---
title: Palo Alto Cortex XSIAM Reviews
meta_title: 'Palo Alto Cortex XSIAM Reviews 2026: Details, Pricing, & Features | G2'
meta_description: Filter 96 reviews by the users' company size, role or industry to
  find out how Palo Alto Cortex XSIAM works for a business like yours.
aggregate_rating:
  rating_value: 4.5
  review_count: 96
  scale: '5'
date_modified: '2026-07-30'
parent_category:
  name: System Security
  url: https://www.g2.com/categories/system-security
---

# Palo Alto Cortex XSIAM Reviews
**Vendor:** Palo Alto Networks  
**Category:** [Security Information and Event Management (SIEM) Software](https://www.g2.com/categories/security-information-and-event-management-siem)  
**Average Rating:** 4.5/5.0  
**Total Reviews:** 96
## About Palo Alto Cortex XSIAM
Product Description: Palo Alto Networks&#39; Cortex XSIAM is an AI-driven security operations platform designed to transform traditional Security Operations Centers by integrating and automating key functions such as data centralization, threat detection, and incident response. By leveraging machine learning and automation, it enables organizations to detect and respond to threats more efficiently, reducing manual workloads and improving overall security posture. Key Features and Functionality: - Data Centralization: Aggregates data from various sources into a unified platform, providing comprehensive visibility across the enterprise. - AI-Powered Threat Detection: Utilizes machine learning algorithms to identify anomalies and potential threats in real-time. - Automated Incident Response: Streamlines response processes through automation, enabling rapid mitigation of security incidents. - Integrated SOC Capabilities: Combines functions such as Extended Detection and Response , Security Orchestration, Automation, and Response , Attack Surface Management , and Security Information and Event Management into a cohesive platform, eliminating the need for multiple disparate tools. - Scalability: Designed to handle large volumes of data and adapt to the evolving needs of modern enterprises. Primary Value and Problem Solved: Cortex XSIAM addresses the challenges of disjointed data, weak threat defense, and heavy reliance on manual work in traditional SOCs. By centralizing data and automating security operations, it simplifies processes, enhances threat detection accuracy, and accelerates incident response times. This transformation enables organizations to proactively outpace threats, reduce operational costs, and achieve a more robust security posture.



## Palo Alto Cortex XSIAM Pros & Cons
**What users like:**

- Users highlight **best-in-class log management** and effective alerting features, enhancing the overall usability and integration. (13 reviews)
- Users appreciate the **user-friendly dashboards** of Palo Alto Cortex XSIAM, highlighting ease of understanding alerts and metrics. (11 reviews)
- Users value the **real-time monitoring** capabilities of Palo Alto Cortex XSIAM, enhancing threat detection and response efficiency. (11 reviews)
- Users appreciate the **user-friendly interface** of Palo Alto Cortex XSIAM, making monitoring and deployment seamless and efficient. (11 reviews)
- Users appreciate the **good dashboard customization** in Palo Alto Cortex XSIAM, citing ease of use and integration. (9 reviews)
- Incident Management (9 reviews)
- Protection (8 reviews)
- Configuration Ease (7 reviews)
- Incident Response (7 reviews)
- Innovation (7 reviews)

**What users dislike:**

- Users find the solution **resource intensive** , increasing costs and complicating implementation due to high hardware requirements. (9 reviews)
- Users find the **complex implementation** of Palo Alto Cortex XSIAM time-consuming and resource-intensive, requiring significant technical expertise. (8 reviews)
- Users find the **cost** of Palo Alto Cortex XSIAM to be higher than competitors, impacting affordability for smaller companies. (7 reviews)
- Users report **dashboard issues** that hinder monitoring and create a messy interface, impacting usability and visibility. (7 reviews)
- Users struggle with the **difficult setup** of Palo Alto Cortex XSIAM, finding it complex and time-consuming for implementation. (7 reviews)
- Not User-Friendly (7 reviews)
- Poor Interface Design (7 reviews)
- Poor Reporting (7 reviews)
- Time-Consuming (7 reviews)
- Training Required (7 reviews)

## Palo Alto Cortex XSIAM Reviews
  ### 1. One phishing incident could have buried our team but cortex XSIAM connected the whole story.

**Rating:** 5.0/5.0 stars

**Reviewed by:** Audrey W. | Security Operations Manager, Information Technology and Services, Small-Business (50 or fewer emp.)

**Reviewed Date:** July 28, 2026

**What do you like best about Palo Alto Cortex XSIAM?**

I like best how Cortex XSIAM settled into our daily routine at maskiagroup where i lead an 18 member security operations team using microsoft defender and AWS cloudtrail integrations. During one phishing investigation with nearly 9000 alerts matching activity was already linked together so we didn't waste time comparing logs from different tools. Live investigations stayed quick but very old searches can occasionally take a bit longer.

**What do you dislike about Palo Alto Cortex XSIAM?**

Honestly i didn't come across anything that genuinely bothered me. If i have to point out something i'd love to see more flexible pricing as the team grows because costs add up with additional users. Support has been dependable but on one critical ticket we had to wait a little longer than expected before getting a detailed update. Those are small things and improving them would make the overall experience even better.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

One phishing incident flooded our queue with related alerts. Cortex XSIAM's ai grouped them into a single investigation so we understood the full picture much faster instead of checking each alert separately. I also liked how the interface kept the timeline easy to follow which made handoffs between analysts on my 18 member team much smoother.

  ### 2. Palo Alto Cortex XSIAM: Centralized Security with Powerful AI Automation

**Rating:** 4.5/5.0 stars

**Reviewed by:** Tim H. | Marketing Manager, Environmental Services, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 28, 2026

**What do you like best about Palo Alto Cortex XSIAM?**

I like the effectiveness of Palo Alto Cortex in centralizing most of our security services and operations, where it combines XDR capabilities, SOAR, snd SIEM.
Cortex XSIAM has enabled AI powered automation, and this accelerates the investigation process and prioritizes the sensitive threats.
We acknowledge the reliability and efficiency of Cortex XSIAM dashboard, where it gives us detailed reports concerning all companies endpoints, identifies, and other security issues.
The software has robust security automations, which reduces the manual workloads for employees.
Cortex XSIAM is determined in automating most of the repetitive security tasks and this gives the analyst adequate time to deal with other issues.

**What do you dislike about Palo Alto Cortex XSIAM?**

The initial installation of Palo Alto Cortex demands accurate configuration and tuning to match companies needs, and this calls for experienced professionals.
Cortex XSIAM has high licensing costs, which discourages small businesses

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

Palo Alto Cortex has streamlined the challenge of managing multiple security alerts coming from many sources, and it helps eliminate duplication. The application has improved the productivity of our security analysts by reducing alert fatigue through accurate filtering. The process of detecting anomalies and threats is more streamlined and automated, which accelerates our response when we face attacks. We have also seamlessly consolidated security data from diverse endpoints, networks, and other third-party applications, which supports proactive security measures. Overall, the application identifies incidents before they create operational risk or harm, and this helps guide our investigation process.

  ### 3. Efficient Security Monitoring with Powerful Automation

**Rating:** 4.0/5.0 stars

**Reviewed by:** Anas M. | SOC Analyst , Information Technology and Services, Small-Business (50 or fewer emp.)

**Reviewed Date:** July 20, 2026

**What do you like best about Palo Alto Cortex XSIAM?**

I like the automation Palo Alto Cortex XSIAM provides; it cuts down a lot of the manual work involved in investigating alerts, saving a ton of time. I also like that everything is in one place, allowing me to avoid jumping between different tools to understand what's happening. The dashboards are clear, and the overall visibility into our environment is much better than what we had before. I appreciate that it pulls logs from different sources, correlates alerts automatically, and helps prioritize the ones that matter, which prevents chasing false positives. The automation saves our SOC team a lot of time, especially for repetitive investigation and response tasks, making threat detection and incident handling much more efficient. Having everything integrated into Cortex XSIAM makes correlating alerts from different sources easier and helps investigate incidents without constantly switching consoles. The integrations are smooth overall and help provide a much better view of what's happening across the environment.

