Try our new research platform with insights from 80,000+ expert users

Cortex XSIAM vs Palo Alto Networks Cortex XSOAR comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
4.6
Cortex XSIAM enhances incident management and provides significant financial returns by automating detection and response, reducing staffing needs.
Sentiment score
6.9
Cortex XSOAR enhances ROI by automating tasks, requiring mature SOC processes for effective use and reduced false positives.
We are positioning Palo Alto Networks Cortex XSOAR, which can be used in the SOC and do a lot of automation for the customer.
Vice President, Technology at Cache Digitech Pvt Ltd.
 

Customer Service

Sentiment score
5.8
Cortex XSIAM support varies; premium service excels, while non-premium experiences depend on distributor expertise and sometimes face delays.
Sentiment score
6.4
Palo Alto Networks Cortex XSOAR support is responsive and skilled, though experiences vary with occasional delays and access issues.
With premium support, core Palo Alto technical experts handle issues directly.
Team Lead, Security at seamlessinfotech.com
It is ineffective in terms of responding to basic queries and addressing future requirements.
Associate Director at a financial services firm with 5,001-10,000 employees
The Palo Alto support team is fully responsive and helpful.
SOC Analyst at OVELOSEC
Their support has been better than Anomali's and they are more responsive.
Enterprise Security Architect V at FirstEnergy
The technical support provided by Palo Alto Networks Cortex XSOAR is good.
Vice President, Technology at Cache Digitech Pvt Ltd.
 

Scalability Issues

Sentiment score
6.5
Cortex XSIAM is scalable for various business sizes with cloud-based integration, but lacks on-premises deployment and mixed reviews.
Sentiment score
7.3
Palo Alto Networks Cortex XSOAR is praised for scalability and integration, handling enterprise demands with careful large deployment planning.
Without proper integration, scaling up with more servers is meaningless.
Associate Director at a financial services firm with 5,001-10,000 employees
Cortex XSIAM is highly scalable.
SOC Analyst at OVELOSEC
The scalability of Palo Alto Networks Cortex XSOAR supports our growth and security needs because we can integrate various tools and continuously add more capability.
Enterprise Security Architect V at FirstEnergy
 

Stability Issues

Sentiment score
7.6
Cortex XSIAM is praised for its stability, rapid issue resolution, and efficient performance despite minor post-update challenges.
Sentiment score
7.5
Palo Alto Networks Cortex XSOAR is stable and reliable, with occasional bugs and performance issues, especially in cloud environments.
The product was easy to install and set up and worked right.
Owner at Xelere
Overall, Cortex XSIAM is stable.
SOC Analyst at OVELOSEC
It works really nice and performs really efficiently after configuration.
IT COMMUNICATIONS AND NETWORKS at Américas BPS
 

Room For Improvement

Cortex XSIAM needs improved integration, performance, interface, pricing, support, ASM, AI, onboarding, tagging, and identity management enhancements.
Cortex XSOAR requires improved documentation, expanded IoT support, enhanced features, and better pricing for streamlined integration and user experience.
Obtaining validation for integrations from Palo Alto takes around eight months, which is quite long.
Associate Director at a financial services firm with 5,001-10,000 employees
Cortex XSIAM needs improvements in terms of data onboarding, parsers, and third-party integration supports.
SOC Analyst at OVELOSEC
Cortex XSIAM is on the expensive side and requires substantial improvement in pricing.
Solutions Architect at ostec
The deployment requires integration and the development of integration modules.
Presale Engineer at Westcon-Comstor
One of the significant issues we encounter is system slowdown when we receive an influx of alerts, which inhibits how quickly we can access the information needed for investigation.
Enterprise Security Architect V at FirstEnergy
To improve the solution, it needs to have complete features that are low-code, no-code, and should be plug-and-play.
Vice President, Technology at Cache Digitech Pvt Ltd.
 

Setup Cost

Cortex XSIAM is viewed as competitively priced but complex, aligning with market expectations despite some regional variations.
Palo Alto Networks Cortex XSOAR is costly but offers valuable integration and features, appealing to medium and large enterprises.
The first impression is that XSIAM would be more expensive than others we tried.
Owner at Xelere
The product is very expensive.
Associate Director at a financial services firm with 5,001-10,000 employees
Cortex XSIAM is pretty expensive, and the licensing process is not very comfortable.
Director at MICROLOGIC NETWORKS PRIVATE LIMITED
For customers, it is zero versus $20 million, which is why they have to make a decision.
Vice President, Technology at Cache Digitech Pvt Ltd.
 

