
We use Palo Alto Cortex XSIAM regularly for security monitoring, alert investigation, and endpoint visibility. One of the features I find most useful is the ability to investigate an alert and quickly move from the initial detection to related endpoint activity and other relevant security events without having to manually piece everything together from multiple tools.
Another useful aspect is the automation and correlation of security events. Instead of manually reviewing large numbers of individual alerts, XSIAM helps bring related activity together, which makes the investigation process more efficient. Review collected by and hosted on G2.com.
The main thing I dislike about Cortex XSIAM is the learning curve. I would also like to see some workflows made more intuitive, particularly for users who are new to the platform. More straightforward documentation and guided configuration would make onboarding easier. Review collected by and hosted on G2.com.