**What do you dislike about Palo Alto Cortex XSIAM?**

I found the initial setup and configuration could be better, as it takes some time to get everything tuned properly, especially when integrating a lot of different data sources. We also experienced a bit of a learning curve due to the platform's numerous features, which can be challenging for new users.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

I use Palo Alto Cortex XSIAM to monitor security incidents in one place, saving time by automating repetitive tasks. It reduces alert fatigue and improves threat detection by correlating alerts and prioritizing important ones. The centralized visibility and automation make my security operations more efficient.

  ### 4. Dramatically Fewer Alerts and Faster Response in One Console

**Rating:** 4.5/5.0 stars

**Reviewed by:** Yogesh G. | Linux Administrator, Information Technology and Services, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 21, 2026

**What do you like best about Palo Alto Cortex XSIAM?**

Alert consolidation and noise reduction are major strengths. XSIAM ingests raw logs and telemetry and then automatically correlates them into a small number of “incidents,” rather than flooding the SOC with thousands of individual alerts. This is consistently described as the biggest win, with analysts reporting a dramatic drop in the daily alert volume they need to triage.

Speed to detection and response also stands out. Because it’s built around a unified data lake with built-in automation, mean time to detect and respond drops sharply compared with a traditional SIEM paired with separate SOAR and separate EDR tools.

Native integration across the Palo Alto stack is another draw. Firewall data, Cortex XDR endpoint telemetry, cloud logs, and third-party feeds land in a single data model, so correlation across network, endpoint, and cloud can happen without custom parsers—especially appealing for teams already running Palo Alto gear.

Built-in automation and out-of-the-box playbooks are frequently praised as well. Users like that common response actions are already pre-built, instead of being something the SOC has to author from scratch.

Finally, having a single console instead of a swivel-chair workflow is cited as a quality-of-life improvement. Not having to jump between separate SIEM, SOAR, EDR, and TIP UIs is repeatedly mentioned as a win for analysts.

**What do you dislike about Palo Alto Cortex XSIAM?**

Pricing (per-GB ingestion plus compute) gets expensive quickly, especially at scale, and it’s often described as one of the priciest options on the market.

Onboarding data sources and setting up correlation rules feels heavier than I expected for a “unified” platform. Tuning detections and playbooks, along with getting data onboarding right, takes real time and expertise before it starts to pay off.

The deep tie-in to the Palo Alto ecosystem also makes it harder to mix in other vendors’ tools, and it could make migrating away later more difficult.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

It consolidates thousands of raw logs and alerts into just a handful of correlated incidents, so analysts aren’t drowning in noise. It also correlates data across all three sources, helping catch multi-stage attacks that siloed tools can miss.

  ### 5. Powerful Correlation and Integrations, but Slow UI and Clunky IAM Setup

**Rating:** 3.5/5.0 stars

**Reviewed by:** Verified User in Hospital & Health Care | Enterprise (> 1000 emp.)

**Reviewed Date:** July 16, 2026

**What do you like best about Palo Alto Cortex XSIAM?**

XSIAM is very powerful and has allowed us to ingest data from multiple sources, with most of them coming from out-of-the-box integrations. For the few data sources where we had to build support, the help from Palo Alto has been great. The biggest benefit is the correlation engine; however, without Palo Alto professional services, we wouldn’t be using even a fraction of its capabilities.

**What do you dislike about Palo Alto Cortex XSIAM?**

Often when I’m running queries, the UI is very slow. I’ve started warning teammates that if you do this, it’s going to be click, wait, wait, wait. Another thing I don’t like is how some of the IAM works. You have to create an account in the Palo Alto support portal, then log in to XSIAM, create the account there as well, and assign roles and permissions. This is still required even with SSO integration.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

XSIAM is helping us solve two key issues. First, it’s allowing us to consolidate multiple technologies from different vendors into the Cortex ecosystem, and we’ve already been able to retire several tools as a result. Second, the level of automation in XSIAM is incredible, and it’s drastically reducing our response times.

  ### 6. Cortex XSIAM helps us cut through noise and focus on real threats

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Financial Services | Enterprise (> 1000 emp.)

**Reviewed Date:** July 16, 2026

**What do you like best about Palo Alto Cortex XSIAM?**

The Cortex XSIAM interface is clean and makes complex investigations easy to navigate, and the dashboards are highly customizable. Integrations are another advantage of this platform, especially when working across multiple data sets. Query execution is super fast, and the scalability is solid compared to other SIEM solutions I’ve worked with previously. It also goes without saying that consolidating SIEM + SOAR + AI analytics into one platform makes it more budget-friendly. Since we’re already Palo Alto customers, their onboarding support was impressive, as always. Their AI driven correlation is pretty impressive, especially while linking signals across hosts, users and applications.

**What do you dislike about Palo Alto Cortex XSIAM?**

Honestly, while Cortex XSIAM is powerful, getting used to the platform takes time and can feel overwhelming at times, especially for those who are new to the industry. The support and onboarding are good, but I felt that more hands-on workshops would have helped us adopt the platform faster. The AI correlation is impressive compared to the other technologies we’re currently using. However, it does surface false positives sometimes, which means we have to spend extra time tuning the models.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

Cortex XSIAM is helping us tackle the challenge of managing high volumes of security alerts by bringing everything into a single platform and automatically correlating signals. Its AI-driven analytics highlights incident context, which saves a lot of investigation time, helps us respond faster, and ultimately saves our analysts time.

  ### 7. Unified SIEM/XDR/SOAR Platform That Cuts Alert Noise and Speeds Investigations

**Rating:** 5.0/5.0 stars

**Reviewed by:** Sachit  S. | Associate – Cyber Incident Response, Enterprise (> 1000 emp.)

**Reviewed Date:** July 16, 2026

**What do you like best about Palo Alto Cortex XSIAM?**

What I like best about Palo Alto Cortex XSIAM is how it brings SIEM, XDR, SOAR, threat intelligence, and automation into a single platform. It uses AI to reduce alert noise, automatically prioritize incidents, and speed up investigations, allowing security teams to focus on real threats instead of repetitive manual tasks. I also like its strong automation capabilities and centralized visibility, which help improve SOC efficiency and reduce incident response time.

**What do you dislike about Palo Alto Cortex XSIAM?**

One drawback of Palo Alto Cortex XSIAM is that it has a steep learning curve, especially for new users. Its advanced features and extensive customization options can take time to understand. It can also be expensive for smaller organizations, and setting up complex automation workflows may require experienced security professionals. However, once implemented properly, the platform provides significant value through improved security operations and automation.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

Palo Alto Cortex XSIAM solves the problem of managing a large number of security alerts by using AI and automation to detect, prioritize, and respond to threats more efficiently. It combines multiple security tools into one platform, reducing manual work and improving visibility across the environment. This benefits me by making investigations faster, reducing alert fatigue, and helping me focus on real security incidents instead of routine tasks.

