
What I appreciate most about Cortex XSIAM is how it consolidates SOC operations into a single platform. Bringing SIEM, XDR, SOAR, and threat intelligence together under one console removes the constant context-switching that comes with running multiple disconnected tools, and it gives analysts a much clearer picture during investigations.
The data ingestion and normalisation are strong, and having endpoint, network, cloud, and identity telemetry available in one place makes threat hunting and incident response noticeably faster. The AI-driven detection and correlation reduce alert fatigue by grouping related events into coherent incidents rather than flooding the queue with isolated alerts, which has been a meaningful improvement for day-to-day operations.
Automation is another strong point. The playbooks are flexible enough to handle routine triage and response tasks with minimal analyst intervention, which frees the team up to focus on higher-value work. Integration with the broader Palo Alto ecosystem is seamless, and third-party integrations are well supported. Review collected by and hosted on G2.com.
The pricing model can be steep, particularly for smaller teams, and cost scales quickly with data ingestion volume. The learning curve is also fairly steep — getting the most out of the platform requires meaningful time investment in tuning detections, building playbooks, and understanding the underlying data model. Documentation, while comprehensive, can be difficult to navigate when troubleshooting specific issues. Review collected by and hosted on G2.com.