The negative aspect of Palo Alto Networks Cortex XSOAR is the price; cost-wise, it is a bit higher. Other than enterprise clients, they might need to push their management to get additional approval to proceed with Palo Alto due to that higher investment. If Palo Alto can work on being more aggressive, especially on the pricing part, their product could be more reachable, and that might lead to more sales, providing more revenue to them. The higher cost is one of the negatives for them. Improvements are needed, especially in after-sales support. If the chatbox itself, after a set of AI responses, can be redirected to TAC, that would be better to create tickets when facing challenges. Currently, we communicate in a chatbot, and once it gets exhausted, we have to start a TAC ticket from scratch. This process needs to be repeated in TAC as well. Having the chatbox convert into a TAC ticket would save us time in repeating all these questions and answers.
One area for improvement I see in Cortex XSOAR is the cost. It is too costly, although it offers a lot of features for security operation centers, especially in complex environments, but the overall cost of ownership is high, making it not easy to maintain for small or SMB customers. Compared to competitors, if I compare Cortex XSOAR with Zscaler or any other vendor, they are leaders from an automation perspective. However, there are competitors such as Splunk and FortiNet. FortiNet offers a cost-efficient solution but lacks technical strength compared to Palo Alto, making Cortex XSOAR's overall technical ability and the value it provides superior.
One disadvantage or thing which can be improved in Palo Alto Networks Cortex XSOAR is the cost because it is too costly. I know that it offers many things for any security operation center, especially for complex environments, but overall, the cost of ownership is too high. This is something which needs to be taken care of. From the technical side, unless a customer has very specific requirements stating they do not want to put all eggs in a single basket, the product is very good from the scalability perspective and from the time to put the platform in production. Everything is fine, but the cost is concerning. For small or SMB or small enterprise customers, it is really not that easy to maintain the tool from the commercial perspective. There is ROI for Palo Alto Networks Cortex XSOAR without doubt, but because customers have their own budgets, this is the only feedback which I have received from customers where we have positioned Cortex XSOAR.
Currently, we haven't worked on playbook automation. It is very difficult to work on the integration part when it comes to implementation. However, when we implement properly, we have a good enhancement. The biggest challenge when we implement is that we need to have properly certified experienced engineers to do that. Otherwise, it is very difficult to get it implemented. It is not easy to integrate with other tools. If we have experienced certified engineers, then it will be an easy task. Otherwise, if we don't have certified engineers, it is very difficult. We can't just pass it to the customers and say that they can get it done from their knowledge. We need to have the proper certified experienced engineers to get it done. It is both difficult to implement, deploy, and integrate the product. When we position Palo Alto Networks Cortex XSOAR, we are targeting the ISP level and high enterprise customers who can afford that solution. The price will be high, but the solution is absolutely superb. Therefore, we are highly focusing on those kinds of products for the ISP side and high-level enterprise customers. Still, we are not doing those kinds of things regarding machine learning models in Palo Alto Networks Cortex XSOAR. The biggest challenge we are facing is the pricing factor and the implementation. We need to have the proper engineers for the implementation and the pricing factor. Otherwise, we are not experiencing any kind of issues. We prefer if we could get to do configurations and push them throughout the cloud for remote sessions. For remote locations, if we could push configurations and everything through the cloud, that would be great.
I did notice some drawbacks, as it is a bit complex. The deployment and implementation are complex in nature. Integration with third-party tools had some issues, particularly with open source platforms, but enterprise tools integrated just fine. The exact platform we integrated required custom solutions, especially with open-source tools.
I believe ease of use would be an improvement for Palo Alto Networks Cortex XSOAR, as I see this as a valuable feature for future iterations. For queries, I believe improvement in that area could enhance Palo Alto Networks Cortex XSOAR further.
Learn what your peers think about Palo Alto Networks Cortex XSOAR. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
Palo Alto Networks Cortex XSOAR can be improved if it can include AI modules within Palo Alto Networks Cortex XSOAR as a product or at least as a summarizing feature. If that is there, I think it would make it easier for analysts to go through the alert. Another area I can suggest is the searching or reporting feature where you have to write a query, which is definitely good for searching your incidents. However, if you have long queries and if you want to take out reports, that is when the real challenge comes in. Probably an advanced search within Palo Alto Networks Cortex XSOAR incidents tab could address this.
Regarding areas for improvement in Palo Alto Networks Cortex XSOAR, I want to highlight one concern about playbook creation. While I personally appreciate this approach, I have observed that junior analysts on my team find it difficult to build playbooks. If Palo Alto Networks could improve the ease of use, specifically for playbook creation, that would be beneficial, as this is a gap I have identified. When I create a playbook for spyware or malware, I need to develop level one, level two, and sometimes level three sub-playbooks. Fetching data in the input and output fields is sometimes challenging. I have observed that junior analysts find this particularly challenging, so I believe it would be valuable to simplify the process of creating and configuring input fields and sub-playbooks.
