We are a solution provider and this is one of the products that we are selling to our clients.
Director at a tech services company with 11-50 employees
Simple to use, good documentation, and integrates well into the environment
Pros and Cons
- "The most valuable features are simplicity and ease of integration."
- "Implementing this solution requires a lot of involvement from the vendor and it should be made easier for the partners."
What is our primary use case?
What is most valuable?
The most valuable features are simplicity and ease of integration.
The documentation is fantastic.
What needs improvement?
Implementing this solution requires a lot of involvement from the vendor and it should be made easier for the partners.
It has to be richer with respect to IoT. I expect that in future versions, support for a variety of devices will be added.
For how long have I used the solution?
We have about two months of experience with Demisto Enterprise.
Buyer's Guide
Palo Alto Networks Cortex XSOAR
December 2025
Learn what your peers think about Palo Alto Networks Cortex XSOAR. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,768 professionals have used our research since 2012.
What do I think about the stability of the solution?
This is a stable solution.
What do I think about the scalability of the solution?
My impression is that Demisto is scalable and it is capable of working across wide geography at any given point in time. The traffic comes in from everywhere in the world and this solution is able to identify threats ahead of time.
Our clients for this solution are medium-sized and enterprise-level businesses.
How was the initial setup?
The initial setup of this solution is complex. My understanding is that it can be deployed within a few days.
What's my experience with pricing, setup cost, and licensing?
There is a perception that it is priced very high compared to other solutions.
What other advice do I have?
Demisto is a product that I recommend.
I would rate this solution an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Commercial Director at a security firm with 11-50 employees
An overall satisfactory solution, but its pricing and technical support could be improved
Pros and Cons
- "I am satisfied with the product overall."
- "The solution’s price and technical support could be improved."
What is most valuable?
I am satisfied with the product overall.
What needs improvement?
The solution’s price and technical support could be improved.
What other advice do I have?
I would recommend Palo Alto Networks Cortex XSOAR for bigger businesses.
It is the kind of product I would recommend for clients who know what they want to achieve. They can put the potential tools to the test or POCs and verify the checkpoints of their needs before using the product. Palo Alto Networks Cortex XSOAR is not an out-of-the-box kind of product.
Overall, I rate the solution a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Buyer's Guide
Palo Alto Networks Cortex XSOAR
December 2025
Learn what your peers think about Palo Alto Networks Cortex XSOAR. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,768 professionals have used our research since 2012.
Security Operations Center Analyst (L2 at a tech vendor with 10,001+ employees
An easy-to-setup solution with good technical support services
Pros and Cons
- "It is a scalable solution."
- "They should provide integration with machine learning platforms."
What is our primary use case?
We use the solution for incident orchestration.
How has it helped my organization?
The solution helps us with incident analysis.
What is most valuable?
The solution has the best processing and incident analysis features.
What needs improvement?
The solution's price could be better. Also, they should provide integration with machine learning and artificial intelligence platforms.
For how long have I used the solution?
We have been using the solution for seven months.
What do I think about the stability of the solution?
I rate the solution's stability an eight out of ten.
What do I think about the scalability of the solution?
I rate the solution's scalability a ten out of ten.
How are customer service and support?
The solution's technical support team is good.
How would you rate customer service and support?
Positive
How was the initial setup?
The solution's initial setup process is easy. We implement it on the cloud and premises.
What was our ROI?
The solution generates a good return on investment.
What's my experience with pricing, setup cost, and licensing?
The solution's pricing needs improvement.
What other advice do I have?
I recommend the solution to others and rate it a ten out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
User-friendly solution with good stability
Pros and Cons
- "It is a scalable solution."
- "Its dashboard features need improvement."
What is most valuable?
The solution is user-friendly and provides integration with multiple products.
What needs improvement?
The solution's features for reporting and dashboards need improvement. They need more customization options.
For how long have I used the solution?
We have been using the solution for two years.
What do I think about the stability of the solution?
The solution is stable. I rate its stability a nine out of ten.
What do I think about the scalability of the solution?
It is a scalable solution. I rate its scalability an eight out of ten.
How was the initial setup?
The solution's initial setup process with proxy environments is complicated. It takes an hour to two complete.
I rate the process a seven out of ten.
What's my experience with pricing, setup cost, and licensing?
The solution's cost is high. I rate its pricing a nine out of ten.
What other advice do I have?
I rate the solution a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Network and Information Security at a tech services company with 10,001+ employees
Highly scalable solution
Pros and Cons
- "It is quite scalable. I would rate it a ten out of ten."
- "The dashboard performance could be improved."
What is our primary use case?
I work for a company, and we provide support and complete end-to-end management of the product for our customers who hold the product.
How has it helped my organization?
Over thirty users are currently using Palo Alto Networks Cortex XSOAR in your organization. The role is inclusive, like administrator and engineer.
What is most valuable?
According to Gartner, it's a leader in NID. Customers are investing more in it, and that's why we are using the product.
What needs improvement?
The dashboard performance could be improved.
Another area of improvement is a support team. Moreover, we need to pay for modifying anything with scripting in terms of customization. It can be a challenge if the person isn't 100% good with scripting.
For how long have I used the solution?
