Try our new research platform with insights from 80,000+ expert users

Cortex XSIAM vs Palo Alto Networks Cortex XSOAR comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
5.1
Cortex XSIAM automates over 50% of workflows, saving up to $500k, benefiting understaffed teams with quick ROI.
Sentiment score
6.9
Cortex XSOAR enhances ROI by automating tasks, requiring mature SOC processes for effective use and reduced false positives.
We are positioning Palo Alto Networks Cortex XSOAR, which can be used in the SOC and do a lot of automation for the customer.
 

Customer Service

Sentiment score
6.4
Cortex XSIAM support receives mixed feedback, with premium plans praised for expert guidance but needing improved responsiveness overall.
Sentiment score
6.4
Palo Alto Networks Cortex XSOAR support is responsive and skilled, though experiences vary with occasional delays and access issues.
With premium support, core Palo Alto technical experts handle issues directly.
It is ineffective in terms of responding to basic queries and addressing future requirements.
The Palo Alto support team is fully responsive and helpful.
Their support has been better than Anomali's and they are more responsive.
The technical support provided by Palo Alto Networks Cortex XSOAR is good.
 

Scalability Issues

Sentiment score
6.9
Cortex XSIAM is praised for its scalability in enterprise and cloud, though some seek better on-premises capabilities.
Sentiment score
7.3
Palo Alto Networks Cortex XSOAR is praised for scalability and integration, handling enterprise demands with careful large deployment planning.
Without proper integration, scaling up with more servers is meaningless.
Cortex XSIAM is highly scalable.
The scalability of Palo Alto Networks Cortex XSOAR supports our growth and security needs because we can integrate various tools and continuously add more capability.
 

Stability Issues

Sentiment score
7.6
Cortex XSIAM is praised for its robust cloud-based stability, offering reliable performance with minimal and swiftly handled issues.
Sentiment score
7.5
Palo Alto Networks Cortex XSOAR is stable and reliable, with occasional bugs and performance issues, especially in cloud environments.
The product was easy to install and set up and worked right.
Overall, Cortex XSIAM is stable.
 

Room For Improvement

Cortex XSIAM needs enhancements in performance, pricing, support, integration, UI intuitiveness, AI analytics, and identity management expansion.
Cortex XSOAR requires improved documentation, expanded IoT support, enhanced features, and better pricing for streamlined integration and user experience.
Obtaining validation for integrations from Palo Alto takes around eight months, which is quite long.
Cortex XSIAM needs improvements in terms of data onboarding, parsers, and third-party integration supports.
Cortex XSIAM is on the expensive side and requires substantial improvement in pricing.
The deployment requires integration and the development of integration modules.
One of the significant issues we encounter is system slowdown when we receive an influx of alerts, which inhibits how quickly we can access the information needed for investigation.
To improve the solution, it needs to have complete features that are low-code, no-code, and should be plug-and-play.
 

Setup Cost

Cortex XSIAM pricing is high but competitive, with costs varying based on add-ons, licensing, and regional differences.
Palo Alto Networks Cortex XSOAR is costly but offers valuable integration and features, appealing to medium and large enterprises.
The first impression is that XSIAM would be more expensive than others we tried.
The product is very expensive.
Cortex XSIAM is pretty expensive, and the licensing process is not very comfortable.
For customers, it is zero versus $20 million, which is why they have to make a decision.
 

Valuable Features

Cortex XSIAM offers advanced security automation, machine learning detection, and seamless integration, enhancing threat management and forensic investigation.
Cortex XSOAR excels in integration, automation, and customization, enhancing security operations with efficient orchestration and high user satisfaction.
The advanced visualization capabilities of the product are important for understanding security trends in an organization.
One of the valued aspects of the product is its use of artificial intelligence to detect security vulnerabilities.
The flexibility for creating manual workflows stands out.
Execution of automatic tasks for collecting, enriching, and correlating security events from hundreds of different technologies.
If I already have an established process, I do not have to change my process to fit into the tool. I can modify the tool to fit into my process, which makes things considerably easier.
We have implemented automation features, such as automated responses to email threats and automatic configuration of target devices for blocking specific IPs.
 