  ### 8. Streamlines Security Operations with Automation

**Rating:** 4.0/5.0 stars

**Reviewed by:** Ronald D. | Senior Business Development Specialist, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 06, 2026

**What do you like best about Palo Alto Cortex XSIAM?**

I like that Palo Alto Cortex XSIAM really helps with alert fatigue and slow incident response. It's great how it gives the security team the capability to handle thousands of alerts in one day instead of dealing with them multiple times. The use of AI and automation is also a big plus because it helps in prioritizing high-risk incidents and automating routine processes. This means my team can respond to incidents before they escalate into major security threats. The way it centralizes automations and reduces false positives is pretty handy, especially with improved alert formats that increase analyst activity. Also, the automation in compliance reporting is beneficial as it reduces the mean time to detect and respond, which leads to lower operational costs and improved cybersecurity. Additionally, setting it up was quite easy, and it integrates well with existing platforms without needing third-party tools or cumbersome manuals.

**What do you dislike about Palo Alto Cortex XSIAM?**

The automation part in Palo Alto Cortex XSIAM could be improved. Some people need to learn how to do it, and security teams are spending a lot of time investigating thousands of alerts. The volume of alerts and connecting with the security tools has critically increased the response time.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

Palo Alto Cortex XSIAM reduces time spent on log collection and investigation, consolidates security data, automates alert management, and enhances compliance reporting. It lowers operational costs and improves response time by identifying and prioritizing high-risk incidents automatically.

  ### 9. Strong incident correlation, but commit fully or don't bother

**Rating:** 3.5/5.0 stars

**Reviewed by:** Alessandro D. | Technical Leader, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 16, 2026

**What do you like best about Palo Alto Cortex XSIAM?**

Incident clustering cuts alert fatigue fast. The ML groups related alerts into a single case instead of 15 separate pings, which makes a big difference during H24 on-call shifts.

**What do you dislike about Palo Alto Cortex XSIAM?**

XQL has a steep learning curve for analysts coming from KQL or YARA-L, and onboarding took longer than I expected. The licensing cost is high, and the ROI weakens quickly if you don’t fully commit to the Cortex ecosystem.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

It helps solve alert fatigue and fragmented tooling. Instead of stitching together separate SIEM, EDR, and SOAR consoles during 24/7 on-call coverage, the ML-driven clustering groups related alerts into a single incident. That reduces noise and cuts triage time, so my team has less to sift through on every shift.

  ### 10. Cortex XSIAM Turns Massive Alert Noise into High-Confidence Signals

**Rating:** 5.0/5.0 stars

**Reviewed by:** sikunju I. | Desktop Support Engineer, Enterprise (> 1000 emp.)

**Reviewed Date:** July 20, 2026

**What do you like best about Palo Alto Cortex XSIAM?**

The best part about Palo Alto Cortex XSIAM is how it works with huge amounts of data to streamline activity. I was genuinely shocked by how effectively it groups millions of noisy, fragmented alerts into a small handful of high-confidence alerts.

**What do you dislike about Palo Alto Cortex XSIAM?**

The platform seems designed to work mainly within its own ecosystem, such as Cortex XDR and Palo Alto Firewalls. If it could extend beyond this proximity and be made to function smoothly with third-party firewalls and other tools, it would be more functional and useful for the vendor.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

This helps me analyze thousands of disconnected, low-fidelity alerts. However, it also slows incident response, and it leaves out critical logs to save money.

  ### 11. Revolutionizes Security Operations but Challenging Data Onboarding

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User | Enterprise (> 1000 emp.)

**Reviewed Date:** July 21, 2026

**What do you like best about Palo Alto Cortex XSIAM?**

I like Palo Alto Cortex XSIAM's ability to unify data, automation, and analytics, wrapping all these into a single platform. It's great at solving major security operations challenges like eliminating alert fatigue and tool fragmentation. I also appreciate how it brings data, analytics, and automation together to stop cyber threats faster, cutting down manual work and linking information across different security tools. It also spots hidden dangers early. The initial setup and tenant activation are quite efficient, taking about an hour via the gateway, and the full environment configuration is streamlined using migration tools.

**What do you dislike about Palo Alto Cortex XSIAM?**

I find the high costs and complex data onboarding with Palo Alto Cortex XSIAM challenging. The data onboarding is complex because of messy file formats, custom mapping requirements, and poor data quality. It would be helpful to have pre-built validation and cleansing tools to catch formatting errors instantly, and letting users map and fix their own data fields through an intuitive UI would improve the experience.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

I use Palo Alto Cortex XSIAM because it solves my security operation challenges by eliminating alert fatigue, addressing tool fragmentation, and speeding up response times. It centralizes my security operations, integrates data, analytics, and automation, reduces my manual workload, helps me spot hidden dangers early, and stops cyber threats faster.

  ### 12. Centralize Security Management but with High Costs

**Rating:** 3.5/5.0 stars

**Reviewed by:** Verified User | Mid-Market (51-1000 emp.)

**Reviewed Date:** July 16, 2026

**What do you like best about Palo Alto Cortex XSIAM?**

I like how Palo Alto Cortex XSIAM eliminates duplicates, which avoids having to do the work twice. I value the behavioral analysis, as it allows predicting potential attacks before a human detects them. Additionally, I appreciate that in the SOC where I work, we use Palo Alto Cortex XSIAM to manage all the tools in one place, which allows us to have all the logs from the EDR, XDR, SOAR, and SIEM in a single point without the need for multiple screens or duplicate logs.

**What do you dislike about Palo Alto Cortex XSIAM?**

Perhaps due to the high cost or the great dependence on Palo Alto ecosystems and the low compatibility with other ecosystems. Perhaps for the cost, a pricing based not so much on data volume but on usage or processing.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

I use Palo Alto Cortex XSIAM to manage all the tools in one place, unifying logs and eliminating duplicates. It allows us to predict attacks before a human detects them. We switched from Splunk to Palo Alto Cortex XSIAM for better data ingestion.

  ### 13. Powerful Log Consolidation with Great Threat Detection Accuracy and Precise Alerts

**Rating:** 5.0/5.0 stars

**Reviewed by:** Tim P. | Information Security Analyst, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 27, 2026

**What do you like best about Palo Alto Cortex XSIAM?**

It effectively consolidates log data from multiple sources in one place and offers a highly customizable dashboard that provides real-time visibility into our environment with the ability to send alerts on specific behaviors so we can respond swiftly to emerging threats.

**What do you dislike about Palo Alto Cortex XSIAM?**

The documentation of the tool can be more detailed but other than that it is powerful for analysis of incidents and I would recommend to others to use it.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

Very useful in analyzing logs and creating alarms for suspicious activities and the built-in threat intelligence feeds provide great visibility across our infrastructure which makes threat remediation easy and highly effective.

  ### 14. Palo Alto Cortex XSIAM Streamlines SOC Work with Smart Noise Reduction and Automation

**Rating:** 5.0/5.0 stars

**Reviewed by:** Rohan K. | Senior Azure devops engineer , Enterprise (> 1000 emp.)

**Reviewed Date:** April 14, 2026

**What do you like best about Palo Alto Cortex XSIAM?**

I’ve been using Palo Alto Cortex XSIAM for a while now, and honestly it has made a big difference in how we handle security operations. The platform brings everything into one place, so I don’t have to jump between multiple tools anymore. What I like the most is how well it reduces alert noise and highlights only the important threats, which saves a lot of time. The automation is very helpful too—it speeds up investigation and response without much manual effort. Overall, it feels reliable, efficient, and makes daily SOC work much smoother.