I think Palo Alto Networks Cortex XSOAR can be improved as it has a little bit higher cost than any other SOAR. I think Palo Alto needs to reconsider the pricing for Palo Alto Networks Cortex XSOAR.
Vice President, Technology at Cache Digitech Pvt Ltd.
Reseller
Top 5
Aug 18, 2025
To improve the solution, it needs to have complete features that are low-code, no-code, and should be plug-and-play. We need to see improvements in that area to facilitate cyber analysts.
For Palo Alto Networks Cortex XSOAR, there is always room for improvement. One of the significant issues we encounter is system slowdown when we receive an influx of alerts, which inhibits how quickly we can access the information needed for investigation.
The complexity of Cortex XSOAR has a trade-off with its versatility. The product can be tailored for each deployment to respond to specific customer needs, and this complexity may be seen as a downside. The deployment requires integration and the development of integration modules. Deployment is not easy, requiring significant tuning and building of integrations over weeks.
The price of the solution could be lower. Companies utilizing this solution should have a well-developed cybersecurity team to maximize its benefits. It is more suited for large organizations rather than small or medium-sized companies.
Recently, they started implementing microservices in XSOAR, which has improved quality and addressed previous issues. However, they should focus more on licensing costs. The user licensing fees are quite high. For example, I received a quote for XSOAR, and it was $12,000 per user per year. If you have a SOC team of 30 members/analysts, you're looking at a substantial expense. They should consider reducing these costs since this high pricing seems to be more about profit. So, there is room for improvement in the pricing. Moreover, the reporting and dashboard features are decent but could be improved. The user interface (UI) is quite heavy and takes time to load, which is a major drawback.
The solution is complicated to learn. Customers find it difficult to learn how the solution works. We need professionals to learn and understand how the tool works to expand it further. Our customers want to see more use cases. They want to have more facilitations and more visibility on how it works. We need more skilled people inside and outside the team to understand how it works. It’s difficult to find skilled people to understand how the tool works.
Cybersecurity incident response team lead at Information Technology Solutions- ITS
Real User
Sep 29, 2023
One limitation I have noticed with Cortex XSOAR is that it doesn't offer automatic threat intel reports out of the box. However, you can achieve this through coding, and we have managed to do it in our own environment using scripts and playbooks. It is not a built-in feature, but it is possible with some coding skills. The good news is that Palo Alto Networks plans to make this process more automated in the future, but it is not available yet.
Network and Information Security at a tech services company with 10,001+ employees
Real User
Apr 7, 2023
The dashboard performance could be improved. Another area of improvement is a support team. Moreover, we need to pay for modifying anything with scripting in terms of customization. It can be a challenge if the person isn't 100% good with scripting.
Head of Security Monitoring and Control at Alstom Ferroviaria S.p.A.
Real User
Nov 14, 2022
Customization and performance can be improved. For example, some formats were incompatible when integrating, and they said we needed to work with the vendor to fix this issue because some logs that AVA logs were not compatible, and it did not readily recognize the format. Most of the time, I heard this as feedback. The formats are not compatible, are readily not available, and are not readable. Then we had to work it and write it manually.
Manager at a financial services firm with 5,001-10,000 employees
Real User
Top 10
Oct 7, 2022
Integrations with other applications are challenging and need to be improved. Reports or issues are often duplicated. The solution requires DV but does not support open-source DV elastic searches.
I would like to see Cortex become less dependent on Active Directory and group policies to manage the deployment. Maybe I need to update my understanding of how to deploy it, but that's the way I know how to use it. That makes it somewhat challenging to deploy Cortex where not every client is part of the directory. I've also had some problems with the update process, and it's failed two or three times.
Nothing needs to be changed. It is a part of Cortex inside Palo Alto Networks. If you want to get all the benefits, you will need the Cortex XDR, then you will need to get Cortex XSOAR. It's like a brother and sister, and they will give you a lot of benefits if you integrate them. It's only one cloud right now. It might be helpful for some companies to have an on-premies option.
Associate Director at a financial services firm with 5,001-10,000 employees
Real User
Top 10
Jul 19, 2022
It doesn't have any integrations. It lacks multiple integrations. It is been decommissioned by Palo Alto. There's no more trying to support it. There will be no more additional items added. The initial setup was complex.