Categories and Ranking

Cortex XSIAM
Average Rating
8.6
Reviews Sentiment
6.9
Number of Reviews
14
Ranking in other categories
Security Information and Event Management (SIEM) (13th), Identity Threat Detection and Response (ITDR) (5th), AI-Powered Cybersecurity Platforms (7th)
Palo Alto Networks Cortex X...
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
48
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (2nd), SOC as a Service (2nd)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Cortex XSIAM is designed for Security Information and Event Management (SIEM) and holds a mindshare of 2.9%, up 1.5% compared to last year.
Palo Alto Networks Cortex XSOAR, on the other hand, focuses on Security Orchestration Automation and Response (SOAR), holds 9.7% mindshare, down 12.2% since last year.
Security Information and Event Management (SIEM) Market Share Distribution
ProductMarket Share (%)
Cortex XSIAM2.9%
Wazuh10.9%
Splunk Enterprise Security9.3%
Other76.9%
Security Information and Event Management (SIEM)
Security Orchestration Automation and Response (SOAR) Market Share Distribution
ProductMarket Share (%)
Palo Alto Networks Cortex XSOAR9.7%
Microsoft Sentinel16.3%
AWS Security Hub8.3%
Other65.7%
Security Orchestration Automation and Response (SOAR)
 

Featured Reviews

AKASH MAJUMDER - PeerSpot reviewer
Incident response times have significantly reduced with efficient device integration and log parsing capabilities
Cortex XSIAM needs improvements in terms of data onboarding, parsers, and third-party integration supports. Additionally, a future update request is to enable tagging of endpoints in groups, similar to a feature available in Cortex XDR. The AI analytics need fine-tuning because some use cases are not working from my side.
DayaramGoyal - PeerSpot reviewer
Offers automation but requires enhancements for intuitive configuration
Palo Alto Networks Cortex XSOAR is a good product with enhanced and efficient playbooks, as demonstrated during our use case simulations. We have implemented automation features, such as automated responses to email threats and automatic configuration of target devices for blocking specific IPs. The analytics feature in Palo Alto Networks Cortex XSOAR is impressive. The solution is quite exhaustive regarding integrations, with many pre-integrations available, especially for market-leading products. There might be challenges with make-in-India products, as they tend not to build the necessary connectors. This depends on whether you are selling to enterprises or other customers. For government customers, you might encounter many Indian products, such as firewalls, which could pose integration challenges unless you have open APIs. However, for market-leading products, there are ready-made integrations available.
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
867,676 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Manufacturing Company
10%
Financial Services Firm
10%
Government
7%
Financial Services Firm
15%
Computer Software Company
11%
Manufacturing Company
9%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise2
Large Enterprise3
By reviewers
Company SizeCount
Small Business19
Midsize Enterprise8
Large Enterprise24
 

Questions from the Community

What do you like most about Cortex XSIAM?
It is an effective solution in terms of performance and functionalities.
What is your experience regarding pricing and costs for Cortex XSIAM?
The cost of Cortex XSIAM in the India market differs from other regions. When considering competition, from a sales perspective, the pricing is acceptable.
What needs improvement with Cortex XSIAM?
The main area for improvement is the user interface intuitiveness - specifically how quickly users can grasp the portal functionality. For SOC analysts, the focus should be on improving the speed o...
What is your experience regarding pricing and costs for Palo Alto Networks Cortex XSOAR?
Comparing pricing to Micro Focus, they were offering bundles, making it free with their SIEM. For customers, it is zero versus $20 million, which is why they have to make a decision.
What needs improvement with Palo Alto Networks Cortex XSOAR?
To improve the solution, it needs to have complete features that are low-code, no-code, and should be plug-and-play. We need to see improvements in that area to facilitate cyber analysts.
 

Also Known As

No data available
Demisto Enterprise, Cortex XSOAR, Demisto
 

Overview

 

Sample Customers

Information Not Available
Cellcom Israel, Blue Cross and Blue Shield of Kansas City, esri, Cylance, Flatiron Health, Veeva, ADT Cybersecurity
Find out what your peers are saying about Splunk, Wazuh, Microsoft and others in Security Information and Event Management (SIEM). Updated: August 2025.
867,676 professionals have used our research since 2012.