**What do you dislike about Palo Alto Cortex XSIAM?**

While I’ve had a positive experience overall with Palo Alto Cortex XSIAM, there are a few areas that could be improved. The platform can feel a bit complex at first, especially during the initial setup and onboarding phase, which may require time and proper training to fully understand all its capabilities. Additionally, customization and fine-tuning certain workflows can sometimes be less intuitive than expected. In some cases, the resource usage and cost considerations can also be a concern for smaller teams. That said, once you get past the learning curve, it becomes much more manageable and effective in daily operations.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

Using Palo Alto Cortex XSIAM has really helped solve the challenge of handling too many alerts and disconnected security tools in our environment. Earlier, it was difficult to correlate data and prioritize real threats, which slowed down our response time. With XSIAM, everything is centralized and powered by AI, so it automatically filters noise and highlights the most critical issues. This has significantly improved our efficiency, reduced manual effort, and allowed us to respond to incidents much faster. Overall, it has made our security operations more streamlined, proactive, and much easier to manage.

  ### 15. Delivers Quick Visibility into Anomalies and Easy to Tune Alerts with Impressive Granularity

**Rating:** 5.0/5.0 stars

**Reviewed by:** Christopher G. | SOC Analyst, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 27, 2026

**What do you like best about Palo Alto Cortex XSIAM?**

The strong capabilities in log correlation and threat detection provides deep visibility into network activity and security events and it sends real time alerts in form of alarms enabling us to respond to security issues right away.

**What do you dislike about Palo Alto Cortex XSIAM?**

There are no major challenges experienced since the initial setup and they have a very reliable support so the platform is great for collecting, analyzing and reporting log information.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

The platform allows us to pull in data from a wide range of sources for comprehensive security analysis which makes investigation faster, threat detections more accurate and overall situational awareness significantly stronger.

  ### 16. Powerful Integration, High Learning Curve

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User | Enterprise (> 1000 emp.)

**Reviewed Date:** July 22, 2026

**What do you like best about Palo Alto Cortex XSIAM?**

I really like Palo Alto Cortex XSIAM's simplicity and its very humanistic approach to solving problems, even ones that seem complex at first. Its features work together seamlessly as an integrated security operating platform, which eliminates the need to switch between separate tools like endpoint detection, log analysis, threat intelligence, instant investigation, and response. This integration brings the data and workflows into a single environment, making it easier to connect related activities.

**What do you dislike about Palo Alto Cortex XSIAM?**

If I had to point out something, I'd say there's quite a large learning curve. Because it combines SIEM and SOAR and point security automation and threat intelligence into a single platform, it can be quite a daunting task to learn.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

I find Palo Alto Cortex XSIAM solves my daily transaction issues, integrating multiple tools into a single environment, which simplifies complex tasks for me.

  ### 17. Centralized Event Correlation That Strengthens Threat Monitoring and Anomalies Detection

**Rating:** 5.0/5.0 stars

**Reviewed by:** Thomas M. | Senior System Engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 24, 2026

**What do you like best about Palo Alto Cortex XSIAM?**

It provides strong threat detection and better visibility across security events with automated incident investigation making it a reliable solution for security monitoring that helps prevent anomalous behavior in our systems.

**What do you dislike about Palo Alto Cortex XSIAM?**

Nothing much to dislike so far as it has been a very reliable SIEM solution although personally I would improve the graphical interface it is good but in my opinion improvable.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

It offers good visibility across many log sources, including endpoints, network devices, firewalls and servers which helps with better investigation of events which has led to effective threat prioritization for faster incident response.

  ### 18. Automatically Connects All Log Events for Clearer Incident Visibility and Threat Handling

**Rating:** 5.0/5.0 stars

**Reviewed by:** Aaron G. | Cyber Security Engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 26, 2026

**What do you like best about Palo Alto Cortex XSIAM?**

It automatically stitches together disparate log events into a coherent incident view providing deeper visibility into anomalous user behavior and helps identify complex attack patterns.

**What do you dislike about Palo Alto Cortex XSIAM?**

The system supports a wide array of log sources so it requires intensive resources to maintain and tuning the rules to reduce false positives requires significant expertise.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

The tool keeps us updated and alerted of the security events and logs generated by the routers, firewalls and servers within our infrastructure enabling us to detect any kind of suspicious activity and take actions to quarantine and block anomalies.

  ### 19. Expansive Threat Visibility and Smart Log Correlation That Streamlines Incident Investigation

**Rating:** 5.0/5.0 stars

**Reviewed by:** Lauren R. | System Administrator, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 22, 2026

**What do you like best about Palo Alto Cortex XSIAM?**

The platform provides an expansive view of the network, endpoint and application layers automatically grouping related security events and the correlation engine helps catch suspicious activity from different log sources in one place which helps streamline the investigation process.

**What do you dislike about Palo Alto Cortex XSIAM?**

I find the platform very powerful without any major issues and from an analysis perspective it is very reliable for analysis across our event log collation.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

The platform facilitates access to the information needed during an incident investigation and offers good visibility into the environment’s activity which helps improve detection and response processes.

  ### 20. Efficient in High Volume Log Monitoring for Quick Investigation of Security Events

**Rating:** 5.0/5.0 stars

**Reviewed by:** Antonio F. | System Engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 27, 2026

**What do you like best about Palo Alto Cortex XSIAM?**

It has proven to be a highly effective tool for deep forensic investigation of vulnerabilities with precision and it performs well handling high log event volumes efficiently which helps in monitoring end users activity very closely.

**What do you dislike about Palo Alto Cortex XSIAM?**

We have used the tool for more than 2 years now and we are absolutely satisfied with it and it offers greater value than its competitors on the market.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

Very reliable monitoring tool that is helping correlate logs from any source to identify security threats and simplifies the process of preventing malicious activity.

  ### 21. Robust Correlation Capability of Multiple Log Sources to Effectively Improve Threat Visibility

**Rating:** 5.0/5.0 stars

**Reviewed by:** Ricardo O. | SOC Analyst, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 24, 2026

**What do you like best about Palo Alto Cortex XSIAM?**

It offers robust real-time dashboards with forensic monitoring of cyber related threats, incidents and log analysis which has greatly improved our ability to detect and respond to threats.

**What do you dislike about Palo Alto Cortex XSIAM?**

I have been using this platform for more than 2 years and found it to be more user friendly than any other SIEM in the present market and I have not faced any issues whatsoever.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

The comprehensive visibility into logs, incidents and events offers robust insights across our environment which enables us to effectively reduce false positives and prevent potential security incidents.

  ### 22. Powerful and Scalable Tool for Centralized Log Analysis and Accurate Incident Reporting

**Rating:** 5.0/5.0 stars

**Reviewed by:** Nadeem P. | Network Security Engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 24, 2026

**What do you like best about Palo Alto Cortex XSIAM?**

Solid tool for daily network monitoring and handling of security incidents with ease and I like that it is highly scalable when dealing with an increase in received events.

**What do you dislike about Palo Alto Cortex XSIAM?**

I haven’t encountered any problems using this tool it is very powerful for centralizing and analyzing logs and very flexible on the incident reporting.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

It has been a solid platform for monitoring security events, correlating logs, and responding to incidents which significantly improves our SOC efficiency.

  ### 23. Highly Usable for Boosting Brand Marketing with Graphic Design & Posters

**Rating:** 5.0/5.0 stars

**Reviewed by:** Eric O. | Partner, Enterprise (> 1000 emp.)

**Reviewed Date:** July 15, 2026

**What do you like best about Palo Alto Cortex XSIAM?**

Helping improving digital work on brands and very usable software for business upgrading and improving marketing strategies with graphic design and posters

**What do you dislike about Palo Alto Cortex XSIAM?**

The downside is not actually noted due to the new using system of the software for upgrading your website or building a startup business helping fascination

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

Customer reach and global leading cortex helping to improve business strategies for customers or client to get attractiveness to the type of business you have

  ### 24. Advanced AI, Correlation, and SOAR for Deep, Rich Incident Analysis

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Computer & Network Security | Mid-Market (51-1000 emp.)

