Try our new research platform with insights from 80,000+ expert users

Cortex XSIAM vs Splunk SOAR comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 8, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Customer Service

Sentiment score
7.3
Cortex XSIAM's customer service is mixed, with some users praising effectiveness and others experiencing delays and escalation needs.
Sentiment score
7.1
Splunk SOAR's support is praised for responsiveness and resources, with improvements needed in telecom and IoT support areas.
 

Room For Improvement

Sentiment score
5.5
Cortex XSIAM needs better integration, performance, developer-friendliness, and AI-enhanced security solutions despite satisfactory current features.
Sentiment score
4.3
Splunk SOAR needs better integration, usability, documentation, and pricing, with limited customization, case management, and a missing Android app.
Cortex could improve the detection and online resolution of security vulnerabilities.
 

Scalability Issues

Sentiment score
8.5
Cortex XSIAM is highly scalable in the cloud, supporting enterprises efficiently and earning high user ratings for scalability.
Sentiment score
7.1
Splunk SOAR is scalable and adaptable, performing well in various environments, despite some challenges with hardware and configuration.
 

Setup Cost

Sentiment score
4.0
Cortex XSIAM pricing is competitive, considered reasonable yet costly with add-ons, offering value but varies on affordability.
Sentiment score
5.7
Splunk SOAR uses a data-processed pricing model, offering volume discounts, with costs from $100,000 to $1 million.
The first impression is that XSIAM would be more expensive than others we tried.
 

Stability Issues

Sentiment score
9.1
Cortex XSIAM is highly stable and reliable, with minimal downtime, swift issue resolution, and easy installation.
No sentiment score available
The product was easy to install and set up and worked right.
 

Valuable Features

Sentiment score
8.8
Cortex XSIAM provides advanced threat detection, integration, and user-friendly features, enhancing security management for Palo Alto users.
Sentiment score
8.3
Splunk SOAR enhances security operations with flexible integrations, efficient automation, customizable playbooks, robust analytics, and seamless third-party integration.
One of the valued aspects of the product is its use of artificial intelligence to detect security vulnerabilities.
 

Categories and Ranking

Cortex XSIAM
Average Rating
9.0
Reviews Sentiment
7.6
Number of Reviews
8
Ranking in other categories
Security Information and Event Management (SIEM) (14th), Identity Threat Detection and Response (ITDR) (6th), AI-Powered Cybersecurity Platforms (6th)
Splunk SOAR
Average Rating
8.2
Reviews Sentiment
6.8
Number of Reviews
43
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (3rd)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Cortex XSIAM is designed for Security Information and Event Management (SIEM) and holds a mindshare of 2.1%, up 0.2% compared to last year.
Splunk SOAR, on the other hand, focuses on Security Orchestration Automation and Response (SOAR), holds 8.6% mindshare, down 9.8% since last year.
Security Information and Event Management (SIEM)
Security Orchestration Automation and Response (SOAR)
 

Featured Reviews

Forrest Stevens - PeerSpot reviewer
A robust security operation that ensures achieving automation, stability, and scalability
There is room for improvement in some areas, and I would highlight three key aspects. Firstly, the Attack Surface Management (ASM) module could benefit from more contextual depth. Currently, it tends to provide a broad overview without enriched context, and there's room for enhancement in this regard. Secondly, further integration capabilities with various other software products that can seamlessly tie into Cortex XSIAM would be advantageous. This would enhance its versatility and interoperability within a broader ecosystem. Regarding performance, there's potential for optimization. When multiple tabs are open in Cortex XSIAM, it can experience slowdowns, leading to longer load times for web pages. It's worth noting that this isn't a severe issue, and it doesn't entail waiting for extended periods, but there is room for improvement in terms of performance optimization.
Ryan Plas - PeerSpot reviewer
Offers playbook automation that helps reduce the manual and tedious work for users
When it comes to Splunk SOAR's ability to provide end-to-end visibility into our company's cloud-native environment, I would say that we are not using the cloud portions of it. I don't know if that's super relevant to what we are doing in our organization. I am 100 percent sure that Splunk SOAR helped reduce your mean time to resolve, but I don't have any metrics on hand but I know it has dramatically decreased. The tool has helped with the business resilience part. I think having it as a platform has been a solid portion of the product that we offer to people. Spunk SOAR has definitely saved my time in alert triage. When some of the tedious enrichment and lookup stuff happens, the analyst doesn't have to deal with such areas, and they can just jump in and see relevant data all in one pane of glass, which has been super helpful for speeding things up. The unified platform helps consolidate networking, security, and IT observability tools. The consolidation of tools impacts our organization as it just helps focus the SOC analyst on a single unified place to find information. It helps keep things streamlined and regular so they know where to look for certain stuff they want. It really helps people with training. It is a really easy tool to onboard people into because everything is right there in the product itself. The product is really great. I would love to see more SOAR innovation going into the tool, especially the on-premises version since it is what we use in our company. I feel the tool needs to encourage continuous improvements, but as a product itself, my company is really happy with the solution. I rate the tool an eight out of ten.
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
823,875 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
13%
Manufacturing Company
11%
Financial Services Firm
10%
Government
7%
Computer Software Company
15%
Financial Services Firm
14%
Manufacturing Company
11%
Government
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Cortex XSIAM?
It is an effective solution in terms of performance and functionalities.
What is your experience regarding pricing and costs for Cortex XSIAM?
The first impression is that XSIAM would be more expensive than others we tried.
What needs improvement with Cortex XSIAM?
Cortex could improve the detection and online resolution of security vulnerabilities. We hope that the artificial intelligence in Cortex will assist in optimizing responses to vulnerabilities.
What do you like most about Splunk Phantom?
Splunk SOAR's quick response to incidents is the most valuable part.
What is your experience regarding pricing and costs for Splunk Phantom?
I rate Splunk SOAR two out of 10 for affordability. Splunk is a fast enterprise tool, but it costs too much. At the same time, it's worth what we pay, in my opinion. We can efficiently perform all ...
What needs improvement with Splunk Phantom?
The dashboard could be improved and some other features. SOAR should integrate network capabilities, allowing us to also monitor the WLAN network. Splunk is also expensive and difficult for beginne...
 

Also Known As

No data available
Phantom
 

Overview

 

Sample Customers

Information Not Available
Recorded Future, Blackstone
Find out what your peers are saying about Splunk, Wazuh, Microsoft and others in Security Information and Event Management (SIEM). Updated: November 2024.
823,875 professionals have used our research since 2012.