No more typing reviews! Try our Samantha, our new voice AI agent.

BigFix vs Cisco Secure Cloud Analytics [EOL] comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
118
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (5th), Extended Detection and Response (XDR) (3rd), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
BigFix
Average Rating
8.6
Reviews Sentiment
6.4
Number of Reviews
100
Ranking in other categories
Configuration Management (8th), Endpoint Protection Platform (EPP) (22nd), Patch Management (8th), Unified Endpoint Management (UEM) (11th), Autonomous Endpoint Management (6th)
Cisco Secure Cloud Analytic...
Average Rating
8.6
Number of Reviews
7
Ranking in other categories
No ranking in other categories
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
InderjeetSingh4 - PeerSpot reviewer
Administrator at a tech vendor with 10,001+ employees
End-to-end automation has simplified patching and software deployment across thousands of servers
There is one feature in BigFix called the automation patch policy that requires enhancement. When an action is initiated through the patch policy, it appears on the console but arrives in chunks. When targeting hundreds of servers from the patch policy, the actions come in chunks such as ten out of six, ten out of nine, or ten out of fifteen. This fragmented approach creates a significant challenge for the patching team to monitor the action status. I would recommend that the development team provide a single action or one to two actions instead of multiple actions requiring individual monitoring. A broad status update could be provided to the client indicating the overall progress of the patch policy implementation rather than requiring monitoring of every individual action. This would reduce the bandwidth required by the team to track multiple actions on the console.
SP
Security Analyst at Orange España
Efficiently generates alerts for suspicious activities and scales easily
There are two areas of improvement. Firstly, extend the log retrieval limit to at least three months. For example, there is a limit on the number of log messages that can be received. So, I would like to expand the log retrieval limit. And another thing, if we migrate these things to an event or send us an email if there is any critical event, I would like to configure these things on the initial launch. Because if a system is compromised, there will be a lot of data movement from one post to another post to the outside. Then, we should also get an alert on email as well. We have since we have integrated these things. But a direct email for critical alerts should be there. So, I would like to enhance the critical event configuration. If a new user wants to learn how it should work, how policies work, and where we can configure policies, there should be some learning material for this product.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Previously, we had to install endpoint protection per machine and then scan and update, but Cortex XDR basically does that centrally and predictably, so we have more time to do day-to-day work rather than spend time chasing those endpoints."
"What I like about Cortex XDR by Palo Alto Networks is that it is a comprehensive solution that contains everything the organization may need when using endpoints."
"I have found the solution to be very easy in respect of the integration and configurable."
"Palo Alto is one of the tech vendors that always provides top-of-the-line products."
"My advice for others looking into using Cortex is that it is very easy to use and very useful for the customer environment, whether it's a public or private one."
"Palo Alto is the best security solution in the market."
"It is an easy-to-use tool."
"This software helps us understand any issues that may arise when someone is not at work."
"Before we had BigFix, we had problems with some malware. BigFix allows us to immediately patch all instances of endpoints that were vulnerable to antivirus and initiate scans. That's key."
"I like the overall usage of it; it's easy to use, gives you great visibility into your environment, allows customization of your reports, and offers a community of users from whom you can pull experience and knowledge, which is one of the main advantages of using BigFix."
"From a security standpoint, it allows us to make sure that we're not leaving ourselves vulnerable to exploits and things like that. That's the biggest advantage that we see to the product from a security standpoint."
"The architecture for patching and the 100% correct reporting makes BigFix stand apart from other solutions."
"Patch Management for a variety of operating systems makes it valuable as we can rely on a single tool for obtaining patch compliance of the entire compute infrastructure."
"My company provides support services to a lot of customers and companies. We have reduced a huge amount of man-effort. Along with the man-effort, we have reduced the timeline to fix the compliance and security gaps. We have an unbroken record. The documentation clearly says that we have done the patching of newly released patches, including Microsoft and third-party patches, in up to 80% of the computers, within 72 hours of the release of the production. That was a very massive benefit that we have seen. When I talk about the 80% endpoints, it is 100 or 200. I am talking about 25,000 endpoints."
"Software distribution and patch management are the most valuable."
"Support is very awesome. Every time we have needed something from technical support, they have been on top of everything with a very quick turnaround in the issues that we've had with the product."
"We were able to prevent an electric fraud of almost $200,000."
"Monitoring the traffic, making sure you have the visibility."
"The tool's best feature is its ability to monitor network traffic. It will also inform users whether the traffic generated by a network is legitimate. The tool helps to capture and analyze the network traffic."
"It tells you if there is any communication going to command and control servers, or if there is any traffic that violates your internal policy, or if any data hoarding is happening where data is being dumped from your machine to outside of the environment. It provides all such meaningful reports to help you understand what's happening."
"The logs in Cisco Stealthwatch Cloud are very good when doing the API integration in the team. It is able to give you important information for the correlations."
"My advice to others is Cisco has great solutions and I would recommend them."
"I would recommend Cisco Stealthwatch Cloud 100 percent."
"The product helps me to see malware."
 