**Reviewed Date:** July 16, 2026

**What do you like best about Palo Alto Cortex XSIAM?**

Palo Alto Cortex XSIAM have the advance features like co-relation, AI and SOAR. With the help of AI you can analyse the incidents on more deep dive. Analysis of the incident is also rich and approriate.

**What do you dislike about Palo Alto Cortex XSIAM?**

The playbooks of the XSIAM need some more enhancement. It is more complex for the people who is new to Palo Alto Cortex. There should be more default playbooks available to use.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

It is giving us more visibility into the network and whats going on in our network. Incase there is any anomaly or any attacks we will be able to identify and mitigate on the timely basis to avoid any business impact.

  ### 25. Data Automation, and AI Analytics for Faster Incident Response

**Rating:** 4.5/5.0 stars

**Reviewed by:** Ahmad O. | Security Design and Estimation Engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** April 23, 2026

**What do you like best about Palo Alto Cortex XSIAM?**

What stands out most about Palo Alto Cortex XSIAM is its ability to unify data, automation, and AI-driven analytics into a single platform. It significantly reduces manual effort by automating threat detection and response, while providing deep visibility across the entire security environment. This leads to faster incident resolution and stronger overall security posture.

**What do you dislike about Palo Alto Cortex XSIAM?**

complexity, especially during initial deployment and tuning. It often requires skilled resources to configure properly, and the learning curve can be steep for new users. Additionally, the cost can be high compared to other solutions, which may not be ideal for smaller organizations.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

It solves problems like too many security alerts, disconnected tools, and slow incident response.

  ### 26. Great unified console, but too expensive compared to alternatives

**Rating:** 2.5/5.0 stars

**Reviewed by:** sagar p. | AVP, Enterprise (> 1000 emp.)

**Reviewed Date:** February 23, 2026

**What do you like best about Palo Alto Cortex XSIAM?**

One single console for all the solution for endpoints , network and cloud data.
Count of false positive is reduced with help of system learning
Integration is very easy with other tools

**What do you dislike about Palo Alto Cortex XSIAM?**

Very expensive as compared to other solution
Console is very complex and takes time to understand
There are to many various options due to which complexity is increased
Support is a major concern

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

Protection agents real time threats which is much more beneficial than other vendors

  ### 27. A strong security platform for Advanced Automation

**Rating:** 4.5/5.0 stars

**Reviewed by:** Rakshitha T. | Technical engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** March 12, 2026

**What do you like best about Palo Alto Cortex XSIAM?**

What I like is how it combines multiple security tools into one platform and automates threat detection and response which saves a lot of time for security teams.

**What do you dislike about Palo Alto Cortex XSIAM?**

The main downside is its high cost and complexity.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

It solves the problem of siloed security tools and large volumes of alerts.

  ### 28. IBM Qradar review

**Rating:** 5.0/5.0 stars

**Reviewed by:** Sameer K. | Vice President Cyber Security &amp; Infrastructure Risk, Enterprise (> 1000 emp.)

**Reviewed Date:** September 14, 2024

**What do you like best about Palo Alto Cortex XSIAM?**

It helps into deep packet inspection to identify threat as well correlate the data for analysis and threat hunting.

**What do you dislike about Palo Alto Cortex XSIAM?**

Cannot handle large data sets requires and ELK for data injections, memory intensive which increases the chances of instability, the latest version doesn't have a gpt kind of functions which helps adminstrator run simple query to get output as not every one can learn the query language

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

Qradar help provide a good siem function which strengthen our society team in deep packet analysis to identify threats and help mitigate via incident response.

  ### 29. Grandpa QRadar

**Rating:** 3.0/5.0 stars

**Reviewed by:** Flore v. | Mid-Market (51-1000 emp.)

**Reviewed Date:** April 11, 2024

**What do you like best about Palo Alto Cortex XSIAM?**

I like building use cases in QRadar. The logic is easy to understand, parsing has several options and a lot is possible to make custom use cases.

**What do you dislike about Palo Alto Cortex XSIAM?**

It's so slow (hence Grandpa QRadar). If you ask it to move too fast it will fall down. Adjusting use cases, especially multiple in a row, is so slow that I can read a book in the meantime. It makes me work slower.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

Integrating a multitude of log sources from several customers and making custom use cases on that. It's nice that QRadar integrates different log sources and I can parse custom fields and make reference sets to improve/make use cases.

  ### 30. Qradar: Best SIEM tool for Monitoring Endpoints & Cloud

**Rating:** 5.0/5.0 stars

**Reviewed by:** Rohan G. | Mid-Market (51-1000 emp.)

**Reviewed Date:** July 06, 2023

**What do you like best about Palo Alto Cortex XSIAM?**

Basically Qradar is a SIEM Tool which is made by IBM, by using Qradar we can monitor our endpoints as well as cloud.

Alerts from Endpoints will come under Events and activity related to networking will come under Flows.

If it find any suspicious activity then it will create Offense.

So if i want to investigate any incident for that you can go to offense it contains rich information.

So you can also integrate Qradar with Qradar SIEM for Automation purpose.

**What do you dislike about Palo Alto Cortex XSIAM?**

So if you are new to Qradar SIEM, first you need to understand the general architecture of Qradar then all features of Qradar.

Although it gives us variety of features Qradar is more costly than any other tool.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

So if your organisation needs a SIEM helps us monitor endpoints, network analysis and Cloud Monitoring then one can Qradar SIEM tool using this tool we can monitor our whole infrastructure.

  ### 31. A practical experience

**Rating:** 5.0/5.0 stars

**Reviewed by:** Renata C. | Mid-Market (51-1000 emp.)

**Reviewed Date:** November 30, 2023

**What do you like best about Palo Alto Cortex XSIAM?**

I like the reliability of the tool and although a SIEM is not a simple tool to handle, IBM Qradar is quite intuitive.

**What do you dislike about Palo Alto Cortex XSIAM?**

The tool could be more customizable (offense screen, for example) and the reports could have a more user-friendly appearance.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

Attend to multiple clients and bring vision to the events

  ### 32. QRadar Needs Improvement

**Rating:** 3.0/5.0 stars

**Reviewed by:** Verified User in Financial Services | Mid-Market (51-1000 emp.)

**Reviewed Date:** August 18, 2023

**What do you like best about Palo Alto Cortex XSIAM?**

Central log management is very effective, but the assimilation of the data and ability to make the data actionable is somewhat lacking as alerting and actual monitoring does not have all of the features and customizations required to be an actual SIEM.

**What do you dislike about Palo Alto Cortex XSIAM?**

Central log management is very effective, but the assimilation of the data and ability to make the data actionable is somewhat lacking as alerting and actual monitoring does not have all of the features and customizations required to be an actual SIEM.  Better alerting and monitoring with the ability to customize reporting and alerting specifically tailored to an organization is not implicitly available with QRadar.  The user interface is somewhat clunky and needs to have better enhancements to compete with other SIEM solutions.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

Centralized log management for monitoring and alerting. While QRadar when it was independent prior to the acquisition by IBM was ahead of its competitors, it seems that the enhancements and features that were supposed to be implemented and developed got lost in the acquisition.  Rather than logs displaced in multiple data stores, QRadar does a great job of centrally maintaining all of the logs.

