TH
Tim H.
Marketing Manager
Environmental Services
Mid-Market (51-1000 emp.)
"Palo Alto Cortex XSIAM: Centralized Security with Powerful AI Automation"
4.5/5
What do you like best about Palo Alto Cortex XSIAM?

I like the effectiveness of Palo Alto Cortex in centralizing most of our security services and operations, where it combines XDR capabilities, SOAR, snd SIEM.

Cortex XSIAM has enabled AI powered automation, and this accelerates the investigation process and prioritizes the sensitive threats.

We acknowledge the reliability and efficiency of Cortex XSIAM dashboard, where it gives us detailed reports concerning all companies endpoints, identifies, and other security issues.

The software has robust security automations, which reduces the manual workloads for employees.

Cortex XSIAM is determined in automating most of the repetitive security tasks and this gives the analyst adequate time to deal with other issues. Review collected by and hosted on G2.com.

What do you dislike about Palo Alto Cortex XSIAM?

The initial installation of Palo Alto Cortex demands accurate configuration and tuning to match companies needs, and this calls for experienced professionals.

Cortex XSIAM has high licensing costs, which discourages small businesses Review collected by and hosted on G2.com.

AM
Anas M.
SOC Analyst
Information Technology and Services
Small-Business (50 or fewer emp.)
"Efficient Security Monitoring with Powerful Automation"
4/5
What do you like best about Palo Alto Cortex XSIAM?

I like the automation Palo Alto Cortex XSIAM provides; it cuts down a lot of the manual work involved in investigating alerts, saving a ton of time. I also like that everything is in one place, allowing me to avoid jumping between different tools to understand what's happening. The dashboards are clear, and the overall visibility into our environment is much better than what we had before. I appreciate that it pulls logs from different sources, correlates alerts automatically, and helps prioritize the ones that matter, which prevents chasing false positives. The automation saves our SOC team a lot of time, especially for repetitive investigation and response tasks, making threat detection and incident handling much more efficient. Having everything integrated into Cortex XSIAM makes correlating alerts from different sources easier and helps investigate incidents without constantly switching consoles. The integrations are smooth overall and help provide a much better view of what's happening across the environment. Review collected by and hosted on G2.com.

What do you dislike about Palo Alto Cortex XSIAM?

I found the initial setup and configuration could be better, as it takes some time to get everything tuned properly, especially when integrating a lot of different data sources. We also experienced a bit of a learning curve due to the platform's numerous features, which can be challenging for new users. Review collected by and hosted on G2.com.

YG
Yogesh G.
Linux Administrator
Information Technology and Services
Mid-Market (51-1000 emp.)
"Dramatically Fewer Alerts and Faster Response in One Console"
4.5/5
What do you like best about Palo Alto Cortex XSIAM?

Alert consolidation and noise reduction are major strengths. XSIAM ingests raw logs and telemetry and then automatically correlates them into a small number of “incidents,” rather than flooding the SOC with thousands of individual alerts. This is consistently described as the biggest win, with analysts reporting a dramatic drop in the daily alert volume they need to triage.

Speed to detection and response also stands out. Because it’s built around a unified data lake with built-in automation, mean time to detect and respond drops sharply compared with a traditional SIEM paired with separate SOAR and separate EDR tools.

Native integration across the Palo Alto stack is another draw. Firewall data, Cortex XDR endpoint telemetry, cloud logs, and third-party feeds land in a single data model, so correlation across network, endpoint, and cloud can happen without custom parsers—especially appealing for teams already running Palo Alto gear.

Built-in automation and out-of-the-box playbooks are frequently praised as well. Users like that common response actions are already pre-built, instead of being something the SOC has to author from scratch.

Finally, having a single console instead of a swivel-chair workflow is cited as a quality-of-life improvement. Not having to jump between separate SIEM, SOAR, EDR, and TIP UIs is repeatedly mentioned as a win for analysts. Review collected by and hosted on G2.com.

What do you dislike about Palo Alto Cortex XSIAM?

