
What I like best about Cortex XSIAM is how it brings SIEM, XDR, SOAR, endpoint, network and cloud security data into one platform. The AI-driven analytics and automation help reduce alert noise, prioritise real threats, and speed up investigation and response. I particularly like the centralised visibility and automated incident response, as they reduce manual work and allow security teams to focus on higher-risk issues It works very well with other tools in the security stack. Cortex XSIAM supports a wide range of third-party integrations, including firewalls, cloud platforms, endpoint security, Microsoft 365, ServiceNow and other SIEM/SOC tools. The APIs and integration options make it relatively straightforward to centralise logs and automate workflows. Review collected by and hosted on G2.com.
The main drawback for me is the complexity during initial setup, tuning and onboarding. There are many powerful features, but it can take time and training to understand how to configure and customise them effectively. The cost can also be relatively high, particularly for smaller organisations. Once properly configured, though, the platform becomes much easier to manage. Review collected by and hosted on G2.com.