Verified User
G
Verified User
Enterprise (> 1000 emp.)
"Revolutionizes Security Operations but Challenging Data Onboarding"
4.5/5
What do you like best about Palo Alto Cortex XSIAM?

I like Palo Alto Cortex XSIAM's ability to unify data, automation, and analytics, wrapping all these into a single platform. It's great at solving major security operations challenges like eliminating alert fatigue and tool fragmentation. I also appreciate how it brings data, analytics, and automation together to stop cyber threats faster, cutting down manual work and linking information across different security tools. It also spots hidden dangers early. The initial setup and tenant activation are quite efficient, taking about an hour via the gateway, and the full environment configuration is streamlined using migration tools. Review collected by and hosted on G2.com.

What do you dislike about Palo Alto Cortex XSIAM?

I find the high costs and complex data onboarding with Palo Alto Cortex XSIAM challenging. The data onboarding is complex because of messy file formats, custom mapping requirements, and poor data quality. It would be helpful to have pre-built validation and cleansing tools to catch formatting errors instantly, and letting users map and fix their own data fields through an intuitive UI would improve the experience. Review collected by and hosted on G2.com.

Verified User
G
Verified User
Mid-Market (51-1000 emp.)
"Centralize Security Management but with High Costs"
3.5/5
What do you like best about Palo Alto Cortex XSIAM?

I like how Palo Alto Cortex XSIAM eliminates duplicates, which avoids having to do the work twice. I value the behavioral analysis, as it allows predicting potential attacks before a human detects them. Additionally, I appreciate that in the SOC where I work, we use Palo Alto Cortex XSIAM to manage all the tools in one place, which allows us to have all the logs from the EDR, XDR, SOAR, and SIEM in a single point without the need for multiple screens or duplicate logs. Review collected by and hosted on G2.com.

What do you dislike about Palo Alto Cortex XSIAM?

Perhaps due to the high cost or the great dependence on Palo Alto ecosystems and the low compatibility with other ecosystems. Perhaps for the cost, a pricing based not so much on data volume but on usage or processing. Review collected by and hosted on G2.com.

TP
Tim P.
Information Security Analyst
Mid-Market (51-1000 emp.)
"Powerful Log Consolidation with Great Threat Detection Accuracy and Precise Alerts"
5/5
What do you like best about Palo Alto Cortex XSIAM?

It effectively consolidates log data from multiple sources in one place and offers a highly customizable dashboard that provides real-time visibility into our environment with the ability to send alerts on specific behaviors so we can respond swiftly to emerging threats. Review collected by and hosted on G2.com.

What do you dislike about Palo Alto Cortex XSIAM?

The documentation of the tool can be more detailed but other than that it is powerful for analysis of incidents and I would recommend to others to use it. Review collected by and hosted on G2.com.

Rohan K.
RK
Rohan K.
Senior Azure devops engineer
Enterprise (> 1000 emp.)
"Palo Alto Cortex XSIAM Streamlines SOC Work with Smart Noise Reduction and Automation"
5/5
What do you like best about Palo Alto Cortex XSIAM?

I’ve been using Palo Alto Cortex XSIAM for a while now, and honestly it has made a big difference in how we handle security operations. The platform brings everything into one place, so I don’t have to jump between multiple tools anymore. What I like the most is how well it reduces alert noise and highlights only the important threats, which saves a lot of time. The automation is very helpful too—it speeds up investigation and response without much manual effort. Overall, it feels reliable, efficient, and makes daily SOC work much smoother. Review collected by and hosted on G2.com.

What do you dislike about Palo Alto Cortex XSIAM?

While I’ve had a positive experience overall with Palo Alto Cortex XSIAM, there are a few areas that could be improved. The platform can feel a bit complex at first, especially during the initial setup and onboarding phase, which may require time and proper training to fully understand all its capabilities. Additionally, customization and fine-tuning certain workflows can sometimes be less intuitive than expected. In some cases, the resource usage and cost considerations can also be a concern for smaller teams. That said, once you get past the learning curve, it becomes much more manageable and effective in daily operations. Review collected by and hosted on G2.com.