IT Operations Deputy Manager at Ultramar Agencia MarĂtima
Real User
Jun 1, 2022
Palo Alto Networks Cortex XSOAR could improve the look, feel, and management of the cloud console. Additionally, the user could be more easily integrated.
Corex XSOAR could be improved by reducing the time it takes to process large amounts of data and increasing the number of integrations. In the next release, Palo Alto should include popup features - for example, if someone is working on an incident, it should pop up and display in front of me once it's clicked.
Cybersecurity Cyber Crime Infrastructure Engineer & Investigator at a government with 5,001-10,000 employees
Real User
Nov 11, 2021
In terms of improvement, it needs to be more modular. It's not. When you're working in layouts and you create specific apps within layouts, there's no portability right now in order to reuse that code across multiple layouts. I can't take a tab and say I want to use this tab on these other layouts. I have to physically go in there and recreate it from scratch, which is maddening. From an analyst perspective, it's not that hard to use. From a developer, it takes a little while in order to get to understand exactly how one would go about creating a playbook. The automation part is not that hard. It's relatively easy. It's just creating the flowchart.
Delivery Manager at a tech services company with 1,001-5,000 employees
Reseller
Top 5
May 15, 2021
We'd like to be able to add as many integrations as possible. We would like more options for our clients. A few times, I have noticed some bugs. That may be due to the fact that they are consistently upgrading the product. With new releases, a few bugs might get through. The solution is expensive. They should work to make it less costly for the customer.
Regional Director, Customer Success (GTM Solutions & Services) at a tech services company with 51-200 employees
MSP
Apr 16, 2021
Although we haven't used the solution for too long, we haven't come across any issues and haven't noticed any features that are lacking. We're largely satisfied with the offering. The user interface could be a bit better. It's the only aspect I've noticed that could possibly be improved. Other than that, we've been pretty happy with it.
Network Security Engineer at a tech services company with 201-500 employees
Real User
Nov 4, 2020
For building automation, there is not a lot of good documentation. The documentation is there, but it is not very good from my perspective. There should be an improvement in this area. I don't see issues with anything else. In terms of new features, I have heard that other products have EBA functionality. It would be good if this functionality could be added.
Director at a tech services company with 11-50 employees
Reseller
Apr 23, 2020
Implementing this solution requires a lot of involvement from the vendor and it should be made easier for the partners. It has to be richer with respect to IoT. I expect that in future versions, support for a variety of devices will be added.
Palo Alto Networks Cortex XSOAR enhances security operations automation and integration. Users rely on its incident management capabilities and machine learning to improve response times and efficiency.Cortex XSOAR stands out for its capability to automate and orchestrate security tasks through customizable playbooks and robust third-party integrations. Its analytics offer insights into incidents, while machine learning prioritizes alerts and reduces false positives. Despite its powerful...
The negative aspect of Palo Alto Networks Cortex XSOAR is the price; cost-wise, it is a bit higher. Other than enterprise clients, they might need to push their management to get additional approval to proceed with Palo Alto due to that higher investment. If Palo Alto can work on being more aggressive, especially on the pricing part, their product could be more reachable, and that might lead to more sales, providing more revenue to them. The higher cost is one of the negatives for them. Improvements are needed, especially in after-sales support. If the chatbox itself, after a set of AI responses, can be redirected to TAC, that would be better to create tickets when facing challenges. Currently, we communicate in a chatbot, and once it gets exhausted, we have to start a TAC ticket from scratch. This process needs to be repeated in TAC as well. Having the chatbox convert into a TAC ticket would save us time in repeating all these questions and answers.
One area for improvement I see in Cortex XSOAR is the cost. It is too costly, although it offers a lot of features for security operation centers, especially in complex environments, but the overall cost of ownership is high, making it not easy to maintain for small or SMB customers. Compared to competitors, if I compare Cortex XSOAR with Zscaler or any other vendor, they are leaders from an automation perspective. However, there are competitors such as Splunk and FortiNet. FortiNet offers a cost-efficient solution but lacks technical strength compared to Palo Alto, making Cortex XSOAR's overall technical ability and the value it provides superior.
One disadvantage or thing which can be improved in Palo Alto Networks Cortex XSOAR is the cost because it is too costly. I know that it offers many things for any security operation center, especially for complex environments, but overall, the cost of ownership is too high. This is something which needs to be taken care of. From the technical side, unless a customer has very specific requirements stating they do not want to put all eggs in a single basket, the product is very good from the scalability perspective and from the time to put the platform in production. Everything is fine, but the cost is concerning. For small or SMB or small enterprise customers, it is really not that easy to maintain the tool from the commercial perspective. There is ROI for Palo Alto Networks Cortex XSOAR without doubt, but because customers have their own budgets, this is the only feedback which I have received from customers where we have positioned Cortex XSOAR.
