No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer1980216 - PeerSpot reviewer
Business Development Manager For Palo Alto Networks at a tech services company with 1,001-5,000 employees
Reseller
Top 20
Dec 5, 2023
Has a simple setup process and efficient stability
Pros and Cons
  • "The product's most valuable features are massive user and feature intelligence exploit detection."
  • "It is an enterprise-level solution. Its price could be less expensive."

What is our primary use case?

We use the product as a detection and response application.

What is most valuable?

The product's most valuable features are massive user and feature intelligence exploit detection. It is very useful in detecting threats to databases. The last meter statistics prove the efficient capabilities of the solution.

What needs improvement?

It is an enterprise-level solution. Its price could be less expensive.

For how long have I used the solution?

We have been using Cortex XDR by Palo Alto Networks for three years.

Buyer's Guide
Cortex XDR by Palo Alto Networks
March 2026
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,444 professionals have used our research since 2012.

What do I think about the stability of the solution?

The product is 100% stable. I have never received any complaints from the customers.

What do I think about the scalability of the solution?

Cortex XDR by Palo Alto Networks is easily scalable as it is a cloud-based product.

How are customer service and support?

We provide support services for our customers. Palo Alto's support services are expensive, and customers also encounter language barriers.

How was the initial setup?

The initial process is simple. It requires training of about three to four days to understand the installation process. It is deployed on the cloud. The number of software engineers required depends on the number of the endpoints.

What's my experience with pricing, setup cost, and licensing?

We pay in advance for the product's license. It has reasonable pricing for the use cases it provides to the company. We can split this payment monthly, quarterly, or yearly, according to the customer's requirements. For a cost-benefit analysis when choosing a security solution, consider factors such as the number of attacks prevented, the impact of those attacks, potential losses, and other hidden costs.

What other advice do I have?

I rate Cortex XDR by Palo Alto Networks for ten out of ten. It could be improved from a commercial perspective. It could approach the SMB market as well.

Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
reviewer2159517 - PeerSpot reviewer
Mdr of Presales & Customer Success Head at a financial services firm with 1-10 employees
Real User
Apr 21, 2023
A stable and scalable solution with good customer support
Pros and Cons
  • "The solution allows us to make investigations. Other XDR solutions also provide similar capabilities but for investigation, Cortex XDR is better."
  • "The product's pricing could be better."

What is our primary use case?

We use the solution for telemetry and for its anti-virus capability.

What is most valuable?

The solution allows us to make investigations. Other XDR solutions also provide similar capabilities but for investigation, Cortex XDR is better.

What needs improvement?

The product's pricing could be better.

For how long have I used the solution?

I have been using the tool for several years.

What do I think about the stability of the solution?

The solution is stable. I would rate its stability a nine out of ten. 

What do I think about the scalability of the solution?

The product is scalable. 

How are customer service and support?

The technical support team is good.

How was the initial setup?

The initial setup was easy.

What was our ROI?

The tool is worth its money. 

What other advice do I have?

I would rate the solution an eight out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Cortex XDR by Palo Alto Networks
March 2026
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,444 professionals have used our research since 2012.
reviewer2082015 - PeerSpot reviewer
Servicio Posventa at a security firm with 11-50 employees
Real User
Feb 6, 2023
A pinpoint evasive threats with patented behavioral analytics solution with a useful policy extension feature
Pros and Cons
  • "One of the things that I enjoy the most is using policy extensions. It's like having host firewalls to control USB connections. I think it's a wonderful tool to restrict use when connecting to our computers. Another important tool is Home Insights. That is an add-on to the Cortex solution. I like that because we can see all the vulnerabilities in the environment and control what assets are connected to our network."
  • "I don't like that they have different types of licenses. For example, if users select a license, they think they will have all the platforms they need to improve their network or security. But after some time, Palo Alto Networks changed their licensing, and some of the features that, for example, were free at the beginning now have a cost. I think the integration can be improved. For example, a lot of tools are just integrated through APIs."

