Try our new research platform with insights from 80,000+ expert users
reviewer1361427 - PeerSpot reviewer
IT Director at a energy/utilities company with 1,001-5,000 employees
Real User
Good protection, stable, it integrates well, and the support is good
Pros and Cons
  • "It integrates well into the environment."
  • "I would like to see them include NDR (Network Detection Response)."

What is our primary use case?

We had firewalls set up and it integrated but didn't meet with our regulations.

We were using this solution for endpoint protection.

What is most valuable?

It's a perfect solution. 

It integrates well into the environment.

What needs improvement?

I would like to see them include NDR (Network Detection Response). Then it would work well with SIEM Response. Also, if they could make an on-premises version we would definitely go with Cortes. At this time, they are not offering an on-premises solution.

For how long have I used the solution?

We had it in our environment for two days.

Buyer's Guide
Cortex XDR by Palo Alto Networks
February 2025
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.

What do I think about the stability of the solution?

It's a stable solution.

What do I think about the scalability of the solution?

Cortex XDR by Palo Alto Networks is scalable.

How are customer service and support?

The technical support was good.

Which other solutions did I evaluate?

We evaluated Fideles and are currently using it, as it meets the regulations and is on-premises.

What other advice do I have?

We had to move away from working with Cortex XDR by Palo Alto Networks due to the regulations. They state that the logs have to be kept in Saudi Arabia. Also, the log is in the cloud, which is against the regulations. 

We chose Fidelis. They meet the regulations and they are on-premises.

We had no issues with Cortex. We were satisfied but it didn't meet with the regional regulations.

I would rate Cortex XDR by Palo Alto Networks an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1489881 - PeerSpot reviewer
Network and Cybersecurity Consultant at a tech services company with 11-50 employees
Reseller
A stable detection and response app with a good policy management feature
Pros and Cons
  • "Stability is a primary factor, and then there's the ease of distribution and policy management."
  • "It would be good to have a better way to search for a file within the UI."

What is our primary use case?

We're primarily a Palo Alto shop, and we integrate solutions in the Palo Alto ecosystem. But for firewalls and threat hunting, it's all through Cortex XDR. We also compliment the Cortex XDR product with other endpoint protection solutions, like Windows Defender, or whatever the customer is using,

What is most valuable?

Stability is a primary factor, and then there's the ease of distribution and policy management. Cortex XDR by Palo Alto Networks is very easy to work with, and we're quite happy with them.

What needs improvement?

It would be good to have a better way to search for a file within the UI. Like in SentinelOne, you can search for an arbitrary file, and in Cortex XDR, you can't. You can do it with an addendum license, but I think we could all benefit from getting it with the standard license. Because if you want to do threat hunting with this product, you have to search for files now and not wait to get a license.

For how long have I used the solution?

I've been using Cortex XDR by Palo Alto Networks for about two years.

What do I think about the stability of the solution?

Cortex XDR by Palo Alto Networks is a stable solution.

How are customer service and technical support?

We used to talk to Palo Alto support extensively, and we always had a pleasant experience and never had a problem with them.

How was the initial setup?

Cortex XDR is quite easy to install. The time it takes to deploy depends on the infrastructure. We have had cases that lasted a few days and other cases where it took two to four months for a proof of concept.

What's my experience with pricing, setup cost, and licensing?

Every customer has to pay for a license because it doesn't work with what you get from a managed services provider. It's quite expensive, and they can't sell it for less than 200 euros a license. It's the lowest license price we can get from them.

What other advice do I have?

I would recommend Cortex XDR by Palo Alto Networks to potential users.

On a scale from one to ten, I would give Cortex XDR by Palo Alto Networks a nine.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
PeerSpot user
Buyer's Guide
Cortex XDR by Palo Alto Networks
February 2025
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
reviewer1890849 - PeerSpot reviewer
Network and security engineer at a tech services company with 11-50 employees
Real User
Easy to set up and won't slow down your system but is expensive
Pros and Cons
  • "It'll not slow down your system when compared to others."
  • "We would also like to have advanced tech protection and email scanning."

What is our primary use case?

I'm testing the product right now. I use the solution for endpoint security.

What is most valuable?

Everything is fine. 

It'll not slow down your system when compared to others.