Currently, we haven't worked on playbook automation. It is very difficult to work on the integration part when it comes to implementation. However, when we implement properly, we have a good enhancement. The biggest challenge when we implement is that we need to have properly certified experienced engineers to do that. Otherwise, it is very difficult to get it implemented. It is not easy to integrate with other tools. If we have experienced certified engineers, then it will be an easy task. Otherwise, if we don't have certified engineers, it is very difficult. We can't just pass it to the customers and say that they can get it done from their knowledge. We need to have the proper certified experienced engineers to get it done. It is both difficult to implement, deploy, and integrate the product. When we position Palo Alto Networks Cortex XSOAR, we are targeting the ISP level and high enterprise customers who can afford that solution. The price will be high, but the solution is absolutely superb. Therefore, we are highly focusing on those kinds of products for the ISP side and high-level enterprise customers. Still, we are not doing those kinds of things regarding machine learning models in Palo Alto Networks Cortex XSOAR. The biggest challenge we are facing is the pricing factor and the implementation. We need to have the proper engineers for the implementation and the pricing factor. Otherwise, we are not experiencing any kind of issues. We prefer if we could get to do configurations and push them throughout the cloud for remote sessions. For remote locations, if we could push configurations and everything through the cloud, that would be great.
I did notice some drawbacks, as it is a bit complex. The deployment and implementation are complex in nature. Integration with third-party tools had some issues, particularly with open source platforms, but enterprise tools integrated just fine. The exact platform we integrated required custom solutions, especially with open-source tools.
I believe ease of use would be an improvement for Palo Alto Networks Cortex XSOAR, as I see this as a valuable feature for future iterations. For queries, I believe improvement in that area could enhance Palo Alto Networks Cortex XSOAR further.
Palo Alto Networks Cortex XSOAR can be improved if it can include AI modules within Palo Alto Networks Cortex XSOAR as a product or at least as a summarizing feature. If that is there, I think it would make it easier for analysts to go through the alert. Another area I can suggest is the searching or reporting feature where you have to write a query, which is definitely good for searching your incidents. However, if you have long queries and if you want to take out reports, that is when the real challenge comes in. Probably an advanced search within Palo Alto Networks Cortex XSOAR incidents tab could address this.
Regarding areas for improvement in Palo Alto Networks Cortex XSOAR, I want to highlight one concern about playbook creation. While I personally appreciate this approach, I have observed that junior analysts on my team find it difficult to build playbooks. If Palo Alto Networks could improve the ease of use, specifically for playbook creation, that would be beneficial, as this is a gap I have identified. When I create a playbook for spyware or malware, I need to develop level one, level two, and sometimes level three sub-playbooks. Fetching data in the input and output fields is sometimes challenging. I have observed that junior analysts find this particularly challenging, so I believe it would be valuable to simplify the process of creating and configuring input fields and sub-playbooks.
I think Palo Alto Networks Cortex XSOAR can be improved as it has a little bit higher cost than any other SOAR. I think Palo Alto needs to reconsider the pricing for Palo Alto Networks Cortex XSOAR.
To improve the solution, it needs to have complete features that are low-code, no-code, and should be plug-and-play. We need to see improvements in that area to facilitate cyber analysts.
For Palo Alto Networks Cortex XSOAR, there is always room for improvement. One of the significant issues we encounter is system slowdown when we receive an influx of alerts, which inhibits how quickly we can access the information needed for investigation.
The complexity of Cortex XSOAR has a trade-off with its versatility. The product can be tailored for each deployment to respond to specific customer needs, and this complexity may be seen as a downside. The deployment requires integration and the development of integration modules. Deployment is not easy, requiring significant tuning and building of integrations over weeks.
The price of the solution could be lower. Companies utilizing this solution should have a well-developed cybersecurity team to maximize its benefits. It is more suited for large organizations rather than small or medium-sized companies.
Creating complex playbooks using coding languages, such as Python, could be easier. Sometimes the process becomes tedious and requires manual tasks.
Recently, they started implementing microservices in XSOAR, which has improved quality and addressed previous issues. However, they should focus more on licensing costs. The user licensing fees are quite high. For example, I received a quote for XSOAR, and it was $12,000 per user per year. If you have a SOC team of 30 members/analysts, you're looking at a substantial expense. They should consider reducing these costs since this high pricing seems to be more about profit. So, there is room for improvement in the pricing. Moreover, the reporting and dashboard features are decent but could be improved. The user interface (UI) is quite heavy and takes time to load, which is a major drawback.
