No more typing reviews! Try our Samantha, our new voice AI agent.

Symantec XDR vs Wazuh comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 1, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Extended Detection and Response (XDR)
4th
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
118
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (5th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
Symantec XDR
Ranking in Extended Detection and Response (XDR)
47th
Average Rating
8.0
Number of Reviews
1
Ranking in other categories
No ranking in other categories
Wazuh
Ranking in Extended Detection and Response (XDR)
3rd
Average Rating
7.4
Reviews Sentiment
5.9
Number of Reviews
51
Ranking in other categories
Log Management (2nd), Security Information and Event Management (SIEM) (4th)
 

Mindshare comparison

As of September 2026, in the Extended Detection and Response (XDR) category, the mindshare of Cortex XDR by Palo Alto Networks is 4.8%, down from 6.1% compared to the previous year. The mindshare of Symantec XDR is 0.6%, up from 0.2% compared to the previous year. The mindshare of Wazuh is 5.4%, down from 12.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Extended Detection and Response (XDR) Mindshare Distribution
ProductMindshare (%)
Wazuh5.4%
Cortex XDR by Palo Alto Networks4.8%
Symantec XDR0.6%
Other89.2%
Extended Detection and Response (XDR)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
BR
Cyber Security Consultant at I(TS)² Saudi Arabia
A scalable and stable solution with straightforward deployment
We can generate maps from the environment. For example, suppose there is a virus that has a zero-day attack and is publicly unknown. We can block that and keep it away from the network so it is not further replicated. It also has custom white and black lists. We can add a good reputation on both lists and use the sonar technology for Symantec and the online network for advanced reports.
Sudarson Prabhu - PeerSpot reviewer
Security Consultant at Payatu
File integrity monitoring has strengthened our data protection and supports compliance needs
I expected one thing from the dashboard in Wazuh. In ManageEngine, when you use ManageEngine, you can assign a unique ID to all employees. Then with the unique ID, if you search any unique ID in the dashboard itself, you can get the unique ID everywhere, including where the laptop has been logged in, when the logout happened, and what actions have been done for that unique ID. I expected the same in Wazuh, but whenever we want to check any monitoring activities for a specific person, we need to search for the endpoint and then get the endpoint details from our Active Directory or wherever we have the endpoint name stored in our resources, and then search for the endpoint to see the history for that specific endpoint only. This made a simple thing a bit complex. If we had a correlation of logs where I could just search one unique ID and then the unique ID pulls every system in a time-wise manner, that would be a great improvement I would suggest.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"When the pandemic started, Palo Alto came up with many solutions, which helped with the quick shift from on-premises to the cloud."
"These days it's machine-learning technology and behavior-based analytics features that make us more secure."
"The multi-layered approach to the product gives you confidence that it will stop exploits, ransomware, worms, or viruses from compromising endpoints, essentially providing peace of mind."
"The product's initial setup phase is very easy."
"Cortex XDR by Palo Alto Networks is specifically designed to prevent zero-day attacks and is part of an ecosystem of Palo Alto, providing customers with a long-term vision to modify and redesign how security is applied in their company."
"They did what they said, and this solution could apply to any scenario."
"It is easy to use."
"The most valuable for us is the correlation feature."
"You can advise the solution and protect your environment."
"We can block a virus that has a zero-day attack and is publicly unknown and keep it away from the network so it is not further replicated."
"Good for monitoring, active response, and for vulnerabilities."
"I recommend Wazuh to everyone and believe more platforms, not just SIEM and XDR capability platforms, should be open source, allowing people to leverage these tools for the greater good."
"Other than that, it's a highly recommended product from our side, and we wish that this product had intel support."
"Wazuh has very flexible and robust features."
"Wazuh is a powerful tool, and you can do lots of things with it."
"Wazuh is free and easy to use. It is also adjustable, and we can use it on the cloud and on-premises."
"Stability-wise, Wazuh seems to have fixed all the past issues, and the latest version is possibly the most stable."
"I like the cloud-native infrastructure and that it's free. We didn't have to pay anything, and it has the capabilities of many premium solutions in the market. We could integrate all of our services and infrastructure in the cloud with Wazuh. From an integration point of view, Wazuh is pretty good. I had a good experience with this platform."
 