CG
Christopher G.
SOC Analyst
Mid-Market (51-1000 emp.)
"Delivers Quick Visibility into Anomalies and Easy to Tune Alerts with Impressive Granularity"
5/5
What do you like best about Palo Alto Cortex XSIAM?

The strong capabilities in log correlation and threat detection provides deep visibility into network activity and security events and it sends real time alerts in form of alarms enabling us to respond to security issues right away. Review collected by and hosted on G2.com.

What do you dislike about Palo Alto Cortex XSIAM?

There are no major challenges experienced since the initial setup and they have a very reliable support so the platform is great for collecting, analyzing and reporting log information. Review collected by and hosted on G2.com.

Verified User
G
Verified User
Enterprise (> 1000 emp.)
"Powerful Integration, High Learning Curve"
5/5
What do you like best about Palo Alto Cortex XSIAM?

I really like Palo Alto Cortex XSIAM's simplicity and its very humanistic approach to solving problems, even ones that seem complex at first. Its features work together seamlessly as an integrated security operating platform, which eliminates the need to switch between separate tools like endpoint detection, log analysis, threat intelligence, instant investigation, and response. This integration brings the data and workflows into a single environment, making it easier to connect related activities. Review collected by and hosted on G2.com.

What do you dislike about Palo Alto Cortex XSIAM?

If I had to point out something, I'd say there's quite a large learning curve. Because it combines SIEM and SOAR and point security automation and threat intelligence into a single platform, it can be quite a daunting task to learn. Review collected by and hosted on G2.com.

TM
Thomas M.
Senior System Engineer
Mid-Market (51-1000 emp.)
"Centralized Event Correlation That Strengthens Threat Monitoring and Anomalies Detection"
5/5
What do you like best about Palo Alto Cortex XSIAM?

It provides strong threat detection and better visibility across security events with automated incident investigation making it a reliable solution for security monitoring that helps prevent anomalous behavior in our systems. Review collected by and hosted on G2.com.

What do you dislike about Palo Alto Cortex XSIAM?

Nothing much to dislike so far as it has been a very reliable SIEM solution although personally I would improve the graphical interface it is good but in my opinion improvable. Review collected by and hosted on G2.com.

AG
Aaron G.
Cyber Security Engineer
Mid-Market (51-1000 emp.)
"Automatically Connects All Log Events for Clearer Incident Visibility and Threat Handling"
5/5
What do you like best about Palo Alto Cortex XSIAM?

It automatically stitches together disparate log events into a coherent incident view providing deeper visibility into anomalous user behavior and helps identify complex attack patterns. Review collected by and hosted on G2.com.

What do you dislike about Palo Alto Cortex XSIAM?

The system supports a wide array of log sources so it requires intensive resources to maintain and tuning the rules to reduce false positives requires significant expertise. Review collected by and hosted on G2.com.

LR
Lauren R.
System Administrator
Mid-Market (51-1000 emp.)
"Expansive Threat Visibility and Smart Log Correlation That Streamlines Incident Investigation"
5/5
What do you like best about Palo Alto Cortex XSIAM?

The platform provides an expansive view of the network, endpoint and application layers automatically grouping related security events and the correlation engine helps catch suspicious activity from different log sources in one place which helps streamline the investigation process. Review collected by and hosted on G2.com.

What do you dislike about Palo Alto Cortex XSIAM?

I find the platform very powerful without any major issues and from an analysis perspective it is very reliable for analysis across our event log collation. Review collected by and hosted on G2.com.

AF
Antonio F.
System Engineer
Mid-Market (51-1000 emp.)
"Efficient in High Volume Log Monitoring for Quick Investigation of Security Events"
5/5
What do you like best about Palo Alto Cortex XSIAM?

It has proven to be a highly effective tool for deep forensic investigation of vulnerabilities with precision and it performs well handling high log event volumes efficiently which helps in monitoring end users activity very closely. Review collected by and hosted on G2.com.

What do you dislike about Palo Alto Cortex XSIAM?

We have used the tool for more than 2 years now and we are absolutely satisfied with it and it offers greater value than its competitors on the market. Review collected by and hosted on G2.com.