The solution is complicated to learn. Customers find it difficult to learn how the solution works. We need professionals to learn and understand how the tool works to expand it further. Our customers want to see more use cases. They want to have more facilitations and more visibility on how it works. We need more skilled people inside and outside the team to understand how it works. It’s difficult to find skilled people to understand how the tool works.
Palo Alto needs to develop more AI-centric products. Also, the price could be cheaper. It doesn’t have infinite connectors.
There is room for improvement in support. The response time could be faster.
The tool’s multi-tenancy feature must be improved. The user interface must be made a little bit easier.
One limitation I have noticed with Cortex XSOAR is that it doesn't offer automatic threat intel reports out of the box. However, you can achieve this through coding, and we have managed to do it in our own environment using scripts and playbooks. It is not a built-in feature, but it is possible with some coding skills. The good news is that Palo Alto Networks plans to make this process more automated in the future, but it is not available yet.
The dashboard could be better.
The price of the solution could be improved.
The solution's features for reporting and dashboards need improvement. They need more customization options.
The solution should be made a bit cheaper.
The solution's integration with non-security solutions will be helpful.
The dashboard performance could be improved. Another area of improvement is a support team. Moreover, we need to pay for modifying anything with scripting in terms of customization. It can be a challenge if the person isn't 100% good with scripting.
Customization and performance can be improved. For example, some formats were incompatible when integrating, and they said we needed to work with the vendor to fix this issue because some logs that AVA logs were not compatible, and it did not readily recognize the format. Most of the time, I heard this as feedback. The formats are not compatible, are readily not available, and are not readable. Then we had to work it and write it manually.
Integrations with other applications are challenging and need to be improved. Reports or issues are often duplicated. The solution requires DV but does not support open-source DV elastic searches.
I would like to see Cortex become less dependent on Active Directory and group policies to manage the deployment. Maybe I need to update my understanding of how to deploy it, but that's the way I know how to use it. That makes it somewhat challenging to deploy Cortex where not every client is part of the directory. I've also had some problems with the update process, and it's failed two or three times.
I think they should increase their collaboration base so that XSOAR can be utilized for any number of automation.
Nothing needs to be changed. It is a part of Cortex inside Palo Alto Networks. If you want to get all the benefits, you will need the Cortex XDR, then you will need to get Cortex XSOAR. It's like a brother and sister, and they will give you a lot of benefits if you integrate them. It's only one cloud right now. It might be helpful for some companies to have an on-premies option.
It doesn't have any integrations. It lacks multiple integrations. It is been decommissioned by Palo Alto. There's no more trying to support it. There will be no more additional items added. The initial setup was complex.
The stability could be better. The integration could be better. Cortex, for example, does not work with iPhone.
Palo Alto Networks Cortex XSOAR could improve the look, feel, and management of the cloud console. Additionally, the user could be more easily integrated.
Corex XSOAR could be improved by reducing the time it takes to process large amounts of data and increasing the number of integrations. In the next release, Palo Alto should include popup features - for example, if someone is working on an incident, it should pop up and display in front of me once it's clicked.
In terms of improvement, it needs to be more modular. It's not. When you're working in layouts and you create specific apps within layouts, there's no portability right now in order to reuse that code across multiple layouts. I can't take a tab and say I want to use this tab on these other layouts. I have to physically go in there and recreate it from scratch, which is maddening. From an analyst perspective, it's not that hard to use. From a developer, it takes a little while in order to get to understand exactly how one would go about creating a playbook. The automation part is not that hard. It's relatively easy. It's just creating the flowchart.
I would love to see more flexibility on what we can display and design on the dashboards.
The solution is very expensive. They would get more clients if it wasn't so pricey.
There should be an on-premise version available for customers to have different choices.
We'd like to be able to add as many integrations as possible. We would like more options for our clients. A few times, I have noticed some bugs. That may be due to the fact that they are consistently upgrading the product. With new releases, a few bugs might get through. The solution is expensive. They should work to make it less costly for the customer.
Although we haven't used the solution for too long, we haven't come across any issues and haven't noticed any features that are lacking. We're largely satisfied with the offering. The user interface could be a bit better. It's the only aspect I've noticed that could possibly be improved. Other than that, we've been pretty happy with it.
For building automation, there is not a lot of good documentation. The documentation is there, but it is not very good from my perspective. There should be an improvement in this area. I don't see issues with anything else. In terms of new features, I have heard that other products have EBA functionality. It would be good if this functionality could be added.
Implementing this solution requires a lot of involvement from the vendor and it should be made easier for the partners. It has to be richer with respect to IoT. I expect that in future versions, support for a variety of devices will be added.