  ### 33. Good Cybersecurity Tool

**Rating:** 4.5/5.0 stars

**Reviewed by:** Rahul P. | Consultant, Enterprise (> 1000 emp.)

**Reviewed Date:** August 17, 2023

**What do you like best about Palo Alto Cortex XSIAM?**

Once configured with appropriate rules and configuration as per our requirement then QRadar is one of the best tool which will give each and evry important information/incident/report from your whole environment.

**What do you dislike about Palo Alto Cortex XSIAM?**

I don't find much problem in QRadar, its one of the popular tool in SIEM technology. But if you have not configured it properly then it would give many false possitive which will make your life dificult.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

QRadar gives appropriate alerts and reports to monitor complete environment which will make Cybersecurity person life easy. You will get all view of information moving accross complete networks of all the applications along with the actions who/why/whom etc.

  ### 34. Good SIEM Soltuion with Great features and it keeps on updating.

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Financial Services | Enterprise (> 1000 emp.)

**Reviewed Date:** May 13, 2023

**What do you like best about Palo Alto Cortex XSIAM?**

QRadar is one of the best SIEM solution I have ever worked. First of all, The deployment of the solution is quite easy compared with other SIEM solutions. Integration of Flows in addition the events makes it unique from other SIEM solutions. Integration of log sources with the QRadar is really easy and the current versions have DSM editor feature, which makes us easy to write custom parser. Processing capabilities in QRadar really strong, CRE works without any issues. We can also integrate several third party apps which is also an addition advantage. The conventional dashboards are not attractive however, new Pusle Dashboard gives a great visibility. Also, the conventional user interface is nor really attractive, but there is an app called analyst workflow, with that it is also sorted. One important drawback of this product is the vendor support, some technicians doesn't actually check the issue in detail and ask us to upgrade the product simply and response time is also not that good."

**What do you dislike about Palo Alto Cortex XSIAM?**

Vendor support is bad, Often for issues, they ask us to upgrade the device without checking for actual solutions.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

Threat Detection and Monitoring: QRadar SIEM collects and analyzes vast amounts of security event data from various sources, such as network devices, servers, applications, and endpoints. It uses advanced analytics and correlation techniques to identify security incidents and potential threats in real-time. By detecting and alerting on malicious activities promptly, it enables organizations to respond swiftly and prevent potential damage.

  ### 35. A powerful siem solution

**Rating:** 5.0/5.0 stars

**Reviewed by:** Gemini  D. | Mid-Market (51-1000 emp.)

**Reviewed Date:** August 01, 2023

**What do you like best about Palo Alto Cortex XSIAM?**

IBM security qradar siem has great features like log ingestion.
Advanced threat detection capabilities.
Analytics monitor threat Intel, network and user behavior anomalies to prioritize where immediate attention and remediation is needed.

**What do you dislike about Palo Alto Cortex XSIAM?**

It could be a problem with my side but the platform becomes slow to respond when working on huge amounts of data.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

IBM security qradar siem provides real time visibility into our IT infrastructure which helps in threat detection and prioritization.

  ### 36. IBM Security QRadar SIEM:  Good Dashboard and presets

**Rating:** 3.5/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Enterprise (> 1000 emp.)

**Reviewed Date:** November 30, 2023

**What do you like best about Palo Alto Cortex XSIAM?**

The  Dashboard and presets were the best prebuilt factor of this software.   We did a lot of threat hunting and using the NDR.

**What do you dislike about Palo Alto Cortex XSIAM?**

Need Cloud which is coming soon.  Needs a SaSS product feature instead of just classic.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

Visiblity into Network traffic and logging.

  ### 37. Excellent tool and user friendly

**Rating:** 4.5/5.0 stars

**Reviewed by:** PRASHANT KUMAR P. | Senior cybersecurity analyst, Enterprise (> 1000 emp.)

**Reviewed Date:** May 17, 2023

**What do you like best about Palo Alto Cortex XSIAM?**

Log ingestion and querying is the best feature in qardar. It has best user interface and anyone can make the query easily. Best tool keep your environment secure.

**What do you dislike about Palo Alto Cortex XSIAM?**

sometimes it is slow, when you ingest large amount of data or run a queury for longer time. they can increase the memory. support can be improved otherwise a best siem tool available in the market.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

It's helping to keep our environment secure. Analyst can do their analysis in details and can mitigate the issue based on the logs. IR and threat can be done on qradar.

  ### 38. QRadar Review

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Small-Business (50 or fewer emp.)

**Reviewed Date:** May 22, 2023

**What do you like best about Palo Alto Cortex XSIAM?**

The Rules building system now using QRadar Case Manager app is very useful!

**What do you dislike about Palo Alto Cortex XSIAM?**

The old GUI view and the heavy code that need heavy hardware.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

The data segregation for MSSP like rules, searches etc...

  ### 39. Qradar Siem is user friendly gui, and avail with multiple application.

**Rating:** 5.0/5.0 stars

**Reviewed by:** Gautam K. | Cyber Security Engineer (Soc Admin) , Enterprise (> 1000 emp.)

**Reviewed Date:** April 03, 2022

**What do you like best about Palo Alto Cortex XSIAM?**

The application and monitoring tools also ucm is best for tool creation.pulse and use case manager is the best feature which ever i like in qradar, dashaboard is the tab which we can see all important things over here.

**What do you dislike about Palo Alto Cortex XSIAM?**

In qradar the building block,use case manager and Rule crieation is quite difficult for understanding, currently i am facing isse with threat Intelligence app, in that the download tab is note working properly.

**Recommendations to others considering Palo Alto Cortex XSIAM:**

Pls share error documention, because i have faved issue while installation it hits bug.Also i have worked with Thret feed document its casing error.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

Threat Intelligence application download tab is note working, so i have continues working with IBM support team,apphost is another application we are facing isse.

  ### 40. Best security IBM service provider

**Rating:** 5.0/5.0 stars

**Reviewed by:** Faheem Ul Hasan A. | Security Professional, Enterprise (> 1000 emp.)

**Reviewed Date:** July 02, 2022

**What do you like best about Palo Alto Cortex XSIAM?**

Best security alert and safeguarding without a physical security guard. That is most important in the digital world of 25th-century security. Safe and secure IT security.

**What do you dislike about Palo Alto Cortex XSIAM?**

Sometimes the password is missing, or if you enter the password, it clicks another button on the reader. There must be a button with a light and slightly larger to touch and read easily.

**Recommendations to others considering Palo Alto Cortex XSIAM:**

Best IT secure reader system

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

Change or provide an online solution immediately. Work very fast and secure. IBM Qsecurity reader is best for doors and sensitive places to cover. Easy to install and good to use.

  ### 41. IBM QRadar

**Rating:** 4.0/5.0 stars

**Reviewed by:** Mohit V. | Senior Information Technology Security Engineer, Enterprise (> 1000 emp.)

**Reviewed Date:** August 08, 2022

**What do you like best about Palo Alto Cortex XSIAM?**

Its a good SOC tool, and comes with a lot of handy features and functionalitied. 
Captures data from multiple resources over the network and auto generates red flags.
I feel its comparitively better than other tools like splunk and provides better working flexibility.

**What do you dislike about Palo Alto Cortex XSIAM?**

I feel lots of functionality in a tool makes it difficult to manage on the UI and a lot of unrequired features can be provided as an addon which could be installed whenever required.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

centralised tool to collect all infrastructure details, network details and security vulnerabilities as well and helps managing large chunks of data in an organised manner and which can be used in multiple ways.

