Try our new research platform with insights from 80,000+ expert users

Palo Alto Networks URL Filtering with PAN-DB vs Vectra AI comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 19, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Palo Alto Networks URL Filt...
Ranking in Intrusion Detection and Prevention Software (IDPS)
8th
Average Rating
8.6
Reviews Sentiment
6.7
Number of Reviews
13
Ranking in other categories
No ranking in other categories
Vectra AI
Ranking in Intrusion Detection and Prevention Software (IDPS)
5th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
45
Ranking in other categories
Network Detection and Response (NDR) (2nd), Extended Detection and Response (XDR) (16th), Identity Threat Detection and Response (ITDR) (9th), AI-Powered Cybersecurity Platforms (6th)
 

Mindshare comparison

As of October 2025, in the Intrusion Detection and Prevention Software (IDPS) category, the mindshare of Palo Alto Networks URL Filtering with PAN-DB is 1.9%, down from 2.6% compared to the previous year. The mindshare of Vectra AI is 8.0%, up from 7.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Intrusion Detection and Prevention Software (IDPS) Market Share Distribution
ProductMarket Share (%)
Vectra AI8.0%
Palo Alto Networks URL Filtering with PAN-DB1.9%
Other90.1%
Intrusion Detection and Prevention Software (IDPS)
 

Featured Reviews

Abdul  Basit - PeerSpot reviewer
Advanced features and robust support elevate overall network management experience
I think URL filtering could be better to some extent. Improvements could be made in Palo Alto Networks URL Filtering with PAN-DB compared to Sophos. The URL filtering option in Palo Alto gives a very clear vision of the network and the applications using URL filtering. If you assign a user in a group not to access certain URLs, that user should only be allowed to access LinkedIn without running videos. However, deep URL filtering in Palo Alto is not configurable. One user can have access to LinkedIn with video running, while another cannot. They should improve this deep analysis of URL filtering options.
Mohammad Alkurdi - PeerSpot reviewer
Innovative detection features enhance monitoring
The advantages of the integration are not entirely out-of-the-box. You have to do it manually. When I'm doing tier response, an out-of-the-box solution is not available. You need to have a Linux server, and from the Linux server, you must perform AI tasks, and there is a lot to be handled in the back end. This is a major consideration about them. The recall feature, if it can be placed in some areas instead of the cloud, and charged for, would be better. Recall the storage where you watch all the traffic, and you can recall it and try to analyze it in the back end. It’s cloud-based. If they offer it on-prem, it would be better. I think they have a solution, but I have never tested it, to be honest with you.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Real-time analysis is excellent, and the integration of the solution with our infrastructure is straightforward and less challenging."
"The initial setup is easy."
"I would rate Palo Alto Networks URL Filtering with PAN-DB a perfect 10 out of 10."
"Prohibited URLs can be listed by category."
"The URL categories are updated by Palo Alto Networks itself."
"It provides visibility and control over where people are web browsing and protects them from going to malicious sites."
"Being able to manage blacklists and whitelists easily is very useful, especially for internal access and limiting outbound access."
"The tool blocks URLs."
"It keeps up with the network traffic, which is a good thing. It provides more context to plain alerts compared to using an older system. So, it helps an analyst reduce the information overload."
"Most of their use cases, including deployment, are managed by the tool itself, requiring less manual input from our team."
"The packet-capturing feature is very useful."
"I like the way that Vectra AI focuses on the internal network. Nowadays, most of the attackers are already inside, and they can be inside for many years before they start attacking. With normal monitoring, it's quite difficult to find them."
"We discovered a lot of things in our network and are correcting several misconfigurations. We are learning how some apps work together and how some things shouldn't happen. It's also easier for us to identify the source of a brute force, whereas before, we didn't even know we had a brute force."
"The most useful feature is the anomaly detection because it's not signature-based. It picks up the initial part of any attack, like the recon and those aspects of the kill chain, very well."
"The administrative privilege detection feature is the most valuable feature. The admin accounts are often highly accessible to the high-risk component of the environment. If those accounts are compromised or are being used in a suspicious manner, that's high-fidelity events for us to look into."
"Some valuable features of Vectra AI are that it is very intuitive and that there are only a small amount of false positives. Therefore, it's an effective solution."
 