The initial setup is easy.

What needs improvement?

I'd like the solution to provide URL filtering and web-based prevention. We'd like to block web pages at a high level.

We would also like to have advanced tech protection and email scanning.

For how long have I used the solution?

I've been using the solution for a year.

What do I think about the stability of the solution?

The product is very stable and the performance is good. It doesn't slow down the systems it runs on. There are no bugs or glitches. It doesn't crash or freeze. 

What do I think about the scalability of the solution?

The solution can scale well.

More than 100 people are using the solution right now. 

How are customer service and support?

We've never needed the assistance of technical support just yet.

Which solution did I use previously and why did I switch?

I've also used McAfee MVISION Endpoint. 

I'm testing them both and finding the advantages and disadvantages between them.

How was the initial setup?

The solution is very easy to set up.

What's my experience with pricing, setup cost, and licensing?

You do have to pay for a license in order to use a solution. It's expensive.

What other advice do I have?

We're a reseller.

We are using the latest, most up-to-date version, of the product.

I would recommend using it with another protection layer. Cortex should provide an additional layer of security apart from this. You might have to integrate with other vendors also.

If you are looking to deploy a security solution as a whole, this is a good option.

I'd rate the solution seven out of ten. If we had more advanced security features, I'd rate it higher.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1460898 - PeerSpot reviewer
Lead Consultant at a tech services company with 1-10 employees
Real User
Helpful support that can be reached quickly and easily, and the endpoint reporting is good
Pros and Cons
  • "The protection offered by this product is good, as is the endpoint reporting."
  • "Being able to filter the events to see those that are related to the actual alert would save time spent by the engineer."

What is our primary use case?

We are a solution provider and one of the Palo Alto products that we implement for our clients is Cortex XDR (Extended Detection and Response).

It is also known as Traps, and it is mostly used for endpoint protection. For example, when remote users want to connect to their organization using a VPN, they will be protected.

What is most valuable?

The protection offered by this product is good, as is the endpoint reporting.

Once installed, this product is easy to manage, whether it is on-premises or the cloud-based management system.

What needs improvement?

There are a lot of logs generated and an engineer has to go through all of the events to find out exactly what the bottleneck is. We do need to collect the events but this can be time-consuming. Being able to filter the events to see those that are related to the actual alert would save time spent by the engineer.

A better pricing plan would make this product more competitive.

For how long have I used the solution?

We have been dealing with Palo Alto, including Cortex XDR for more than three years.

What do I think about the stability of the solution?

This is a stable product and it is good, but we will keep evaluating other products as we continue to offer this type of solution to our customers.

What do I think about the scalability of the solution?

Cortex XDR is a scalable solution.

How are customer service and technical support?

The technical support team is good, and we can reach them quickly and easily. However, finding a resolution might take time.

Which solution did I use previously and why did I switch?

We have used Cylance in the past, although we stopped using it about three years ago.

We are currently using K7 Endpoint Protection. Unfortunately, it is not catching anything, whether it is malware or a virus.

How was the initial setup?

When we first implemented this product, it was called Traps. However, I don't see any difference, other than the name. For new customers, it might be a bit difficult to install and set up. It takes perhaps eight hours to install.

What about the implementation team?

I deployed this product, and I was also involved with the initial POC.

Only one admin is needed for deployment and a second person should be available to work with the users.

What's my experience with pricing, setup cost, and licensing?

This is an expensive solution.

Which other solutions did I evaluate?

We are currently trying to evaluate ELK.

What other advice do I have?

Overall, this is a good product and I can recommend it to others.

I would rate this solution an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Pre-sales engineer at a tech services company with 51-200 employees
Real User
Best support and good interface, price, and security
Pros and Cons
  • "Its interface and pricing are most valuable. It is better than other vendors in terms of security."
  • "It is not very strong in terms of endpoint management. It should have additional features like DLP, encryption, or advanced device control. Currently, Cortex is good in terms of the security of the endpoints, but it is not as good as other vendors in terms of the management of the endpoint."

What is our primary use case?

We are using it for a banking client.

What is most valuable?

Its interface and pricing are most valuable. It is better than other vendors in terms of security.

What needs improvement?

