

BigFix and Cortex XDR by Palo Alto Networks compete in the endpoint management and security market. Users appreciate the pricing and support of BigFix but find Cortex XDR's superior security features worth the higher cost.
Features: BigFix offers comprehensive patch management, robust endpoint compliance capabilities, and effective asset discovery. Cortex XDR provides advanced threat detection, seamless integration with Palo Alto Networks' ecosystem, and efficient incident response features.
Room for Improvement: Users suggest BigFix needs better scalability, improved speed, and enhanced user interface. Cortex XDR could benefit from better alert correlation, fewer false positives, and more intuitive reporting.
Ease of Deployment and Customer Service: BigFix has a straightforward deployment process but can be challenging at scale. Cortex XDR receives mixed reviews for deployment ease but is known for robust support services, handling complex installations well.
Pricing and ROI: BigFix is noted for its competitive pricing and positive ROI. Cortex XDR is perceived as more expensive but justifies the cost with advanced security features, providing significant long-term benefits.
They appreciate the rich telemetry data from the solution, as it provides in-depth threat identification.
Cortex XDR by Palo Alto Networks helps to reduce my total cost of ownership significantly.
I have seen a return on investment with Cortex XDR by Palo Alto Networks, as this product is offered at a minimal cost, and we can find a good ROI from it.
On a scale from one to ten, with ten being the highest quality, enterprise support provides timely responses, typically within four to eight hours.
Technical support from HCL is satisfactory unless there are customization requirements.
The technical support from Palo Alto deserves a mark of ten because they reach out within an hour whenever assistance is needed.
There is no back and forth, and they know what we are asking for and come up with the best resolution for a solution.
If any of these services are missed, it becomes a problem in terms of support tickets, follow-up, or special configuration that needs to be done in the system.
BigFix requires some minimum configuration requirements.
Cortex XDR by Palo Alto Networks can be expanded anytime by purchasing another license without any issues related to scalability.
I think scalability for Cortex XDR by Palo Alto Networks is good.
Cortex remains fast and responsive, even with increasing data and alerts.
The thresholds we've seen on our firewall boxes at some instances reached 80% to 85%, but even at that level of utilization, we don't observe any latency or any issues reported with respect to accessing the application.
Cortex XDR is stable, offering high quality and reliable performance.
Building a management console is quick and simple, taking only one to two hours for setup.
The problem was related to the hardware configuration and hardware specifications.
In addition to reporting improvements, there should be a feature for application control to allow or disallow certain applications from being executed on endpoints.
Improving reporting and dashboard customization, along with the addition of real-time and exportable reports, would help SOC teams greatly.
The inclusion of this feature would allow the application of DLP policies alongside antivirus policies via a single agent and console, making it more competitive as other OEMs often offer DLP solutions as part of their antivirus products.
If the per GB data could be provided at a certain level free of cost or at the same cost which the customer is taking for the entire bundle, that would be better.
The pricing is pretty good and now follows a subscription model similar to SolarWinds, making it easier for customers to subscribe and unsubscribe.
The pricing on SentinelOne is far more reasonable and cheaper than Cortex XDR by Palo Alto Networks.
I would say it is definitely not a cheap product, considering how mature it is and how scalable all Palo Alto products are together.
Cortex XDR is perceived as expensive by some customers, yet offers dynamic pricing.
The BigFix features that have proven most effective include inventory, software delivery, software distribution, software catalog, and both software and hardware management.
I use this mainly to capture inventory for IBM products, and as BigFix was part of IBM, it gets easily integrated with IBM solutions.
BigFix supports something known as Patch Policies, which allows users to define that whenever critical patches are released, they should get evaluated against machines and automatically deploy them.
It incorporates AI for normal behavior detection, distinguishing unusual operations.
The product provides automation responses in case of a threat attack, severity assessments, centralized manageability, and comprehensive compliance features, resulting in reduced costs.
It includes machine learning to easily analyze data and detect complex threats across endpoints, networks, or clouds.
| Product | Market Share (%) |
|---|---|
| Cortex XDR by Palo Alto Networks | 3.3% |
| BigFix | 1.1% |
| Other | 95.6% |

| Company Size | Count |
|---|---|
| Small Business | 30 |
| Midsize Enterprise | 12 |
| Large Enterprise | 66 |
| Company Size | Count |
|---|---|
| Small Business | 43 |
| Midsize Enterprise | 20 |
| Large Enterprise | 44 |
HCL BigFix is a powerful patch management tool that enables organizations to simply control their patch management operations. It is designed so that IT security and operations teams can collaborate in the most effective way possible. Users that employ BigFix can find and fix issues with their endpoints faster than those that employ its competitors. It comes with thousands of security checks that can be deployed quickly and easily. These enable users to safeguard themselves from a wide variety of digital threats.
HCL BigFix Benefits
Some of the ways that organizations can benefit by choosing to deploy HCL BigFix include:
BigFix Features
Reviews from Real Users
HCL BigFix is a highly effective solution that stands out when compared to most of its competitors. Two major advantages it offers are its auto-patching capability and its user-friendly tools.
Santhosh K., the chief executive officer of Catnip Infotech Private Limited, writes, “The second valuable feature is, BigFix also has an auto patch updating feature, where the latest patches, and what is required for my system are automatically downloaded and kept ready for me. The solution applies the patch and notifies me after applying the patch. BigFix also gives me a ping saying that I should reset my system within a certain period of time, while the patch is being applied. Let's say, the patch is being applied and if there's an issue, the solution can revoke the applied patch, and revert back to the old state.”
Benedikt S., an application administrator, says, “It's very straightforward. The usability is very close to everyday technical tools that you use as a systems administrator. So it's quite user-friendly.”
Cortex XDR by Palo Alto Networks delivers comprehensive endpoint security, integrating well with other systems to offer robust threat detection and real-time protection through AI-driven analytics.
Cortex XDR by Palo Alto Networks offers advanced endpoint protection and threat detection through AI and behavior-based analytics. Its user-friendly design simplifies integration with firewalls, delivering multi-layered protection with low resource consumption. Valued for policy management, USB control, and incident correlation, Cortex XDR enhances threat management and real-time threat hunting capabilities. However, users note challenges with third-party integration, reporting, and dashboard automation. Agent performance across operating systems and memory consumption are areas for improvement, alongside reducing false positives and simplifying endpoint management and setup.
What features does Cortex XDR offer?
What benefits should be considered in reviews?
Cortex XDR is crucial in industries requiring robust endpoint protection, such as finance, healthcare, and technology. It supports malware detection, behavioral analysis, and ransomware mitigation across endpoints, including remote work environments, providing comprehensive threat visibility and security policy management. The solution's integration with firewalls and specialized industry requirements enhances security posture in diverse operational settings.
We monitor all Endpoint Protection Platform (EPP) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.