Try our new research platform with insights from 80,000+ expert users

Cortex XSIAM vs Sentinel comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
5.7
Organizations using Cortex XSIAM saw significant ROI and improved incident management through automation, though results vary short-term.
Sentiment score
7.5
Sentinel enhanced efficiency, resource allocation, productivity, and financial gains with a user-friendly interface and robust functionality.
 

Customer Service

Sentiment score
6.1
Customer service differs for Cortex XSIAM: Premium support is favored; other tiers vary in efficiency and responsiveness.
Sentiment score
8.0
Micro Focus technical support varies from needing multiple emails to being very good, while Microsoft's support is generally effective.
Premium support provides direct access, while distributor support quality can vary.
It is ineffective in terms of responding to basic queries and addressing future requirements.
The Palo Alto support team is fully responsive and helpful.
 

Scalability Issues

Sentiment score
6.8
Cortex XSIAM is praised for scalability and flexibility, though some desire improved on-premises options and integration capabilities.
Sentiment score
7.5
Sentinel's high scalability, cost-effectiveness, and seamless cloud integration make it popular among large enterprises, educational institutions, and SMBs.
Without proper integration, scaling up with more servers is meaningless.
Cortex XSIAM is highly scalable.
 

Stability Issues

Sentiment score
7.5
Cortex XSIAM is highly stable, despite occasional issues, praised for reliability, installation ease, and performance across environments.
Sentiment score
8.5
Sentinel is highly stable and reliable, supporting 5,000 events per second, but can experience occasional region-specific outages during fixes.
The product was easy to install and set up and worked right.
Overall, Cortex XSIAM is stable.
 

Room For Improvement

Cortex XSIAM needs better integration, user interface, and performance, with improvements in vulnerability detection, support, and licensing options.
Sentinel requires enhancements in scripting, integration, security, user interface, customization, vendor support, and reducing region-specific outages.
Cortex XSIAM needs improvements in terms of data onboarding, parsers, and third-party integration supports.
In terms of incident response automation, it is quite poor due to the lack of integration with all security tools, making manual intervention necessary.
Cortex XSIAM is pretty expensive, and the licensing process is not very comfortable compared to CrowdStrike.
 

Setup Cost

Cortex XSIAM's competitive pricing faces mixed reviews, with additional costs for add-ons and integration despite perceived value.
The licensing cost of Cortex XSIAM is more or less the same as Splunk, making it quite expensive compared to other tools.
Cortex XSIAM is pretty expensive, and the licensing process is not very comfortable.
The first impression is that XSIAM would be more expensive than others we tried.
 

Valuable Features

Cortex XSIAM offers advanced SOAR capabilities, enhancing security with machine learning, automation, and efficient threat detection without extensive logs.
Sentinel excels in log monitoring, threat detection, automation, cloud security, and offers a user-friendly interface with advanced analysis tools.
One of the valued aspects of the product is its use of artificial intelligence to detect security vulnerabilities.
Cortex XSIAM allows us to onboard almost every device, whether they are on-prem or on SaaS.
Cortex XSIAM is able to detect abnormal behavior of malicious code and subsequently block it.
 

Categories and Ranking

Cortex XSIAM
Ranking in Security Information and Event Management (SIEM)
15th
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
13
Ranking in other categories
Identity Threat Detection and Response (ITDR) (5th), AI-Powered Cybersecurity Platforms (7th)
Sentinel
Ranking in Security Information and Event Management (SIEM)
13th
Average Rating
7.6
Reviews Sentiment
7.3
Number of Reviews
16
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of August 2025, in the Security Information and Event Management (SIEM) category, the mindshare of Cortex XSIAM is 2.9%, up from 1.4% compared to the previous year. The mindshare of Sentinel is 3.6%, up from 2.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM)
 

Featured Reviews

AKASH MAJUMDER - PeerSpot reviewer
Incident response times have significantly reduced with efficient device integration and log parsing capabilities
Cortex XSIAM needs improvements in terms of data onboarding, parsers, and third-party integration supports. Additionally, a future update request is to enable tagging of endpoints in groups, similar to a feature available in Cortex XDR. The AI analytics need fine-tuning because some use cases are not working from my side.
JaideepSingh - PeerSpot reviewer
An automated solution that helped me detect threats in less than half the time it used to take
Sentinel gave us logs to tell us what's going right and wrong in your environment so we could secure the network. We also got multiple kinds of logs. By running some queries from the logs, we could find and fix the anomalies in the environment. Sentinel's threat visibility was great at telling us if we had something going on in our environment. We had to set up alerts in our environment based on the logs. If we had the right alerts set up, we got notified about threats and where security was lacking, so we could also take care of that. Sentinel's threat intelligence helped us prepare and take proactive steps for potential threats before they hit. Having preparation before a threat has helped our security operations. When I was using it, I used to keep going into my dashboards and looking for any threats on a weekly basis, or maybe two or three times a week. Based on that, we would recommend certain changes to the server and infrastructure teams to block or allow some ports. Sentinel's threat intelligence helped plan security against risks.
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
865,295 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
13%
Manufacturing Company
10%
Financial Services Firm
10%
Government
7%
Computer Software Company
13%
Financial Services Firm
9%
Manufacturing Company
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Cortex XSIAM?
It is an effective solution in terms of performance and functionalities.
What is your experience regarding pricing and costs for Cortex XSIAM?
The licensing cost of Cortex XSIAM is more or less the same as Splunk, making it quite expensive compared to other tools. There are additional expenses for more functionalities.
What needs improvement with Cortex XSIAM?
Cortex XSIAM needs improvements in terms of data onboarding, parsers, and third-party integration supports. Additionally, a future update request is to enable tagging of endpoints in groups, simila...
What do you like most about NetIQ Sentinel?
The solution lets us get all the logs properly and regularly monitor customer infrastructure.
What needs improvement with NetIQ Sentinel?
There are still a few vendor-specific devices for which Sentinel needs to work on integration, such as Netskope devices. Also, we often face region-wise outages during operation due to product team...
 

Also Known As

No data available
NetIQ Sentinel, Novell SIEM
 

Overview

 

Sample Customers

Information Not Available
Faysal Bank, GaVI, Handelsbanken, ISC Mªnster, Lambeth Council, Swisscard, The Municipality of Siena, Tukes, University of Dayton, University of the Sunshine Coast
Find out what your peers are saying about Cortex XSIAM vs. Sentinel and other solutions. Updated: July 2025.
865,295 professionals have used our research since 2012.