  ### 42. One of the best SIEM tools we at Ebryx have ever used.

**Rating:** 5.0/5.0 stars

**Reviewed by:** Syed Muhammad Hussain M. | Cyber Security Engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** June 07, 2022

**What do you like best about Palo Alto Cortex XSIAM?**

The ability to engineer custom Log Collectors as well as use HTTP Receivers to utilize integrations with other third-party tools like Cloudflare and the availability of tool specific certifications.

**What do you dislike about Palo Alto Cortex XSIAM?**

The overall graphical user interface of this Security Information and Event Management tool is not up to mark when compared with other tools. The pricing is also well above average.

**Recommendations to others considering Palo Alto Cortex XSIAM:**

Learn how to utilize Custom Data Connectors for third-party app integrations.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

The Security team at Ebryx has integrated IBM Security QRadar on all of our Financial Technology-based clients and so far we have not discovered any mishaps of any kind.

  ### 43. IBM Security QRadar

**Rating:** 5.0/5.0 stars

**Reviewed by:** Tristan Ray L. | Ethical Hacker, Small-Business (50 or fewer emp.)

**Reviewed Date:** March 26, 2022

**What do you like best about Palo Alto Cortex XSIAM?**

The most helpful about IBM Security QRadar as it provides a non-technical overview of endpoint and user activity as well as monitoring in a graphical user interfac.

**What do you dislike about Palo Alto Cortex XSIAM?**

There's nothing I dislike about the product as the security control provided by the product is what is currently essential on the threat landscape. As a security practitioner, detection and response as part of the layer of defense in depth is crucial for mitigating the risks that organizations are constantly facing daily as attacks have been more vivid about detection and response

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

IBM Security QRadar would solve the detection and response layer of defense an organization needs as it is the most critical security control an organization can have to be able to address the security policies that it requires. The benefits in regards to IBM Security Qradar is that it is a multipurpose security control combined into one platform that makes it easier to manage than having multiple GUIs that doesn't provide a analytical comparison between different sources of data or logs.

  ### 44. I love Qradar for its reliability

**Rating:** 4.5/5.0 stars

**Reviewed by:** Alex S. | Senior Infrastructure Engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** August 17, 2022

**What do you like best about Palo Alto Cortex XSIAM?**

We feel safer everyday. Qradar protects our IT infrastructure and in case of any threats it send alerts with reports and the likely possible outcome plus ways to mitigate the risk

**What do you dislike about Palo Alto Cortex XSIAM?**

Qradar is a great and advanced solution that require documentation for beginners to use to learn the software

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

What Qradar gives us everyday is complete protection from outside threats, protection from data leaks, and remote management of devices that are connected to the company

  ### 45. An extremely powerful tool that makes system administration simpler and easier

**Rating:** 5.0/5.0 stars

**Reviewed by:** Hà T. | Cyber Security Engineer, Enterprise (> 1000 emp.)

**Reviewed Date:** June 26, 2022

**What do you like best about Palo Alto Cortex XSIAM?**

IBM Security Qradar helps administrators monitor system details, processes as well as the activities of agents in their system, making it easier for administrators to analyze logs. From there, administrators can detect attacks on the system early.

**What do you dislike about Palo Alto Cortex XSIAM?**

The initial installation cost and license fee are quite large, so it is not suitable for agencies and organizations with network systems.
small and medium scale with limited resources

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

SIEM helps to manage, collect and analyze logs easily and efficiently to help detect possible cyber attacks against the system early, reducing the damage and risks that the organization may face. right if attacked.

  ### 46. A Great SIEM Solution

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Computer & Network Security | Mid-Market (51-1000 emp.)

**Reviewed Date:** May 31, 2022

**What do you like best about Palo Alto Cortex XSIAM?**

QRadar offers alot of different applications that enriches the alerts receieved from the rules defined. It allows integrations with threat intelligence sources such as X-Force.

**What do you dislike about Palo Alto Cortex XSIAM?**

I think that the deployment and maintenance of qradar is sometime abit demanding.
This translates to quite intensive support from integrators (even though we have a very good understanding in QRadar's system administration.

**Recommendations to others considering Palo Alto Cortex XSIAM:**

I really recommend the product. just keep in mind that it is not SaaS and have infrastructure cost implications.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

Allows log collection, parsing and eventually monitoring (based on rules we define).
There are also alot of out-of-the-box rules and parsing mechanisms existing for many

  ### 47. IBM QRadar, Advanced Security

**Rating:** 4.5/5.0 stars

**Reviewed by:** Meherzad J. | SOC Analyst, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 25, 2020

**What do you like best about Palo Alto Cortex XSIAM?**

Available Templates for rules and building blocks, categorisation of domain and tenants and DSM Editor. Auto integration of large no of devices. UBA, its AI models are phenomenal

**What do you dislike about Palo Alto Cortex XSIAM?**

GUI needs few user friendly moves like navigating back to original page and not the home page of offences, no support for huawei devices, overall complexity of the tool.

**Recommendations to others considering Palo Alto Cortex XSIAM:**

QRadar has been instrumental in our fight against cyber threats. It helps identify and mitigate the threats effectively in a short time.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

Better insider view
Great ROI
Improved loopholes in security, overall resulting in increadd uptime of services.
Identifying vulnerabilities

  ### 48. IBM Security QRadar one of the best SIEM Solution

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Enterprise (> 1000 emp.)

**Reviewed Date:** July 22, 2022

**What do you like best about Palo Alto Cortex XSIAM?**

What I like about IBM Security QRadar is that it can be managed in cloud that helps us detect any cyber security attacks and network breaches. Also, the detailed logging data that we collect usung this.

**What do you dislike about Palo Alto Cortex XSIAM?**

What I really dislike about IBM Security QRadar is that, you need to invest on it and spend money to have this. Because, IBM Security QRadar is really an expensive one.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

The common issues and troubleshooting that we always encounter is the auto patching or auto update problem of the versions. We experienced update download errors but the work around is that we always check for au-cert and that so much benefiting us.

  ### 49. A Great  SIEM Solution for your SOC

**Rating:** 4.5/5.0 stars

**Reviewed by:** Pradeep G. | Security Engineer II, Enterprise (> 1000 emp.)

**Reviewed Date:** May 04, 2022

**What do you like best about Palo Alto Cortex XSIAM?**

Easy filtering of logs, Reporting, Alerting, User-friendly interface, Quick filtering and sorting, User and Entity Behavior Analytics,

**What do you dislike about Palo Alto Cortex XSIAM?**

The administration is not easy, there is documentation provided but, one can still face issues in the administration because of its complexity.

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

Incident Handling, Reporting, Log Collection, Alerting etc.
It is easy to handle incidents using this tool, one can easily fetch reports with filters, easy monitoring of logs from different devices.