What is our primary use case?

Our clients want to correlate information they have in their network. Many engineers or companies have different tools like CMs, firewalls, VPNs, and some other things related to networks. They mentioned that after they acquired the Cortex XDR solution they have all of the information in one place. That is important because they improved the time to solve security issues.

What is most valuable?

One of the things that I enjoy the most is using policy extensions. It's like having host firewalls to control USB connections. I think it's a wonderful tool to restrict use when connecting to our computers. 

Another important tool is Home Insights. That is an add-on to the Cortex solution. I like that because we can see all the vulnerabilities in the environment and control what assets are connected to our network.

What needs improvement?

I don't like that they have different types of licenses. For example, if users select a license, they think they will have all the platforms they need to improve their network or security. But after some time, Palo Alto Networks changed their licensing, and some of the features that, for example, were free at the beginning now have a cost. I think the integration can be improved. For example, a lot of tools are just integrated through APIs.

For how long have I used the solution?

I have worked with Cortex XDR by Palo Alto Network for about four years.

What do I think about the stability of the solution?

Cortex XDR by Palo Alto Network is a stable solution. I have been working with it for years, and it only went down once.

On a scale from one to ten, I would give stability a nine.

What do I think about the scalability of the solution?

Cortex XDR by Palo Alto Network is a scalable solution.

How are customer service and support?

Technical support is okay.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is straightforward and not very complicated. I think it takes about two hours to deploy this solution. The number of personnel needed depends on the company. For example, banks usually have five cybersecurity engineers installing and maintaining this solution.

On a scale from one to ten, I would give the initial setup a seven.

What's my experience with pricing, setup cost, and licensing?

I don't like that they have different types of licenses.

On a scale from one to nine, I would give licensing costs a seven.

What other advice do I have?

I consider Cortex XDR by Palo Alto Network a good solution. They have good support, and they listen to customer feedback. 

On a scale from one to nine, I would give Cortex XDR by Palo Alto Network a nine.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1890849 - PeerSpot reviewer
Network and security engineer at a tech services company with 11-50 employees
Real User
Jul 9, 2022
Easy to set up and won't slow down your system but is expensive
Pros and Cons
  • "It'll not slow down your system when compared to others."
  • "If you are looking to deploy a security solution as a whole, this is a good option."
  • "We would also like to have advanced tech protection and email scanning."
  • "We would also like to have advanced tech protection and email scanning."

What is our primary use case?

I'm testing the product right now. I use the solution for endpoint security.

What is most valuable?

Everything is fine. 

It'll not slow down your system when compared to others.

The initial setup is easy.

What needs improvement?

I'd like the solution to provide URL filtering and web-based prevention. We'd like to block web pages at a high level.

We would also like to have advanced tech protection and email scanning.

For how long have I used the solution?

I've been using the solution for a year.

What do I think about the stability of the solution?

The product is very stable and the performance is good. It doesn't slow down the systems it runs on. There are no bugs or glitches. It doesn't crash or freeze. 

What do I think about the scalability of the solution?

The solution can scale well.

More than 100 people are using the solution right now. 

How are customer service and support?

We've never needed the assistance of technical support just yet.

Which solution did I use previously and why did I switch?

I've also used McAfee MVISION Endpoint. 

I'm testing them both and finding the advantages and disadvantages between them.

How was the initial setup?

The solution is very easy to set up.

What's my experience with pricing, setup cost, and licensing?

You do have to pay for a license in order to use a solution. It's expensive.

What other advice do I have?

We're a reseller.

We are using the latest, most up-to-date version, of the product.

I would recommend using it with another protection layer. Cortex should provide an additional layer of security apart from this. You might have to integrate with other vendors also.

If you are looking to deploy a security solution as a whole, this is a good option.