Pricing (per-GB ingestion plus compute) gets expensive quickly, especially at scale, and it’s often described as one of the priciest options on the market.

Onboarding data sources and setting up correlation rules feels heavier than I expected for a “unified” platform. Tuning detections and playbooks, along with getting data onboarding right, takes real time and expertise before it starts to pay off.

The deep tie-in to the Palo Alto ecosystem also makes it harder to mix in other vendors’ tools, and it could make migrating away later more difficult. Review collected by and hosted on G2.com.

Verified User in Hospital & Health Care
AH
Verified User in Hospital & Health Care
Enterprise (> 1000 emp.)
"Powerful Correlation and Integrations, but Slow UI and Clunky IAM Setup"
3.5/5
What do you like best about Palo Alto Cortex XSIAM?

XSIAM is very powerful and has allowed us to ingest data from multiple sources, with most of them coming from out-of-the-box integrations. For the few data sources where we had to build support, the help from Palo Alto has been great. The biggest benefit is the correlation engine; however, without Palo Alto professional services, we wouldn’t be using even a fraction of its capabilities. Review collected by and hosted on G2.com.

What do you dislike about Palo Alto Cortex XSIAM?

Often when I’m running queries, the UI is very slow. I’ve started warning teammates that if you do this, it’s going to be click, wait, wait, wait. Another thing I don’t like is how some of the IAM works. You have to create an account in the Palo Alto support portal, then log in to XSIAM, create the account there as well, and assign roles and permissions. This is still required even with SSO integration. Review collected by and hosted on G2.com.

Verified User in Financial Services
UF
Verified User in Financial Services
Enterprise (> 1000 emp.)
"Cortex XSIAM helps us cut through noise and focus on real threats"
4/5
What do you like best about Palo Alto Cortex XSIAM?

The Cortex XSIAM interface is clean and makes complex investigations easy to navigate, and the dashboards are highly customizable. Integrations are another advantage of this platform, especially when working across multiple data sets. Query execution is super fast, and the scalability is solid compared to other SIEM solutions I’ve worked with previously. It also goes without saying that consolidating SIEM + SOAR + AI analytics into one platform makes it more budget-friendly. Since we’re already Palo Alto customers, their onboarding support was impressive, as always. Their AI driven correlation is pretty impressive, especially while linking signals across hosts, users and applications. Review collected by and hosted on G2.com.

What do you dislike about Palo Alto Cortex XSIAM?

Honestly, while Cortex XSIAM is powerful, getting used to the platform takes time and can feel overwhelming at times, especially for those who are new to the industry. The support and onboarding are good, but I felt that more hands-on workshops would have helped us adopt the platform faster. The AI correlation is impressive compared to the other technologies we’re currently using. However, it does surface false positives sometimes, which means we have to spend extra time tuning the models. Review collected by and hosted on G2.com.

Sachit  S.
SS
Sachit S.
Associate – Cyber Incident Response
Enterprise (> 1000 emp.)
"Unified SIEM/XDR/SOAR Platform That Cuts Alert Noise and Speeds Investigations"
5/5
What do you like best about Palo Alto Cortex XSIAM?

What I like best about Palo Alto Cortex XSIAM is how it brings SIEM, XDR, SOAR, threat intelligence, and automation into a single platform. It uses AI to reduce alert noise, automatically prioritize incidents, and speed up investigations, allowing security teams to focus on real threats instead of repetitive manual tasks. I also like its strong automation capabilities and centralized visibility, which help improve SOC efficiency and reduce incident response time. Review collected by and hosted on G2.com.

What do you dislike about Palo Alto Cortex XSIAM?

One drawback of Palo Alto Cortex XSIAM is that it has a steep learning curve, especially for new users. Its advanced features and extensive customization options can take time to understand. It can also be expensive for smaller organizations, and setting up complex automation workflows may require experienced security professionals. However, once implemented properly, the platform provides significant value through improved security operations and automation. Review collected by and hosted on G2.com.