Cons

"One way Palo Alto can improve is by offering sandboxing. I don't know if they currently offer a sandboxing feature together with the firewall or not. They should provide secure sandboxing with the firewalls."
"Customer service is sometimes inconsistent. Some engineers are very knowledgeable, while others cannot answer questions and delay solutions."
"We have had some challenges with making Palo Alto Networks URL Filtering with PAN-DB work with ELK stack."
"The main limitation is that it needs a live Internet connection for ongoing updates."
"Support needs to be enhanced."
"Performance monitoring could use improvement."
"For hosting sites like Blogspot, they host sites that should be in different categories, but get lumped together in general. There needs to be more granularity or multiple categorizations."
"An area for improvement would be the technical support, which can be slow."
"The rules for threats are not always precise and Vectra AI should improve this."
"It does a little bit of packet capture on alert so you can look at the packet capture activity going on, but it doesn't collect a whole lot of data. Sometimes it's only one or two frames, sometimes it does collect more. That's why they have the addition of their Recall platform, because that really does help expand the capability."
"One of the things that we are missing a bit is the capability to add our own rules to it. At the moment, the tech engine does its thing, but we have some cool ideas to make additional rules. There should be an option in the platform to add custom rules, or there should be some kind of user group where we can suggest them for the roadmap and see if they get evaluated and get transparent communication on whether they will be implemented in the product or not."
"The solution needs to become more proactive. When Vectra AI is the primary solution in an environment - like it is in our case - you must work on response time. We have a small team so response time at endpoint level is vital."
"The reporting from Cognito Detect is very limited and doesn't give you too many options. If I want to prepare a customized report on a particular host, even though I see the data, I have to manually prepare the report. The reporting features that are built into the tool are not very helpful."
"I would like to see data processed onshore. Right now, the cloud components, like Office 365, must be processed on servers outside of Australia. I would like to see a future adoption of onshore processing."
"The UI/UX and detection could be improved. More detections of specific security events could be useful. We've had a few incidents that were not detected by Vectra. The teams are working on it right now, but more detection is always better."
"Some of the customization could be improved. Everything is provided for you as an easy solution to use, but working with it and doing specific development could be worked on a bit more in the scope of an incident response team."
 

Pricing and Cost Advice

"Expensive, but that's because it provides everything."
"It is more expensive than ASA but is far cheaper than Checkpoint. So, pricing wise, it is right in the middle."
"Vectra's licensing model could scale to our research network, which has multiple, 100-gigabit links."
"The pricing and licensing are quite straightforward because they're based on the IP licenses. As a result, they are easy to count."
"We are running at about 90,000 pounds per year. The solution is a licensed cost. The hardware that they gave us was pretty much next to nothing. It is the license that we're paying for."
"The license is based on the concurrent IP addresses that it's investigating. We have 9,800 to 10,000 IP addresses."
"Vectra AI's pricing is cheaper than that of Darktrace."
"From a pricing perspective, they are very commercially competitive. From a licensing perspective, just be conscious that some of their future cloud solutions come with additional subscriptions. Also, if you're outside of the US, you will get charged freight for the device back to your country."
"At the time of purchase, we found the pricing acceptable. We had an urgency to get something in place because we had a minor breach that occurred at the tail end of 2016 to the beginning of 2017. This indicated we had a lack of ability to detect things on the network. Hence, why we moved quickly to get into the tool in place. We found things like Bitcoin mining and botnets which we closed quickly. In that regard, it was worth the money."
"The solution's pricing was 50 percent lower than the other vendors shortlisted."
report
Use our free recommendation engine to learn which Intrusion Detection and Prevention Software (IDPS) solutions are best for your needs.
869,089 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Performing Arts
11%
University
9%
Manufacturing Company
7%
Financial Services Firm
11%
Computer Software Company
11%
Manufacturing Company
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise4
Large Enterprise4
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise10
Large Enterprise27
 

Questions from the Community

What is your experience regarding pricing and costs for Palo Alto Networks URL Filtering with PAN-DB?
The licensing costs and setup costs are very expensive for us. The price is significantly higher compared to other competitive products.
What needs improvement with Palo Alto Networks URL Filtering with PAN-DB?
I think URL filtering could be better to some extent. Improvements could be made in Palo Alto Networks URL Filtering with PAN-DB compared to Sophos. The URL filtering option in Palo Alto gives a ve...
What is your primary use case for Palo Alto Networks URL Filtering with PAN-DB?
We previously discussed Palo Alto Networks WildFire, and we are currently using it for our firewalls with the WildFire subscription included. We have micro-segmentation using the VMware environment...
What is the biggest difference between Corelight and Vectra AI?
The two platforms take a fundamentally different approach to NDR. Corelight is limited to use cases that require the eventual forwarding of events and parsed data logs to a security team’s SIEM or ...
What do you like most about Vectra AI?
The solution is currently used as a central threat detection and response system.
What is your experience regarding pricing and costs for Vectra AI?
It is very acceptable when you compare it with Darktrace, for example.
 

Also Known As

Palo Alto Networks URL Filtering PAN-DB
Vectra Networks, Vectra AI NDR
 

Overview

 

Sample Customers

TRI-AD, Telkom Indonesia
Tribune Media Group, Barry University, Aruba Networks, Good Technology, Riverbed, Santa Clara University, Securities Exchange, Tri-State Generation and Transmission Association
Find out what your peers are saying about Palo Alto Networks URL Filtering with PAN-DB vs. Vectra AI and other solutions. Updated: September 2025.
869,089 professionals have used our research since 2012.