Try our new research platform with insights from 80,000+ expert users

Cortex XSIAM vs Elastic Security comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
5.4
Automation increased ROI by over $500,000, reduced analyst needs, and improved incident handling, though some are still evaluating.
Sentiment score
5.9
Elastic Security often delivers positive ROI within two years, though user satisfaction and views on cost-effectiveness vary.
It does not require hefty security budgets and can be deployed for enterprise security effectively.
 

Customer Service

Sentiment score
6.9
Cortex XSIAM support varies widely, with mixed reviews; premium support receives better feedback due to experienced staff.
Sentiment score
6.4
Elastic Security feedback is mixed; users praise community support, yet criticize inconsistent technical support and seek faster solutions.
It is ineffective in terms of responding to basic queries and addressing future requirements.
Most of the time when my team encounters issues, they receive responses within 24 hours.
Support is prompt and helpful.
 

Scalability Issues

Sentiment score
7.2
Cortex XSIAM is mostly seen as highly scalable, adaptable, and integrates seamlessly across various enterprises and IT departments.
Sentiment score
7.3
Elastic Security is scalable and adaptable, suitable for diverse business needs, though skilled personnel are important for effective management.
Without proper integration, scaling up with more servers is meaningless.
It allows us to think about specific use cases, such as gathering malicious IPs in a single view and analyzing threats based on geolocation.
 

Stability Issues

Sentiment score
8.5
Cortex XSIAM is highly stable and reliable, often scoring 10/10, with rapid resolution of occasional update-related issues.
Sentiment score
7.7
Elastic Security is stable and reliable, though challenges arise with big data and real-time usage without proper configuration.
The product was easy to install and set up and worked right.
In terms of stability, I would rate Elastic a solid eight out of ten.
 

Room For Improvement

Cortex XSIAM should enhance context, integration, flexibility, and support while streamlining its pricing and improving incident response automation.
Elastic Security faces challenges in setup, AI integration, permissions management, user support, and requires improved dashboards and cost-efficiency.
Obtaining validation for integrations from Palo Alto takes around eight months, which is quite long.
Improvements could be made to the dashboard and GUI, making it easier to deploy.
Cortex XSIAM is pretty expensive, and the licensing process is not very comfortable compared to CrowdStrike.
CrowdStrike and Defender have more established threat intelligence integration due to having a larger client base.
My security testing team continuously reports vulnerabilities, and we have to fix and update the versions frequently.
Elastic Security consumes a lot of resources, requiring a substantial deployment setup.
 

Setup Cost

Enterprise users find Cortex XSIAM costly, but competitive pricing; extra features and licensing complexity increase expenses.
Elastic Security offers a free open-source option with enterprise features based on usage, making it cost-effective for enterprises.
The first impression is that XSIAM would be more expensive than others we tried.
The product is very expensive.
Cortex XSIAM is pretty expensive, and the licensing process is not very comfortable.
This is beneficial for SMEs as they do not need extensive budgets for security solutions.
The pricing is reasonable, especially for Small Medium Enterprises (SMEs), making it a viable option for businesses building their security infrastructure.
Elastic Security is considered cost-effective, especially at lower EPS levels.
 

Valuable Features

Cortex XSIAM offers strong security orchestration, AI threat mitigation, and competitive pricing, with seamless third-party integration and user-friendly setup.
Elastic Security is praised for fast search, scalability, machine learning, customization, integration, and user-friendly, cost-effective features.
The flexibility for creating manual workflows stands out.
Its signature-less subscriptions and robust detection power stand out in improving threat detection.
Cortex XSIAM is able to detect abnormal behavior of malicious code and subsequently block it.
We require rapid processing speed for alerts and event data, and Elastic Security is very efficient at handling this level of data.
The platform provides more visibility and requires less effort in monitoring.
Elastic Security is as flexible and configurable as Microsoft Sentinel.
 

Categories and Ranking

Cortex XSIAM
Ranking in Security Information and Event Management (SIEM)
17th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
11
Ranking in other categories
Identity Threat Detection and Response (ITDR) (6th), AI-Powered Cybersecurity Platforms (7th)
Elastic Security
Ranking in Security Information and Event Management (SIEM)
5th
Average Rating
7.8
Reviews Sentiment
6.8
Number of Reviews
64
Ranking in other categories
Log Management (7th), Endpoint Detection and Response (EDR) (16th), Security Orchestration Automation and Response (SOAR) (6th), Extended Detection and Response (XDR) (8th)
 

Mindshare comparison

As of April 2025, in the Security Information and Event Management (SIEM) category, the mindshare of Cortex XSIAM is 2.8%, up from 0.6% compared to the previous year. The mindshare of Elastic Security is 6.6%, down from 9.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM)
 

Featured Reviews

Forrest Stevens - PeerSpot reviewer
A robust security operation that ensures achieving automation, stability, and scalability
There is room for improvement in some areas, and I would highlight three key aspects. Firstly, the Attack Surface Management (ASM) module could benefit from more contextual depth. Currently, it tends to provide a broad overview without enriched context, and there's room for enhancement in this regard. Secondly, further integration capabilities with various other software products that can seamlessly tie into Cortex XSIAM would be advantageous. This would enhance its versatility and interoperability within a broader ecosystem. Regarding performance, there's potential for optimization. When multiple tabs are open in Cortex XSIAM, it can experience slowdowns, leading to longer load times for web pages. It's worth noting that this isn't a severe issue, and it doesn't entail waiting for extended periods, but there is room for improvement in terms of performance optimization.
Gajewski Marek - PeerSpot reviewer
Provides good anomaly detection and connectivity reporting
We previously used Splunk but switched to Elastic Security because Splunk was more expensive. Feature-wise, both tools are pretty much the same. They have almost the same functions. Elastic Security has a much better AI assistant that allows you to ask questions like a normal person. With Elastic Security, I can also predict the price and how much it will cost. Splunks's pricing depends on how much data we use and the different add-ons I have to add. The pricing is much better with Elastic Security.
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
845,406 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
14%
Financial Services Firm
10%
Manufacturing Company
10%
Government
7%
Computer Software Company
17%
Government
10%
Financial Services Firm
9%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Cortex XSIAM?
It is an effective solution in terms of performance and functionalities.
What is your experience regarding pricing and costs for Cortex XSIAM?
The product is very expensive. Additional integration and support are not provided by Cortex and must be purchased from partners. This adds to the cost and delays projects due to resource dependency.
What needs improvement with Cortex XSIAM?
The standard integrations are very limited, and the integrations available are not listed in the marketplace. Obtaining validation for integrations from Palo Alto takes around eight months, which i...
Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
With Datadog, we have near-live visibility across our entire platform. We have seen APM metrics impacted several times lately using the dashboards we have created with Datadog; they are very good c...
What do you like most about Elastic Security?
Elastic provides the capability to index quickly due to the reverse indexes it offers. This data is crucial as it contains critical information. The reverse index allows fast data indexing because ...
What is your experience regarding pricing and costs for Elastic Security?
Elastic Security is considered cost-effective, especially at lower EPS levels. However, a direct comparison was not made due to different pricing structures.
 

Also Known As

No data available
Elastic SIEM, ELK Logstash
 

Overview

 

Sample Customers

Information Not Available
Texas A&M, U.S. Air Force, NuScale Power, Martin's Point Health Care
Find out what your peers are saying about Cortex XSIAM vs. Elastic Security and other solutions. Updated: March 2025.
845,406 professionals have used our research since 2012.