Ronald D.
RD
Ronald D.
Senior Business Development Specialist
Mid-Market (51-1000 emp.)
"Streamlines Security Operations with Automation"
4/5
What do you like best about Palo Alto Cortex XSIAM?

I like that Palo Alto Cortex XSIAM really helps with alert fatigue and slow incident response. It's great how it gives the security team the capability to handle thousands of alerts in one day instead of dealing with them multiple times. The use of AI and automation is also a big plus because it helps in prioritizing high-risk incidents and automating routine processes. This means my team can respond to incidents before they escalate into major security threats. The way it centralizes automations and reduces false positives is pretty handy, especially with improved alert formats that increase analyst activity. Also, the automation in compliance reporting is beneficial as it reduces the mean time to detect and respond, which leads to lower operational costs and improved cybersecurity. Additionally, setting it up was quite easy, and it integrates well with existing platforms without needing third-party tools or cumbersome manuals. Review collected by and hosted on G2.com.

What do you dislike about Palo Alto Cortex XSIAM?

The automation part in Palo Alto Cortex XSIAM could be improved. Some people need to learn how to do it, and security teams are spending a lot of time investigating thousands of alerts. The volume of alerts and connecting with the security tools has critically increased the response time. Review collected by and hosted on G2.com.

Alessandro D.
AD
Alessandro D.
Technical Leader
Mid-Market (51-1000 emp.)
"Strong incident correlation, but commit fully or don't bother"
3.5/5
What do you like best about Palo Alto Cortex XSIAM?

Incident clustering cuts alert fatigue fast. The ML groups related alerts into a single case instead of 15 separate pings, which makes a big difference during H24 on-call shifts. Review collected by and hosted on G2.com.

What do you dislike about Palo Alto Cortex XSIAM?

XQL has a steep learning curve for analysts coming from KQL or YARA-L, and onboarding took longer than I expected. The licensing cost is high, and the ROI weakens quickly if you don’t fully commit to the Cortex ecosystem. Review collected by and hosted on G2.com.

sikunju I.
SI
sikunju I.
Desktop Support Engineer
Enterprise (> 1000 emp.)
"Cortex XSIAM Turns Massive Alert Noise into High-Confidence Signals"
5/5
What do you like best about Palo Alto Cortex XSIAM?

The best part about Palo Alto Cortex XSIAM is how it works with huge amounts of data to streamline activity. I was genuinely shocked by how effectively it groups millions of noisy, fragmented alerts into a small handful of high-confidence alerts. Review collected by and hosted on G2.com.

What do you dislike about Palo Alto Cortex XSIAM?

The platform seems designed to work mainly within its own ecosystem, such as Cortex XDR and Palo Alto Firewalls. If it could extend beyond this proximity and be made to function smoothly with third-party firewalls and other tools, it would be more functional and useful for the vendor. Review collected by and hosted on G2.com.

Verified User
G
Verified User
Enterprise (> 1000 emp.)
"Revolutionizes Security Operations but Challenging Data Onboarding"
4.5/5
What do you like best about Palo Alto Cortex XSIAM?

I like Palo Alto Cortex XSIAM's ability to unify data, automation, and analytics, wrapping all these into a single platform. It's great at solving major security operations challenges like eliminating alert fatigue and tool fragmentation. I also appreciate how it brings data, analytics, and automation together to stop cyber threats faster, cutting down manual work and linking information across different security tools. It also spots hidden dangers early. The initial setup and tenant activation are quite efficient, taking about an hour via the gateway, and the full environment configuration is streamlined using migration tools. Review collected by and hosted on G2.com.

What do you dislike about Palo Alto Cortex XSIAM?

I find the high costs and complex data onboarding with Palo Alto Cortex XSIAM challenging. The data onboarding is complex because of messy file formats, custom mapping requirements, and poor data quality. It would be helpful to have pre-built validation and cleansing tools to catch formatting errors instantly, and letting users map and fix their own data fields through an intuitive UI would improve the experience. Review collected by and hosted on G2.com.