Try our new research platform with insights from 80,000+ expert users

Cortex XSIAM vs Elastic Security comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
5.4
Cortex XSIAM saves over $500,000 by automating detection, reducing SOC staffing needs, and improving incident management.
Sentiment score
5.5
Elastic Security often delivers positive ROI within two years, though user satisfaction and views on cost-effectiveness vary.
 

Customer Service

Sentiment score
6.3
Cortex XSIAM support varies in effectiveness, with some users noting delays and inefficiencies, though premium support is praised.
Sentiment score
6.3
Elastic Security feedback is mixed; users praise community support, yet criticize inconsistent technical support and seek faster solutions.
It is ineffective in terms of responding to basic queries and addressing future requirements.
Support is prompt and helpful.
 

Scalability Issues

Sentiment score
7.4
Cortex XSIAM offers scalable, cloud-based security solutions, effortlessly integrating new features and supporting large infrastructures efficiently.
Sentiment score
7.3
Elastic Security is scalable and adaptable, suitable for diverse business needs, though skilled personnel are important for effective management.
Without proper integration, scaling up with more servers is meaningless.
 

Stability Issues

Sentiment score
8.5
Cortex XSIAM is highly rated for stability and performance, with minimal issues, providing reliable cloud-based operation.
Sentiment score
7.6
Elastic Security is stable and reliable, though challenges arise with big data and real-time usage without proper configuration.
The product was easy to install and set up and worked right.
In terms of stability, I would rate Elastic a solid eight out of ten.
 

Room For Improvement

Cortex XSIAM could improve integration, performance, and support with enhanced insights, faster processes, and better GUI deployment.
Elastic Security faces challenges in setup, AI integration, permissions management, user support, and requires improved dashboards and cost-efficiency.
In terms of incident response automation, it is quite poor due to the lack of integration with all security tools, making manual intervention necessary.
Cortex could improve the detection and online resolution of security vulnerabilities.
Improvements could be made to the dashboard and GUI, making it easier to deploy.
CrowdStrike and Defender have more established threat intelligence integration due to having a larger client base.
Elastic Security consumes a lot of resources, requiring a substantial deployment setup.
 

Setup Cost

Cortex XSIAM pricing is competitive yet high, with extra costs for features and integration, delaying some projects.
Elastic Security offers a free open-source option with enterprise features based on usage, making it cost-effective for enterprises.
The product is very expensive.
The first impression is that XSIAM would be more expensive than others we tried.
The pricing is reasonable, especially for Small Medium Enterprises (SMEs), making it a viable option for businesses building their security infrastructure.
Elastic Security is considered cost-effective, especially at lower EPS levels.
 

Valuable Features

Cortex XSIAM offers advanced security orchestration, automation, integration, and ease of use, appealing to Palo Alto users with competitive pricing.
Elastic Security is praised for fast search, scalability, machine learning, customization, integration, and user-friendly, cost-effective features.
The flexibility for creating manual workflows stands out.
Its signature-less subscriptions and robust detection power stand out in improving threat detection.
One of the valued aspects of the product is its use of artificial intelligence to detect security vulnerabilities.
The platform provides more visibility and requires less effort in monitoring.
Elastic Security is as flexible and configurable as Microsoft Sentinel.
 

Categories and Ranking

Cortex XSIAM
Ranking in Security Information and Event Management (SIEM)
18th
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
10
Ranking in other categories
Identity Threat Detection and Response (ITDR) (7th), AI-Powered Cybersecurity Platforms (8th)
Elastic Security
Ranking in Security Information and Event Management (SIEM)
5th
Average Rating
7.6
Reviews Sentiment
6.7
Number of Reviews
63
Ranking in other categories
Log Management (7th), Endpoint Detection and Response (EDR) (16th), Security Orchestration Automation and Response (SOAR) (6th), Extended Detection and Response (XDR) (8th)
 

Mindshare comparison

As of March 2025, in the Security Information and Event Management (SIEM) category, the mindshare of Cortex XSIAM is 2.6%, up from 0.5% compared to the previous year. The mindshare of Elastic Security is 6.9%, down from 9.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM)
 

Featured Reviews

Forrest Stevens - PeerSpot reviewer
A robust security operation that ensures achieving automation, stability, and scalability
There is room for improvement in some areas, and I would highlight three key aspects. Firstly, the Attack Surface Management (ASM) module could benefit from more contextual depth. Currently, it tends to provide a broad overview without enriched context, and there's room for enhancement in this regard. Secondly, further integration capabilities with various other software products that can seamlessly tie into Cortex XSIAM would be advantageous. This would enhance its versatility and interoperability within a broader ecosystem. Regarding performance, there's potential for optimization. When multiple tabs are open in Cortex XSIAM, it can experience slowdowns, leading to longer load times for web pages. It's worth noting that this isn't a severe issue, and it doesn't entail waiting for extended periods, but there is room for improvement in terms of performance optimization.
Nikhil-Kumar - PeerSpot reviewer
Customizable with great dashboards but the premium support is poor
The initial setup can be complex if you don't have technical knowledge. However, once it is deployed, it works well. I'm not sure how long it took to deploy. I wasn't there when it was set up and configured. We have an internal team that handles deployment and maintenance. It doesn't require too many people to deploy. Five or six people would be enough. However, for 24/7 monitoring, you need to have someone always on it.
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
839,422 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
14%
Financial Services Firm
10%
Manufacturing Company
10%
Government
7%
Computer Software Company
16%
Government
10%
Financial Services Firm
10%
University
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Cortex XSIAM?
It is an effective solution in terms of performance and functionalities.
What is your experience regarding pricing and costs for Cortex XSIAM?
The first impression is that XSIAM would be more expensive than others we tried.
What needs improvement with Cortex XSIAM?
Cortex could improve the detection and online resolution of security vulnerabilities. We hope that the artificial intelligence in Cortex will assist in optimizing responses to vulnerabilities.
Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
With Datadog, we have near-live visibility across our entire platform. We have seen APM metrics impacted several times lately using the dashboards we have created with Datadog; they are very good c...
What do you like most about Elastic Security?
Elastic provides the capability to index quickly due to the reverse indexes it offers. This data is crucial as it contains critical information. The reverse index allows fast data indexing because ...
What is your experience regarding pricing and costs for Elastic Security?
Elastic Security is considered cost-effective, especially at lower EPS levels. However, a direct comparison was not made due to different pricing structures.
 

Also Known As

No data available
Elastic SIEM, ELK Logstash
 

Overview

 

Sample Customers

Information Not Available
Texas A&M, U.S. Air Force, NuScale Power, Martin's Point Health Care
Find out what your peers are saying about Cortex XSIAM vs. Elastic Security and other solutions. Updated: January 2025.
839,422 professionals have used our research since 2012.