It is not very strong in terms of endpoint management. It should have additional features like DLP, encryption, or advanced device control. Currently, Cortex is good in terms of the security of the endpoints, but it is not as good as other vendors in terms of the management of the endpoint.

For how long have I used the solution?

I have been using this solution for two years.

What do I think about the stability of the solution?

It is very stable. I wouldn't recommend the latest version. Being a new version, it would have bugs, which is similar to the new versions of other products.

What do I think about the scalability of the solution?

In Peru, we have approximately 20,000 users. The banking client doesn't have any plans to expand the usage. We might increase its usage by 200 to 500 with new clients.

How are customer service and technical support?

Technical support of Palo Alto is the best.

How was the initial setup?

It is very easy to deploy. The deployment is quick. The deployment of the management console takes just two hours, but the deployment of the agent takes approximately a month.

We have five to eight engineers for deployment and maintenance.

What other advice do I have?

I would rate Cortex XDR a nine out of 10.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
PeerSpot user
reviewer1445823 - PeerSpot reviewer
Director of Cloud Security at a comms service provider with 51-200 employees
Real User
Solid solution
Pros and Cons
  • "The dashboard is customizable."
  • "The dashboard could use some significant improvement, just making it more useful with more information. It has a limited amount of information right now. It is customizable, but I'd love to see a better out-of-box dashboard."

What needs improvement?

In terms of what could be improved in Cortex XDR, definitely the host insights module. The ability to kind of take a look at what applications are running on the endpoint is a new feature, but there is a lot of room for improvement there in terms of versioning and so forth.

Additionally, the dashboard could use some significant improvement, just making it more useful with more information. It has a limited amount of information right now. It is customizable, but I'd love to see a better out-of-box dashboard.

For how long have I used the solution?

I have been working with Cortex XDR over the last year, at least.

What other advice do I have?

On a scale of one to ten, I would give Cortex XDR by Palo Alto Networks an eight.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1678701 - PeerSpot reviewer
ISEC Unit Manager at a tech services company with 11-50 employees
Real User
We can manage several clients from the same console, and its endpoint defense is more advanced than traditional antivirus
Pros and Cons
  • "Cortex XDR lets us manage several clients from the same console, and its endpoint defense is more advanced than traditional antivirus."
  • "Cortex XDR is trickier to configure than other Palo Alto products. This is one area where we are not so satisfied."

What is our primary use case?

We have deployed Cortex XDR for a couple of clients in manufacturing.

What is most valuable?

Cortex XDR lets us manage several clients from the same console, and its endpoint defense is more advanced than traditional antivirus.

What needs improvement?

The dashboard could be more user-friendly.

For how long have I used the solution?

I've been using Cortex XDR for two years.

What do I think about the stability of the solution?

Cortex XDR is stable enough.

What do I think about the scalability of the solution?

Cortex's scalability is good. We have about 200 users on it at the moment. 

How are customer service and support?

Palo Alto support is great. 

How was the initial setup?

Cortex XDR is trickier to configure than other Palo Alto products. This is one area where we are not so satisfied. We need two people to deploy and maintain the solution. 

What's my experience with pricing, setup cost, and licensing?

Our clients pay for the license every year. It's just a standard fee with no additional costs. 

What other advice do I have?

I rate Cortex XDR eight out of 10. 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user1009236 - PeerSpot reviewer
SOC Analyst at a tech services company with 201-500 employees
Real User
Valuable firewall and IPS features and has good integration with other products
Pros and Cons
  • "The stability of the solution is very good. We have about 100 users on it right now, and we use it twice a week."
  • "The solution needs better reports. I think they should let the customer go in and customize the reports."

What is most valuable?

The integration with other products, the firewall, and the IPS are good features.

What needs improvement?

The solution needs better reports. I think they should let the customer go in and customize the reports. 

It could also use better graphics and more information.

For how long have I used the solution?

I've been using the solution for four months.

What do I think about the stability of the solution?

The stability of the solution is very good. We have about 100 users on it right now, and we use it twice a week.

How are customer service and technical support?

Technical support has been very good.

What other advice do I have?

I recommend using this solution and I would rate the solution an eight out of 10.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros sharing their opinions.
Updated: February 2025
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros sharing their opinions.