Cons

"Limited remote connection."
"It is not very strong in terms of endpoint management. It should have additional features like DLP, encryption, or advanced device control. Currently, Cortex is good in terms of the security of the endpoints, but it is not as good as other vendors in terms of the management of the endpoint."
"The solution should force customers to integrate with network traffic to see the full benefits of XDR."
"There's room for improvement with Mac device installations, which can be challenging."
"Basically, they don't provide customer support tools just to investigate the logs."
"For Cortex XDR by Palo Alto Networks, if I had to point out improvements, I would say the UI is still somewhat difficult for beginners."
"While using Cortex, I noticed some aspects that could be improved, such as increasing the synchronization speed between XDR and Xnor."
"I have faced some issues with Cortex XDR by Palo Alto Networks; there is room for improvement in the sense that certain options prevent us from seeing and segregating data."
"BigFix can improve the way machines report back to the console."
"We're a partner, so we deliver technical support to customers. When we need to talk to the product support, traditionally, with the product over the last five years, I would not say support has been supportive. I hope that changes."
"Technical support is getting better. About five years ago, it was horrible."
"The main shortcoming of BigFix was integration with vulnerability management."
"I want to see a solution for being able to deploy automated software to a Mac running OS X 10.13, something that's going to deal with kernel exceptions and answering prompts for user permissions for data folders and whatnot. They need to really streamline and automate the Mac software deployment."
"Be careful. It's a super powerful tool. It can be unforgiving, i.e., if you do some of the things wrong, it can be a nightmare."
"The console interface is not friendly, and requires training before using it in production."
"There is limited support or assistance when creating new deployment tasks."
"If we migrate these things to an event or send us an email if there is any critical event, I would like to configure these things on the initial launch. Because if a system is compromised, there will be a lot of data movement from one post to another post to the outside. Then, we should also get an alert on email as well. We have since we have integrated these things. But a direct email for critical alerts should be there. So, I would like to enhance the critical event configuration."
"The product needs to improve its user-friendliness. It is very tricky and you need to study it before using the standard functionalities."
"Cisco Stealthwatch Cloud could improve the graphical user interface. It could be a more user-friendly graphical user interface."
"When I used to work on it, I just didn't see anything new happening for about a year and a half. Providing newer data and newer reports constantly would help. There should be more classifications and more interesting data."
"The initial setup of Cisco Stealthwatch Cloud is complex."
"The product's price is high."
"The initial setup is a bit complex in terms of deployment and configuration."
"Cisco Stealthwatch Cloud could improve the graphical user interface. It could be a more user-friendly graphical user interface. so that. Not everybody's a cyber security professional, most of the customers that I deal with are not very skilled. The terms that they use in the solution are quite understandable for a normal CIO."
 

Pricing and Cost Advice

"It has reasonable pricing for the use cases it provides to the company."
"The pricing is okay, although direct support can be expensive."
"The solution is expensive. It's pricing is on a yearly-basis."
"The pricing is a little bit on the expensive side."
"Every customer has to pay for a license because it doesn't work with what you get from a managed services provider."
"I did PoCs on products called Cylance and CrowdStrike. Although, I consider these products and they were also good, when it come to cost and budgetary factors, Traps has been proven to be better than the other two products. It is quite cost-effective and delivers all the entire solution which we require."
"If one wishes to work with another team or large number of users at a future point, he must purchase a license for them."
"I don't have any issues with the pricing. We are satisfied with the price."
"When purchasing, buying with other IBM tools provided us with a very good discount in pricing."
"The cost is slightly high."
"It is too costly. It is one of the best tools, but because of pricing, not all clients support it. Its licensing is on a yearly basis."
"There's not much big cost. We only have to pay the agents' cost for the server, and for the systems."
"I would stay with the Managed Virtual Server license model, which is a 1-to-1 license per OS whether it is virtual or physical."
"I can estimate the reduced cost of servers maintenance to approximatively $500,000."
"The price of BigFix could be lower. However, I am always seeking a lower price."
"The price of the solution is high. There are not any additional fees from the standard license."
"The solution is quite expensive."
"Cisco Stealthwatch Cloud is an expensive enterprise solution."
"The price of Cisco Stealthwatch Cloud is expensive."
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
914,938 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Comms Service Provider
12%
Construction Company
11%
Manufacturing Company
10%
Financial Services Firm
13%
Manufacturing Company
9%
Outsourcing Company
9%
Construction Company
6%
Construction Company
15%
Comms Service Provider
11%
Outsourcing Company
11%
Manufacturing Company
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise21
Large Enterprise55
By reviewers
Company SizeCount
Small Business30
Midsize Enterprise12
Large Enterprise68
By reviewers
Company SizeCount
Small Business1
Midsize Enterprise2
Large Enterprise6
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What is your experience regarding pricing and costs for BigFix?
I rate the price for BigFix as medium, neither low nor high.
What needs improvement with BigFix?
There is one feature in BigFix called the automation patch policy that requires enhancement. When an action is initia...
What is your primary use case for BigFix?
My current use case involves being one of the products and one of the clients implementing this tool.
Ask a question
Earn 20 points
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
Tivoli Endpoint Manager
Cisco Stealthwatch Cloud, Observable Networks
 

Interactive Demo

Demo not available
Demo not available
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
US Foods, Penn State, St Vincent's Health US Foods, Sabadell Bank, SunTrust, Australia Sydney, Stemac, Capgemini, WNS Global Services, Jebsen & Jessen, CenterBeam, Strauss, Christian Hospital Centre, Brit Insurance, Career Education Corporation
Options, Schneider Electric, Washington University in St Louis, Gotcha, Kraft Kennedy, PartnerRe, Sumologic, Veterans United, AFGE, Agraform, Artesys, Dynamic Ideas Financials, Department of Agriculture and Commerce
Find out what your peers are saying about CrowdStrike, Microsoft, SentinelOne and others in Endpoint Protection Platform (EPP). Updated: September 2026.
914,938 professionals have used our research since 2012.