What is our primary use case?
We use Palo Alto Networks Cortex XSOAR for several areas of security automation, such as phishing, investigating, mitigating, the detection of impossible travel, and consolidating threat information for our internal systems.
How has it helped my organization?
It reduces manual interactions of security analysts. Before they had to check on three, or four different websites to see if something was good or bad. Now, Cortex does all of that for us.
What is most valuable?
It is very easy to use.
It has an extensive list of integrations that are available out of the box which makes it easy to start.
What needs improvement?
I would love to see more flexibility on what we can display and design on the dashboards.
For how long have I used the solution?
Palo Alto Networks Cortex XSOAR has been active for six months.
We are always on the latest version.
What do I think about the stability of the solution?
Palo Alto Networks Cortex XSOAR is pretty stable.
What do I think about the scalability of the solution?
It offers some architecture recommendations to make it really scalable if you choose.
For example, hot standby, bond standby, clustering, and breaking out components in dedicated servers. You can go wild if you want to go wild, but we wanted to keep it easy and stable.
Pretty much network security and SOC are the main users. I believe that we are licensed for 20 users.
We are definitely extensively using this solution. We are currently training many additional teams to be self-sufficient in usage. The usage will increase more and more.
How are customer service and technical support?
With Palo Alto technical support, if you get to the right people, you get an answer very quickly.
What I like about the Cortex team is that they have a dedicated select center where you can get service in minutes and that's extremely helpful.
Overall, I am satisfied with the technical support.
Which solution did I use previously and why did I switch?
We evaluated two or three other vendors.
We are a very big Palo Alto shop and we needed to have some Palo Alto features, which are implemented now in Cortex. We are pretty much guided in that direction for some of the security features we need for our firewalls.
How was the initial setup?
I would say the initial setup was really straightforward.
You need to be a little bit aware of Linux unless you buy the hosted version, then you don't need to know anything about it. If you decide you want to run it yourself, you should have some Linux skills because it's a Docker framework on Linux. Knowing a bit about that is handy.
It was up and running in half a day.
What about the implementation team?
It only requires one person to maintain this solution. I do it myself along with many other tasks. In a larger environment, you split into two teams, OS maintenance and application maintenance.
We had help from Palo Alto SE resource for the PoC, but the setup was completed on our own.
What's my experience with pricing, setup cost, and licensing?
We have a concurrent user license.
The licensing is a pretty high price for a user license per year.
The base product is very cheap, you can even get it for free, but the fee per user is expensive. It is approx $10,000 or $20,000 per year for two user licenses.
It's a great product, although it might become very pricey if you need several user licenses.
They need to automate everything to reduce the number of user licenses needed. If it is an automated workflow, you don't need to be licensed.
If Cortex sends an email asking a user to say yes or no, you don't need a license for that user. You just need a user license if you want to improve what Cortex does in terms of workbooks, cases, and more.
Which other solutions did I evaluate?
We evaluated Splunk for six months and decided against it three to six months ago.
What other advice do I have?
Have a very good understanding of what you want to automate. Define the process and make sure the integrations you need are available out of the box.
I would also suggest starting simple. Try easy use cases first and until you feel confident before you get into more complex use cases.
I would rate Palo Alto Networks Cortex XSOAR a nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.