The primary use case for Cortex XSOAR is that it requires less management and integration effort. It automates many tasks and integrates seamlessly with other Palo Alto Networks products.
Chief Information Security Officer at a tech vendor with 1-10 employees
Does a better job of identifying anomalies that are more likely to be incidents of compromise without as many false positives or false negatives
Pros and Cons
- "It does a better job of identifying anomalies that are more likely to be incidents of compromise without as many false positives or false negatives."
- "It could provide more integration with a large variety of products."
What is our primary use case?
How has it helped my organization?
It does a better job of identifying anomalies that are more likely to be incidents of compromise without as many false positives or false negatives.
What needs improvement?
It could provide more integration with a large variety of products.
For how long have I used the solution?
I have been using Cortex XSIAM for a year.
Buyer's Guide
Security Information and Event Management (SIEM)
June 2025

Find out what your peers are saying about Palo Alto Networks, Microsoft, IBM and others in Security Information and Event Management (SIEM). Updated: June 2025.
856,873 professionals have used our research since 2012.
What do I think about the stability of the solution?
The product is stable.
I rate the solution’s stability a ten out of ten.
What do I think about the scalability of the solution?
There have been no issues with the scalability. 1200 FTEs are using this solution.
As our application stack increases, the size will increase.
Which solution did I use previously and why did I switch?
Splunk is too expensive and too difficult to manage. The additional costs for log ingestion for Splunk were driving the prices up.
How was the initial setup?
The initial setup is straightforward compared to Splunk. It took about three months to complete.
I rate the initial setup an eight out of ten, where one is difficult and ten is easy.
What about the implementation team?
Our engineers were able to do the deployment independently.
What was our ROI?
We are understaffed on the security side. The XSIAM solution from Cortex reduces and makes it feasible for us to handle incidents that we previously struggled with.
What's my experience with pricing, setup cost, and licensing?
The standard licensing is positive. The number of logs ingested into Splunk was primarily driving its cost up, and that is not as much of an issue with Palo Alto as it was with Splunk.
What other advice do I have?
By incorporating XSIAM, it handles and automates many manual processes but allows users to review things manually before changes are made.
There is minimal maintenance from our side.
I recommend it.
Overall, I rate the solution a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
TAC Engineer at a tech services company with 10,001+ employees
Seamless with enhanced security and third-party integrations
Pros and Cons
- "The most valuable feature is the integration capability."
- "I am not sure if any improvements are needed right now."
What is our primary use case?
We use Cortex XSIAM as a NextGen antivirus to detect malware in endpoints and devices. We have integration with data sources and other third-party data sources, enabling us to ingest logs from a third-party website to the Cortex XSIAM console. This allows the management of detailed data. It aims to keep track of work ingested through Cortex.
How has it helped my organization?
Cortex XSIAM is user-friendly, allowing users to easily understand activities within Cortex. Customers can resolve issues by themselves with easy-to-follow documentation, which helps reduce reliance on technical support.
What is most valuable?
The most valuable feature is the integration capability. It is user-friendly and allows easy integration with third-party vendors. The centralized endpoints are secured, even if they are not exposed to the Internet. It provides a more secure and futuristic feature set.
What needs improvement?
I am not sure if any improvements are needed right now. The current features are satisfactory, and new features are implemented following customer feature requests.
For how long have I used the solution?
I have been working with the Cortex XSIAM product for around one year and eight months.
What do I think about the stability of the solution?
Sometimes, stability issues occur, especially after content updates or new version releases. It is important how quickly these are resolved. However, currently, it is performing well.
What do I think about the scalability of the solution?
There are no scalability issues.
How are customer service and support?
If a customer reports an issue, we look for the best resolution from our end. If we are unable to resolve it, a ticket is raised to the engineering team.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Currently, I do not have experience with any other products similar to Cortex XSIAM.
What was our ROI?
Feedback related to revenue and benefits of Cortex is shared with the accounts team, not typically with technical support.
What's my experience with pricing, setup cost, and licensing?
We do not deal with licensing. Only the accounts team handles that information.
Which other solutions did I evaluate?
I was not part of the evaluation process and did not evaluate other options before going with Cortex XSIAM.
What other advice do I have?
I would recommend Cortex XSIAM to other users because it is a leading solution in the market. I suggest using the trial version to get to know Cortex before proceeding with a full license.
I'd rate the solution ten out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer: MSP
Last updated: Oct 15, 2024
Flag as inappropriateBuyer's Guide
Security Information and Event Management (SIEM)
June 2025