I'd rate the solution seven out of ten. If we had more advanced security features, I'd rate it higher.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1678701 - PeerSpot reviewer
ISEC Unit Manager at a tech services company with 11-50 employees
Real User
Jan 11, 2022
We can manage several clients from the same console, and its endpoint defense is more advanced than traditional antivirus
Pros and Cons
  • "Cortex XDR lets us manage several clients from the same console, and its endpoint defense is more advanced than traditional antivirus."
  • "Cortex XDR lets us manage several clients from the same console, and its endpoint defense is more advanced than traditional antivirus."
  • "Cortex XDR is trickier to configure than other Palo Alto products. This is one area where we are not so satisfied."
  • "Cortex XDR is trickier to configure than other Palo Alto products. This is one area where we are not so satisfied."

What is our primary use case?

We have deployed Cortex XDR for a couple of clients in manufacturing.

What is most valuable?

Cortex XDR lets us manage several clients from the same console, and its endpoint defense is more advanced than traditional antivirus.

What needs improvement?

The dashboard could be more user-friendly.

For how long have I used the solution?

I've been using Cortex XDR for two years.

What do I think about the stability of the solution?

Cortex XDR is stable enough.

What do I think about the scalability of the solution?

Cortex's scalability is good. We have about 200 users on it at the moment. 

How are customer service and support?

Palo Alto support is great. 

How was the initial setup?

Cortex XDR is trickier to configure than other Palo Alto products. This is one area where we are not so satisfied. We need two people to deploy and maintain the solution. 

What's my experience with pricing, setup cost, and licensing?

Our clients pay for the license every year. It's just a standard fee with no additional costs. 

What other advice do I have?

I rate Cortex XDR eight out of 10. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Account Manager at CIPHER
MSP
Jan 4, 2022
Easy to use and good for managed threat hunting and incident response
Pros and Cons
  • "Cortex XDR can integrate the firewalls and determine the tendencies of the attacks. It's a new generation antivirus, with protection endpoints and detection response. It is very easy to use and everybody can operate the solution."
  • "It has a higher cost than other solutions, like CrowdStrike or Microsoft’s EDR tools, but it reduces the cost of our operations because it’s a new generation antivirus tool."
  • "It is not easy to sell Cortex XDR, not because it isn't a good tool. Its marketing needs to be improved."
  • "It is not easy to sell Cortex XDR, not because it isn't a good tool."

What is our primary use case?

My customer wanted to use EDR. We worked with the POC to demonstrate the antivirus and how it has more features for detecting threats.

How has it helped my organization?

It makes it easier and faster to investigate problems and incidents.

What is most valuable?

The most valuable features are that it can integrate the firewalls and determine the tendencies of the attacks.

It investigates problems and incidents quickly. Cortex is good at reducing alerts and for having a custom barrier. It's a new generation antivirus, with protection endpoints and detection response.

Cortex detects and shows what the problem is and how to resolve the problem or incident. Cortex is very easy to use and everybody can operate the solution.

It has tools for threat hunting and it has very good incident response features.

What needs improvement?

It is not easy to sell Cortex XDR, not because it isn't a good tool. Its marketing needs to be improved.

For how long have I used the solution?

I've been using it for a year.

How was the initial setup?

Setting it up is very simple.

What's my experience with pricing, setup cost, and licensing?

It has a higher cost than other solutions, like CrowdStrike or Microsoft’s EDR tools, but it reduces the cost of our operations because it’s a new generation antivirus tool.

What other advice do I have?

I'm rating this solution a ten out of ten because it is very good for managed threat hunting and incident response. It is the best XDR solution. It's better than other tools because it uses enterprise architecture. Everybody will find that this solution is easy to use. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Mantu Shaw - PeerSpot reviewer
Project Manager at a outsourcing company with 1,001-5,000 employees
MSP
Top 5
Dec 21, 2021
A stable part of our security solution that correlates logs from relevant sources
Pros and Cons
  • "The most valuable for us is the correlation feature."
  • "My advice for anybody who is considering Cortex XDR is that it is a complete solution, and has very good features."
  • "There are some third-party solutions that are difficult to integrate with, which is something that can be improved."
  • "There are some third-party solutions that are difficult to integrate with, which is something that can be improved."

