Ayoub S.
AS
Information Technology Support Analyst
Small-Business (50 or fewer emp.)
Business partner of the seller or seller's competitor, not included in G2 scores.
"Unified SOC Workflows with Smart Alert Correlation and Automation"
5/5
What do you like best about Palo Alto Cortex XSIAM?

What I like best about Cortex XSIAM is how it unifies SOC workflows into a single platform instead of forcing analysts to jump between separate SIEM, EDR, SOAR, and threat intel tools. The automated alert correlation and stitching of related events into a single incident dramatically cuts down on alert fatigue and manual triage time. The built-in automation/playbooks also let simple, repetitive response actions happen without analyst intervention, which frees the team to focus on genuinely complex investigations. On top of that, the AI-driven analytics do a solid job of surfacing real threats from noise, and the integration with Cortex XDR gives strong endpoint visibility right out of the box. Review collected by and hosted on G2.com.

What do you dislike about Palo Alto Cortex XSIAM?

One thing I dislike about Cortex XSIAM is the steep learning curve — the platform is extremely feature-rich, which also means onboarding new analysts and fully mastering the data modeling, correlation rules, and playbook customization takes considerable time. Pricing and licensing can also be complex and expensive compared to some competitors, making cost forecasting difficult for growing SOC teams. Additionally, some integrations with third-party tools outside the Palo Alto ecosystem feel less mature than the native ones, occasionally requiring workarounds or custom scripting. Documentation, while extensive, can sometimes lag behind new feature releases, making troubleshooting newer capabilities a bit harder. Review collected by and hosted on G2.com.

See what 96 reviewers think of Palo Alto Cortex XSIAM

4.5 out of 5 · Verified reviews from real users

Read all reviews