XSOAR Pricing and Cost Advice →

    report
    Use our free recommendation engine to learn which Security Orchestration Automation and Response (SOAR) solutions are best for your needs.
    656,474 professionals have used our research since 2012.
    Questions from the Community
    Top Answer:This solution allows us to locate the malware in real-time.
    Top Answer:This is not an expensive product. The cost depends on the number of endpoints that you want to monitor, but it is not expensive.
    Top Answer:I would like to see Security Orchestration and Response Automation (SOAR) integration. This way, if there is an endpoint that has been compromised, you don't have to go about repairing or blacklisting… more »
    Top Answer:I think Swimlane is a better cost. It's small and doesn't focus on only integrating with it's own products like other XSoar competitors. 
    Top Answer:Many different playbooks are available and can be customized.
    Top Answer:The solution is based on an annual licensing model that is expensive.
    Ranking
    Views
    2,809
    Comparisons
    2,059
    Reviews
    10
    Average Words per Review
    387
    Rating
    7.9
    Views
    12,831
    Comparisons
    7,796
    Reviews
    15
    Average Words per Review
    493
    Rating
    8.1
    Comparisons
    Also Known As
    RSA ECAT, NetWitness Network
    Demisto Enterprise, Cortex XSOAR, Demisto
    Learn More
    NetWitness
    Video Not Available
    Overview

    Using a centralized combination of network and endpoint analysis, behavioral analysis, data science techniques and threat intelligence, NetWitness XDR helps analysts detect and resolve known and unknown attacks while automating and orchestrating the incident response lifecycle. With these capabilities on one platform, security teams can collapse disparate tools and data into a powerful, blazingly fast user interface.

    Palo Alto Networks delivers a complete solution that helps Tier-1 through Tier-3 analysts and SOC managers to optimize the entire incident life cycle while auto documenting and journaling all the evidence. More than 100+ integrations enable security orchestration workflows for incident management and other critical security operation tasks.

    Palo Alto Networks Cortex XSOAR is a piece of Security Orchestration, Automation, and Response software that redefines what it means for a program to orchestrate security in an automated manner. It is a next-generation solution that offers all of the features of dozens of siloed security operations center tools in one place. Cortex XSOAR combines case management, automation, real-time collaboration, and threat intelligence management to create a platform that can handle all aspects of system security. Teams that make use of Cortex XSOAR can expect to cut the number of issues that they will have to deal with by 75%. At the same time, the speed at which they resolve those issues that slip through will rise by 90%.

    Cortex XSOAR ensures that all of the IT and security tools that you employ function as a unified system. It does this by employing hundreds of integrations that allow you to run a wide variety of programs at once without ever worrying about them interfering with each other. These integrations are limited only by your imagination. They can be used immediately as they are, if that is what you need. However, they can also be customized according to the requirements of your system. This approach provides you with the maximum levels of both flexibility and utility.

    The model that this platform uses is based on a machine learning algorithm. The level of automation allows you to provide more than an unchanging and inflexible blanket of coverage. Cortex XSOAR takes all of the data that it gathers and uses it to expand its protective capabilities. This creates recommendations that you can use to create a threat playbook that can be deployed uniformly throughout your organization.


    Benefits of Palo Alto Networks Cortex XSOAR

    Some of Palo Alto Networks Cortex XSOAR’s benefits include:

    • The ability to have all of your data collected in a single location. Valuable time can be saved now that everything that security analysts need to know in order to diagnose and react to threats has been centralized.
    • Security operations center tasks can be automated. This allows you to assign management and analyst staff to the most essential tasks. The effectiveness of your organization will be increased, which will result in a rise in your company’s overall security and productivity.
    • Many kinds of data can be stitched together by this platform. Network, endpoint, cloud, and identity data can be combined to offer a more complete picture of the threats that are discovered.
    • Integrated threat intelligence management can notify you about threats in real time. Now you can diagnose and address issues as they arise. You can also assign values to the threats so that your resources are being used in the most effective manner possible.


    Reviews from Real Users

    Palo Alto Networks Cortex XSOAR’s centralized monitoring interface and automation are two features that help it stand out. This might help explain why one quarter of the Fortune 500 companies choose Palo Alto Networks Cortex XSOAR over the competition.

    Peerspot users note the effectiveness of these features. One user wrote, “We were looking for a single pane of glass type of solution that would allow us to physically be in one appliance - be able to work in concert with other servers that we have within our environment. We wanted orchestration and automation. The single pane of glass was the most important part.” Another noted, "The automation part and the playbook creation part are awesome. The way it is responding to the customers and incidents is also very good. In the SOC environment, I guess it will carry out around 50% of the work."

    Offer
    Learn more about NetWitness XDR
    Learn more about Palo Alto Networks Cortex XSOAR
    Sample Customers
    ADP, Ameritas, Partners Healthcare
    Cellcom Israel, Blue Cross and Blue Shield of Kansas City, esri, Cylance, Flatiron Health, Veeva, ADT Cybersecurity
    Top Industries
    VISITORS READING REVIEWS
    Computer Software Company22%
    Comms Service Provider10%
    Financial Services Firm9%
    Government9%
    REVIEWERS
    Financial Services Firm27%
    Government18%
    Healthcare Company9%
    Comms Service Provider9%
    VISITORS READING REVIEWS
    Computer Software Company19%
    Financial Services Firm10%
    Comms Service Provider10%
    Government7%
    Company Size
    REVIEWERS
    Small Business59%
    Midsize Enterprise24%
    Large Enterprise18%
    VISITORS READING REVIEWS
    Small Business22%
    Midsize Enterprise16%
    Large Enterprise62%
    REVIEWERS
    Small Business27%
    Midsize Enterprise27%
    Large Enterprise45%
    VISITORS READING REVIEWS
    Small Business18%
    Midsize Enterprise15%
    Large Enterprise67%
    Buyer's Guide
    NetWitness XDR vs. Palo Alto Networks Cortex XSOAR
    October 2022
    Find out what your peers are saying about NetWitness XDR vs. Palo Alto Networks Cortex XSOAR and other solutions. Updated: October 2022.
    656,474 professionals have used our research since 2012.

    NetWitness XDR is ranked 4th in Security Orchestration Automation and Response (SOAR) with 10 reviews while Palo Alto Networks Cortex XSOAR is ranked 2nd in Security Orchestration Automation and Response (SOAR) with 18 reviews. NetWitness XDR is rated 8.0, while Palo Alto Networks Cortex XSOAR is rated 8.0. The top reviewer of NetWitness XDR writes "Log correlation is good, but the solution is slow and there are many licensing complications". On the other hand, the top reviewer of Palo Alto Networks Cortex XSOAR writes "Enables the investigators to go through the review process a lot quicker". NetWitness XDR is most compared with Darktrace, Microsoft Defender for Endpoint, CrowdStrike Falcon, Corelight and Symantec Endpoint Security, whereas Palo Alto Networks Cortex XSOAR is most compared with Splunk Phantom, Fortinet FortiSOAR, Siemplify, IBM Resilient and ServiceNow Security Operations. See our NetWitness XDR vs. Palo Alto Networks Cortex XSOAR report.

    See our list of best Security Orchestration Automation and Response (SOAR) vendors.

    We monitor all Security Orchestration Automation and Response (SOAR) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.