What is our primary use case?

We use Cortex XDR as part of our security solution.

How has it helped my organization?

its a very good solution and single solution for entire infrastructure, give us good co-relation of incident. Single solution for Network, Endpoint, Servers. 

What is most valuable?

The most valuable for us is the correlation feature. You are able to correlate data that is coming from the firewall, network, server, and endpoints. This is one of our main requirements and makes for a good product.

It works with the data lake in an agent-based or agentless manner.

It is easy to integrate most with network devices, including firewalls, and Active Directory. We use firewalls from different vendors including Palo Alto and Check Point, and it supports them.

What needs improvement?

There are some third-party solutions that are difficult to integrate with, which is something that can be improved.

What do I think about the stability of the solution?

We have not experienced any issues with respect to stability at this point.

What do I think about the scalability of the solution?

Scalability has not been a problem.

How are customer service and support?

We have been in contact with technical support and are satisfied with them.

How would you rate customer service and support?

Positive

How was the initial setup?

its a Straightforward

What about the implementation team?

We have an in-house team for deployment and maintenance.

What was our ROI?

It replace multiple solution and due to this it will reduce the Administrative effort.

Which other solutions did I evaluate?

I have run a PoC with both CrowdStrike and Cortex XDR, and from my observation, I felt that Cortex was much better at meeting our requirements. It is also easier to use.

CrowdStrike was difficult when it came to integrating with other products and it does not work on mobile devices.

What other advice do I have?

My advice for anybody who is considering Cortex XDR is that it is a complete solution, and has very good features. From my experience, it is one of the better ones in the market. That said, no product is 100%.

I would rate this solution a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
CyberSecurity Consultant at Information Technology Solutions- ITS
Real User
Nov 15, 2021
A stable and scalable solution with an easy setup and out-of-the-box playbooks and integration
Pros and Cons
  • "The integrations are out-of-the-box, as are the playbooks."
  • "I have found the solution to be very easy in respect of the integration and configurable."
  • "The solution should offer more dashboards and they should be better customized."
  • "The solution should offer more dashboards and they should be better customized."

What is our primary use case?

I have deployed some customized playbooks and modified ones which are out-of-the-box with more integration with SIEM solutions such as ArcSight, QRadar, ADRs and Trend Micro.

What needs improvement?

The solution should offer more dashboards and they should be better customized. The case number of items should be addressed. 

I have found the interface of Azure to be more simple and customizable than that of the solution. 

For how long have I used the solution?

I have worked on Cortex XDR by Palo Alto Networks with my customers for a number of weeks. 

What do I think about the stability of the solution?

The stability is good. 

What do I think about the scalability of the solution?

The scalability is fine. 

We have plans to increase the usage. 

How was the initial setup?

The initial setup was simple. 

The deployment took no more than two hours. 

What's my experience with pricing, setup cost, and licensing?

So far, I have made use of the free license which is offered. Once it ended, I was able to buy a license based on the number of users or divisions. The license varies with the number of users or applications involved. 

If one wishes to work with another team or large number of users at a future point, he must purchase a license for them. 

Which other solutions did I evaluate?

The interface of Azure is more simple and customizable than Cortex XDR by Palo Alto Networks.

What other advice do I have?

I have found the solution to be very easy in respect of the integration and configurable. The integrations are out-of-the-box, as are the playbooks. 

The solution is deployed solely on-premises on a single server. 

As of now, there are six users making use of the solution. 

My advice is that the on-premises environments for the product's use should be increased. 

I rate Cortex XDR by Palo Alto Networks as an eight out of ten. 

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros sharing their opinions.
Updated: March 2026
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros sharing their opinions.