Dharmender  S.
DS
Information Technology Consultant
Enterprise (> 1000 emp.)
"Cortex XSIAM Slashes Alert Fatigue with AI-Driven, High-Context Incidents"
4/5
What do you like best about Palo Alto Cortex XSIAM?

I’ve been testing Cortex XSIAM and am highly impressed by how effectively it cuts through alert fatigue. The platform's ability to automatically stitch raw logs from endpoints, network, and cloud into unified, high-context incidents has dramatically reduced our manual triage workload. Consolidating SIEM, XDR, and SOAR into a single, AI-driven data lake has noticeably accelerated our detection and remediation speeds. For teams already operating within the Palo Alto ecosystem, the seamless data integration is a massive timesaver. It genuinely shifts the SOC from a reactive footing to a highly automated one, allowing our analysts to focus on real threats rather than chasing endless false positives. Review collected by and hosted on G2.com.

What do you dislike about Palo Alto Cortex XSIAM?

While the automation in Cortex XSIAM is powerful, the platform has some noticeable drawbacks. The ingestion-based pricing model is incredibly expensive, making it hard to justify for our budget. We’ve also run into significant vendor lock-in; the tool works seamlessly with Palo Alto products, but configuring third-party, non-Palo Alto data sources and custom parsers has been frustratingly limited and slow. Additionally, the learning curve is exceptionally steep. Review collected by and hosted on G2.com.

See what 95 reviewers think of Palo Alto Cortex XSIAM

4.5 out of 5 · Verified reviews from real users

Read all reviews