Cons

"We had a problem with getting our older endpoints up to date, but their newest updates have been really good. I've been pleased with it in terms of what our needs are. It's doing what we want it to do."
"They've been having some issues with updating their endpoint agents, and it has been quite frustrating."
"The configuration could be simplified. I would like to see better protection, specifically to protect email applications."
"Data privacy is a matter of concern. You have to be careful with data privacy, it can be sensitive and Cortex can have most of your access."
"The solution needs better reports. I think they should let the customer go in and customize the reports."
"Managing the product should be easier."
"There's an overall lack of features."
"It would be better if they could educate the customers more. Some sort of seminars and roadshows will help educate the customers and show what the product can do. The price could be better. It would also help if they had a team for deployment and support."
"The solution should have better reporting."
"Since it's an open-source tool, scalability is the main issue."
"The biggest part that's missing is threat intelligence. It isn't inbuilt, and if a sudden incident occurs, we don't get that feedback inside the SIEM tool. That's a big gap, I see. It would be better if we could get the threat intelligence feeds integrated with the SIEM tools. That would help us push value solutions to the clients in a big way."
"Wazuh needs more security and features, particularly visualization features and a health monitor."
"Scalability is a challenge because it is distributed architecture and it uses Elastic DB. Their Elastic DB doesn't allow open source waste application."
"Wazuh doesn't cover sources of events as well as Splunk. You can integrate Splunk with many sources of events, but it's a painful process to take care of some sources of events with Wazuh."
"I think that the next release should be more suitable for large enterprises, because currently they are not because large companies do not rely on open source solutions."
"The only challenge we faced with Wazuh was the lack of direct support."
"A lack of certain features creates limitations."
 

Pricing and Cost Advice

"Cortex XDR by Palo Alto Networks is quite an expensive solution."
"It has a higher cost than other solutions, like CrowdStrike or Microsoft’s EDR tools, but it reduces the cost of our operations because it’s a new generation antivirus tool."
"It's the most expensive solution, but features-wise, it's quite strong. It's very good for protection, so the results are very good in the case of protection. I would rate it a two out of ten in terms of pricing."
"The pricing is okay, although direct support can be expensive."
"We pay about $50,000 USD per year for a bundle that includes Cortex XDR."
"Its pricing is kind of in line with its competitors and everybody else out there."
"The return on investment is from the user side because we have seen the performance of it increase the delivery time of the product if we are using too many web-based and on-premise applications. In indirect ways, we saw the return of investment in terms of performance and user satisfaction increase."
"I did PoCs on products called Cylance and CrowdStrike. Although, I consider these products and they were also good, when it come to cost and budgetary factors, Traps has been proven to be better than the other two products. It is quite cost-effective and delivers all the entire solution which we require."
Information not available
"When I contacted customer care, they mentioned bundling options, that I found to be overall affordable."
"Wazuh is an open-source tool, which means it is freely available for use."
"Wazuh is a cheaply priced product."
"It is a free-of-cost solution."
"Wazuh is open-source, therefore it is free. You can purchase support for $1,000 a year."
"The current pricing is open source."
"Wazuh is open-source, so I think it's an option for a small organization that cannot go for enterprise-grade solutions like Splunk."
"There is not a license required for Wazuh."
report
Use our free recommendation engine to learn which Extended Detection and Response (XDR) solutions are best for your needs.
914,805 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Comms Service Provider
12%
Construction Company
11%
Manufacturing Company
9%
No data available
Comms Service Provider
13%
University
9%
Computer Software Company
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise21
Large Enterprise55
No data available
By reviewers
Company SizeCount
Small Business27
Midsize Enterprise15
Large Enterprise9
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
Ask a question
Earn 20 points
What do you like most about Wazuh?
Wazuh is its flexibility and open-source nature, which allows us to tailor threat detection and response across diver...
What needs improvement with Wazuh?
I expected one thing from the dashboard in Wazuh. In ManageEngine, when you use ManageEngine, you can assign a unique...
What is your primary use case for Wazuh?
Our organization is focusing on the integrity part for implementing Wazuh. We were checking solutions for File Integr...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
No data available
Wazuh All-In-One Deployment
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Information Not Available
Information Not Available
Find out what your peers are saying about SentinelOne, TrendAI, Wazuh and others in Extended Detection and Response (XDR). Updated: September 2026.
914,805 professionals have used our research since 2012.