Valuable Features

Cortex XSIAM excels in machine learning threat detection, SOAR features, and advanced automation for efficient security management.
Cortex XSOAR excels in integration, automation, and customization, enhancing security operations with efficient orchestration and high user satisfaction.
The advanced visualization capabilities of the product are important for understanding security trends in an organization.
Solutions Architect at ostec
One of the valued aspects of the product is its use of artificial intelligence to detect security vulnerabilities.
Owner at Xelere
The flexibility for creating manual workflows stands out.
Associate Director at a financial services firm with 5,001-10,000 employees
Execution of automatic tasks for collecting, enriching, and correlating security events from hundreds of different technologies.
Presale Engineer at Westcon-Comstor
If I already have an established process, I do not have to change my process to fit into the tool. I can modify the tool to fit into my process, which makes things considerably easier.
Enterprise Security Architect V at FirstEnergy
We have implemented automation features, such as automated responses to email threats and automatic configuration of target devices for blocking specific IPs.
Vice President, Technology at Cache Digitech Pvt Ltd.
 

Categories and Ranking

Cortex XSIAM
Average Rating
8.6
Reviews Sentiment
6.7
Number of Reviews
15
Ranking in other categories
Security Information and Event Management (SIEM) (14th), Identity Threat Detection and Response (ITDR) (7th), AI-Powered Cybersecurity Platforms (8th)
Palo Alto Networks Cortex X...
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
49
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (3rd), SOC as a Service (2nd)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Cortex XSIAM is designed for Security Information and Event Management (SIEM) and holds a mindshare of 2.4%, up 2.3% compared to last year.
Palo Alto Networks Cortex XSOAR, on the other hand, focuses on Security Orchestration Automation and Response (SOAR), holds 8.9% mindshare, down 11.5% since last year.
Security Information and Event Management (SIEM) Market Share Distribution
ProductMarket Share (%)
Cortex XSIAM2.4%
Splunk Enterprise Security7.4%
Wazuh7.3%
Other82.9%
Security Information and Event Management (SIEM)
Security Orchestration Automation and Response (SOAR) Market Share Distribution
ProductMarket Share (%)
Palo Alto Networks Cortex XSOAR8.9%
Microsoft Sentinel13.0%
Splunk SOAR7.8%
Other70.3%
Security Orchestration Automation and Response (SOAR)
 

Featured Reviews

reviewer2666148 - PeerSpot reviewer
Associate Director at a financial services firm with 5,001-10,000 employees
Integration challenges highlight the need for manual workflows
The standard integrations are very limited, and the integrations available are not listed in the marketplace. Obtaining validation for integrations from Palo Alto takes around eight months, which is quite long. The solution would benefit from having more standard playbooks and templates available, as in other partners. Currently, everything must be created from scratch. In terms of incident response automation, it is quite poor due to the lack of integration with all security tools, making manual intervention necessary.
CC
Enterprise Security Architect V at FirstEnergy
Customization supports seamless workflow while data influx challenges response time
What I appreciate most about Palo Alto Networks Cortex XSOAR is that it is very open, even more so than Anomali. I can create various custom automations and custom fields. There is significant customization ability in this platform. If I already have an established process, I do not have to change my process to fit into the tool. I can modify the tool to fit into my process, which makes things considerably easier. All of our alerts from different tools come into this central place as we have multiple SIEMs. We have items coming from Anomali and other platforms that are not SIEM tools. This serves as our central location where our SOC analysts can work and determine if incident response is needed. The platform provides data enrichment capabilities, offering information upfront so analysts do not have to search for it. They can access details such as username, phone number, email address, and workplace information. For malware files, they can retrieve details from VirusTotal, including file names and environment presence. We have built substantial automation around these features, which also helps us track case metrics, investigation time, and threat mitigation duration.
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
879,422 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Financial Services Firm
10%
Manufacturing Company
9%
Government
7%
Financial Services Firm
13%
Computer Software Company
11%
Manufacturing Company
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise2
Large Enterprise4
By reviewers
Company SizeCount
Small Business19
Midsize Enterprise8
Large Enterprise25
 

Questions from the Community

What do you like most about Cortex XSIAM?
It is an effective solution in terms of performance and functionalities.
What is your experience regarding pricing and costs for Cortex XSIAM?
I did not participate in pricing discussions for Cortex XSIAM solutions, so I cannot provide a review regarding prices for this solution.
What needs improvement with Cortex XSIAM?
Cortex XSIAM is on the expensive side and requires substantial improvement in pricing. There are other features that could be improved, including integration with vendors such as CyberArk. I would ...
What is your experience regarding pricing and costs for Palo Alto Networks Cortex XSOAR?
Comparing pricing to Micro Focus, they were offering bundles, making it free with their SIEM. For customers, it is zero versus $20 million, which is why they have to make a decision.
What needs improvement with Palo Alto Networks Cortex XSOAR?
To improve the solution, it needs to have complete features that are low-code, no-code, and should be plug-and-play. We need to see improvements in that area to facilitate cyber analysts.
 

Also Known As

No data available
Demisto Enterprise, Cortex XSOAR, Demisto
 

Overview

 

Sample Customers

Information Not Available
Cellcom Israel, Blue Cross and Blue Shield of Kansas City, esri, Cylance, Flatiron Health, Veeva, ADT Cybersecurity
Find out what your peers are saying about Splunk, Wazuh, IBM and others in Security Information and Event Management (SIEM). Updated: November 2025.
879,422 professionals have used our research since 2012.