Find out what your peers are saying about Palo Alto Networks, Microsoft, IBM and others in Security Information and Event Management (SIEM). Updated: June 2025.
856,873 professionals have used our research since 2012.
Senioor Engineer of System and Security at Connex Information Technologies
Helps us identify incidents across the network and provides valuable automation capabilities
Pros and Cons
- "The automation capabilities significantly improve response times by allowing us to respond to incidents from a single dashboard rather than navigating multiple dashboards."
- "There is room for improvement in expanding integrations to include more cybersecurity solutions."
What is our primary use case?
We use the product to integrate several third-party logs into the dashboard and perform micro-automation in response to incidents.
What is most valuable?
The platform's most valuable features include third-party integration for analyzing incidents across the network, forensic investigation automation, and playbooks.
What needs improvement?
There is room for improvement in expanding integrations to include more cybersecurity solutions.
For how long have I used the solution?
I have been working with Cortex XSIAM for two years.
What do I think about the stability of the solution?
I rate the product stability a ten.
What do I think about the scalability of the solution?
We have six customers using XSIAM. They are predominantly enterprise businesses. I rate the scalability an eight.
How are customer service and support?
The technical support team can be slow in providing solutions, often requiring additional research or escalations to resolve issues.
How would you rate customer service and support?
Neutral
How was the initial setup?
The documentation on deployment procedures needed to be improved and the deployment options were limited, 95% being cloud-based. It typically takes one to two weeks, though fine-tuning and integration can extend this timeframe depending on the scope.
The process involves integrating our XDR Cortex platform with the XSIAM SaaS deployment or management console, correlating the necessary information, and creating the analytics rules.
I would rate the initial setup experience as a seven.
What's my experience with pricing, setup cost, and licensing?
The product cost could be considered value for money compared to other solutions in the market, though it is quite high.
I rate the pricing a nine.
What other advice do I have?
The platform's analytics capabilities are particularly effective in identifying and correlating incidents. It helps identify endpoint-based incidents.
The automation capabilities significantly improve response times by allowing us to respond to incidents from a single dashboard rather than navigating multiple dashboards.
I rate it an eight.
Disclosure: My company has a business relationship with this vendor other than being a customer: reseller
Commercial Director at a security firm with 11-50 employees
An efficient solution that uses machine learning to identify threats, but its pricing and technical support could be improved
Pros and Cons
- "The most valuable features of Cortex XSIAM are the machine learning used to identify threats, the complexity of the environment of products, and efficiency."
- "The solution’s pricing and technical support could be improved."
What is most valuable?
The most valuable features of Cortex XSIAM are the machine learning used to identify threats, the complexity of the environment of products, and efficiency.
What needs improvement?
The solution’s pricing and technical support could be improved.
For how long have I used the solution?
I have been using Cortex XSIAM for five years.
What's my experience with pricing, setup cost, and licensing?
The solution is expensive compared to its competitors.
What other advice do I have?
Users should test the solution quite massively and deeply to verify whether it really suits their needs.
You have to gather some specific knowledge to really get the profits and fully use the functionalities of the product. It's not an out-of-the-box product.
If you have used the product before and know what you want to achieve, it is easy to use the solution. However, if you are newly using the solution, you have to analyze and know what you want to achieve using this tool.
Overall, I rate Cortex XSIAM a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller

Buyer's Guide
Download our free Security Information and Event Management (SIEM) Report and find out what your peers are saying about Palo Alto Networks, Microsoft, IBM, and more!
Updated: June 2025
Product Categories
Security Information and Event Management (SIEM) Identity Threat Detection and Response (ITDR) AI-Powered Cybersecurity PlatformsPopular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
Splunk Enterprise Security
Darktrace
Cortex XDR by Palo Alto Networks
IBM Security QRadar
Elastic Security
Trend Vision One
Varonis Platform
Vectra AI
Microsoft Defender for Identity
Rapid7 InsightIDR
Fortinet FortiSIEM
Google Chronicle Suite
Securonix Next-Gen SIEM
Buyer's Guide
Download our free Security Information and Event Management (SIEM) Report and find out what your peers are saying about Palo Alto Networks, Microsoft, IBM, and more!
Quick Links
Learn More: Questions:
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- RSA-EMC vs. other SIEM products?
- What Questions Should I Ask Before Buying SIEM?
- What are the pros and cons of internal SOC vs SOC-as-a-Service?
Does Cortex XSIAM have 5 years history?