  ### 50. Qradar user since 2015

**Rating:** 4.0/5.0 stars

**Reviewed by:** Khaled S. | IT Security Officer, Mid-Market (51-1000 emp.)

**Reviewed Date:** May 27, 2022

**What do you like best about Palo Alto Cortex XSIAM?**

IBM X Force is by far the most valuable addition to the already complete SOC solution that Qradar is, AI to be added to the product is very exciting

**What do you dislike about Palo Alto Cortex XSIAM?**

need probably better integration with third-party products and faster development of the product to meet evolving security threats

**What problems is Palo Alto Cortex XSIAM solving and how is that benefiting you?**

centralized view of the threat landscape and automated response makes my life as IT Security officer much easier, reporting function is also very useful


## Palo Alto Cortex XSIAM Discussions
  - [What does QRadar stand for?](https://www.g2.com/discussions/what-does-qradar-stand-for) - 1 comment, 1 upvote
  - [How can I study more on IBM Security QRadar?](https://www.g2.com/discussions/how-can-i-study-more-on-ibm-security-qradar) - 1 comment, 1 upvote
  - [How to build visualization with standard deviations?](https://www.g2.com/discussions/how-to-build-visualization-with-standard-deviations) - 1 comment, 1 upvote
  - [Can IBM Qradar be integrated with our own software? apart from software from major vendors](https://www.g2.com/discussions/32099-can-ibm-qradar-be-integrated-with-our-own-software-apart-from-software-from-major-vendors) - 1 comment, 1 upvote
  - [How do I monitor app resource usage on the app host](https://www.g2.com/discussions/16208-how-do-i-monitor-app-resource-usage-on-the-app-host) - 1 comment, 1 upvote

- [View Palo Alto Cortex XSIAM pricing details and edition comparison](https://www.g2.com/products/palo-alto-cortex-xsiam/reviews?section=pricing&secure%5Bexpires_at%5D=2026-07-31+19%3A49%3A21+-0500&secure%5Bsession_id%5D=c0d6c148-6d2e-475d-95f8-542a4dff824b&secure%5Btoken%5D=2c5ff51f271ff6a4a68150b8132be5aa73c3e9e7f63bbb9d3edbd876fd4e5131&format=llm_user)
## Palo Alto Cortex XSIAM Integrations
  - [Azure Pipelines](https://www.g2.com/products/azure-pipelines/reviews)
  - [Bitsight](https://www.g2.com/products/bitsight/reviews)
  - [CheckPoint](https://www.g2.com/products/checkpoint/reviews)
  - [FortiClient](https://www.g2.com/products/forticlient/reviews)
  - [IBM Security QRadar NDR](https://www.g2.com/products/ibm-security-qradar-ndr/reviews)
  - [Jira](https://www.g2.com/products/jira/reviews)
  - [Microsoft 365](https://www.g2.com/products/microsoft365/reviews)
  - [Microsoft Entra ID](https://www.g2.com/products/microsoft-entra-id/reviews)
  - [Microsoft Teams](https://www.g2.com/products/microsoft-teams/reviews)
  - [Okta](https://www.g2.com/products/okta/reviews)
  - [PagerDuty](https://www.g2.com/products/pagerduty/reviews)
  - [Palo Alto Networks Cloud NGFW](https://www.g2.com/products/palo-alto-networks-cloud-ngfw/reviews)
  - [Palo Alto Networks Panorama](https://www.g2.com/products/palo-alto-networks-panorama/reviews)
  - [Proofpoint Adaptive Email Security](https://www.g2.com/products/proofpoint-adaptive-email-security/reviews)
  - [SentinelOne Singularity XDR](https://www.g2.com/products/sentinelone-singularity-xdr/reviews)
  - [ServiceNow IT Service Management](https://www.g2.com/products/servicenow-it-service-management/reviews)
  - [Slack](https://www.g2.com/products/slack/reviews)
  - [Wiz](https://www.g2.com/products/wiz-wiz/reviews)

## Palo Alto Cortex XSIAM Features
**Automation**
- Metadata Management
- Artificial Intelligence & Machine Learning
- Response Automation
- Continuous Analysis

**Analysis**
- File Analysis
- Memory Analysis
- Registry Analysis
- Email Analysis
- Linux Analysis

**Risk Analysis**
- Risk Scoring
- Reporting
- Risk-Prioritization

**Activity Monitoring**
- Usage Monitoring
- Database Monitoring
- API Monitoring
- Activity Monitoring

**Detection & Response**
- Response Automation
- Threat Hunting
- Rule-Based Detection
- Real-Time Detection

**Agentic AI - User and Entity Behavior Analytics (UEBA)**
- Autonomous Task Execution
- Multi-step Planning
- Proactive Assistance
- Decision Making

**Services - Endpoint Detection & Response (EDR) **
- Managed Services

**Response**
- Resolution Automation
- Resolution Guidance
- System Isolation
- Threat Intelligence
- Incident Investigation

**Cloud Visibility**
- Data Discovery
- Cloud Registry
- Cloud Gap Analytics

**Network Management**
- Activity Monitoring
- Asset Management
- Log Management

**System Control**
- Device Control
- Web Control
- Application Control
- Asset Management
- System Isolation

**Functionality**
- Multi-Network Capability
- Anomaly Detection
- Network Visibility
- Scalability

**Functionality**
- Incident Alerts
- Anomaly Detection
- Continuous Analysis
- Decryption

**Analysis**
- Continuous Analysis
- Behavioral Analysis
- Data Context
- Activity Logging

**Automation**
- Workflow Mapping
- Workflow Automation
- Automated Remediation
- Log Monitoring

**Functionality**
- Centralized platform
- Automated response
- Breach notification law compliance
- Workflow
- Reporting

**Vulnerability Assesment**
- Vulnerability Scanning
- Vulnerability Intelligence
- Contextual Data
- Dashboards

**Security**
- Compliance Monitoring
- Risk Analysis
- Reporting

**Management**
- Extensibility
- Workflow Automation
- Unified Visibility

**Records**
- Incident Logs
- Incident Reports

**Security**
- Data Security
- Data loss Prevention
- Security Auditing

**Incident Management**
- Event Management
- Automated Response
- Incident Reporting

**Vulnerability Prevention**
- Endpoint Intelligence
- Firewall
- Malware Detection

**Incident Management**
- Incident Logs
- Incident Alerts
- Incident Reporting

**Remediation**
- Incident Reports
- Remediation Suggestions
- Response Automation

**Detection**
- Anomaly Detection
- Incident Alerts
- Activity Monitoring

**Orchestration**
- Security Orchestration
- Data Collection
- Threat Intelligence
- Data Visualization

**Automation**
- Automated Remediation
- Workflow Automation
- Security Testing
- Test Automation

**Administration**
- Security Automation
- Security Integration
- Multicloud Visibility

**Analytics**
- Threat Intelligence
- Artificial Intelligence & Machine Learning
- Data Collection

**Management**
- Incident Alerts
- Incident Case Management
- Workflow Management

**Identity**
- SSO
- Governance
- User Analytics

**Security Intelligence**
- Threat Intelligence
- Vulnerability Assessment
- Advanced Analytics
- Data Examination

**Security Management**
- Incident Reports
- Security Validation
- Compliance 

**Response**
- Alerting
- Performance Baselin
- High Availability/Disaster Recovery

**Generative AI**
- AI Text Generation
- AI Text Summarization

**Agentic AI - Security Information and Event Management (SIEM)**
- Autonomous Task Execution
- Multi-step Planning
- Proactive Assistance
- Decision Making

**Agentic AI - Cloud Security Monitoring and Analytics**
- Autonomous Task Execution
- Proactive Assistance
- Decision Making

**Agentic AI - Extended Detection and Response (XDR) Platforms**
- Autonomous Task Execution
- Proactive Assistance
- Decision Making

**Generative AI**
- AI Text Generation
- AI Text Summarization

**Services - Extended Detection and Response (XDR)**
- Managed Services

## Top Palo Alto Cortex XSIAM Alternatives
  - [CrowdStrike Falcon Endpoint Protection Platform](https://www.g2.com/products/crowdstrike-falcon-endpoint-protection-platform/reviews) - 4.6/5.0 (415 reviews)
  - [Wiz](https://www.g2.com/products/wiz-wiz/reviews) - 4.7/5.0 (834 reviews)
  - [Splunk Enterprise](https://www.g2.com/products/splunk-enterprise/reviews) - 4.3/5.0 (415 reviews)