I have been using this solution for around four years and currently use the latest version.
What do I think about the stability of the solution?
It is a stable solution. I would rate it a nine out of ten.
What do I think about the scalability of the solution?
It is quite scalable. I would rate it a ten out of ten.
How are customer service and support?
Customer support could be better.
How would you rate customer service and support?
Neutral
How was the initial setup?
For maintenance, two or three engineers are involved.
What's my experience with pricing, setup cost, and licensing?
We use the yearly subscription.
What other advice do I have?
Overall, I rate the solution a nine out of ten.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Google
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Professional at a tech services company with 51-200 employees
Great scalability for medium size organizations, diverse automation opportunities, and professional technical support
Pros and Cons
- "The most valuable feature is automation."
- "I think they should increase their collaboration base."
What is our primary use case?
Our primary case issues are phishing, TI, and sensors.
What is most valuable?
The most valuable feature is automation. There is a huge variety of automation that can help any team and there is a threat model.
What needs improvement?
I think they should increase their collaboration base so that XSOAR can be utilized for any number of automation.
For how long have I used the solution?
I have been using Palo Alto Networks Cortex XSOAR for the past two years.
What do I think about the stability of the solution?
Stability takes around three to six months to achieve complete stability in the environment.
What do I think about the scalability of the solution?
The existing model is good, but if we go for big deployments, I think there are a few challenges in scalability. They use their internal BoltDB, which is good for a medium organization, but for large organizations, they support Elasticsearch, which is too costly. The DR capabilities are not good.
How are customer service and support?
Technical support is professional, but they are not very friendly. The overall remote support is not where it should be.
How would you rate customer service and support?
Neutral
How was the initial setup?
Palo Alto Networks Cortex XSOAR has a straightforward setup. Stability takes three months to six months, and then further stability, performance, and then complete utilization. Usually, it takes around a year to deploy it fully.
What about the implementation team?
Normally, we use a third-party team to help us with the deployment.
What other advice do I have?
I would rate Palo Alto Networks Cortex XSOAR an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
None at a tech services company with 11-50 employees
A scalable and stable product that has artificial intelligence and machine learning capabilities
Pros and Cons
- "The solution provides threat intelligence with EDR."
- "The solution should be made a bit cheaper."
What is our primary use case?
The product can be used for securing endpoints from various types of attacks, threat incidents, and malware attacks.
What is most valuable?
NGFW and Cortex are the best features of the product. The solution provides threat intelligence with EDR. The most interesting part is that the product uses artificial intelligence and machine learning capabilities.
What needs improvement?
The solution should be made a bit cheaper.
For how long have I used the solution?
I have been using the solution for six months.
What do I think about the stability of the solution?
The solution is quite stable.
What do I think about the scalability of the solution?
The product is scalable. It can integrate with a lot of products.
How are customer service and support?
Support is good.
How was the initial setup?
The initial setup is straightforward.
What about the implementation team?
With the right skillsets, the deployment is quite easy and does not take a lot of time. You can do the deployment manually or push it through your Active Directory.
What other advice do I have?
I would definitely recommend the product to others. Overall, I rate the product a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Supervisor SOC at a tech services company with 51-200 employees
Integrates well, stable, and good technical support
Pros and Cons
- "I have found the solution very useful, it integrates well with other platforms."
- "The configuration of the solution could improve it is difficult."
What is most valuable?
I have found the solution very useful, it integrates well with other platforms.
For how long have I used the solution?
I have used Palo Alto Networks Cortex XSOAR within the last 12 months.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
I have found Palo Alto Networks Cortex XSOAR to be scalable all the time.
How are customer service and support?
The technical support is good.
How was the initial setup?
The configuration of the solution could improve it is difficult.
What about the implementation team?
We have four engineers that do the implementation and maintenance of the solution.
What's my experience with pricing, setup cost, and licensing?
The price of Palo Alto Networks Cortex XSOAR is expensive.
What other advice do I have?
I rate Palo Alto Networks Cortex XSOAR a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
Download our free Palo Alto Networks Cortex XSOAR Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2025
Popular Comparisons
Microsoft Sentinel
IBM Security QRadar
AWS Security Hub
Arctic Wolf Managed Detection and Response
Stellar Cyber Open XDR
NetWitness NDR
Sumo Logic Security
ThreatConnect Threat Intelligence Platform (TIP)
ServiceNow Security Operations
Google Security Operations
Fortinet FortiSOAR
Buyer's Guide
Download our free Palo Alto Networks Cortex XSOAR Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which Do You Recommend, Phantom or Demisto?
- Which solution do you prefer: Microsoft Sentinel or Palo Alto Networks Cortex XSOAR?
- Which SOAR product has the better value: Palo Alto Networks Cortex XSOAR or Swimlane? Why?
- What are the Top 5 cybersecurity trends in 2022?
- What is the difference between SIEM and SOAR platforms?
- What is an incident response playbook and how is it used in SOAR?
- What are the latest trends in Security Operations Center (SOC)?
- What tools and solutions do you use for automated incident response in an enterprise in 2022?
- How to evaluate SIEM detection rules?
- Why a Security Operations Center (SOC) is important?

















