Try our new research platform with insights from 80,000+ expert users

Cortex XSIAM vs ServiceNow Security Operations comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XSIAM
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
13
Ranking in other categories
Security Information and Event Management (SIEM) (15th), Identity Threat Detection and Response (ITDR) (5th), AI-Powered Cybersecurity Platforms (7th)
ServiceNow Security Operations
Average Rating
8.0
Reviews Sentiment
6.7
Number of Reviews
22
Ranking in other categories
Security Incident Response (1st), Security Orchestration Automation and Response (SOAR) (5th), Risk-Based Vulnerability Management (10th)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Cortex XSIAM is designed for Security Information and Event Management (SIEM) and holds a mindshare of 2.9%, up 1.4% compared to last year.
ServiceNow Security Operations, on the other hand, focuses on Security Incident Response, holds 14.6% mindshare, down 14.9% since last year.
Security Information and Event Management (SIEM)
Security Incident Response
 

Featured Reviews

AKASH MAJUMDER - PeerSpot reviewer
Incident response times have significantly reduced with efficient device integration and log parsing capabilities
Cortex XSIAM needs improvements in terms of data onboarding, parsers, and third-party integration supports. Additionally, a future update request is to enable tagging of endpoints in groups, similar to a feature available in Cortex XDR. The AI analytics need fine-tuning because some use cases are not working from my side.
George Devasia - PeerSpot reviewer
Communication and organization improve support teams and works well with enterprises
I use ServiceNow for ticketing purposes. Specifically, I raise tickets between the support team. This is used by internal teams within the company for managing support-related tasks ServiceNow is a convenient platform to raise tickets, and the respective support team will contact us to resolve…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The automation capabilities significantly improve response times by allowing us to respond to incidents from a single dashboard rather than navigating multiple dashboards."
"It operates on a single, extensive database which enables it to excel in detecting threats and anomalies across the network and endpoints, delivering a highly effective and comprehensive security solution."
"The most valuable feature is the integration capability."
"The flexibility for creating manual workflows stands out."
"Since implementing Cortex XSIAM, incident response times have been significantly reduced by approximately twenty percent."
"Its ability to deliver a substantial amount of security intelligence greatly enhances and optimizes our security operations program."
"Cortex XSIAM enhances our ability to apply endpoint protection policies, implement restrictions, conduct scans, and engage in sandboxing."
"It does a better job of identifying anomalies that are more likely to be incidents of compromise without as many false positives or false negatives."
"The "follow" feature is really good. If the user is not responding, there's an option to "follow". Just click on the button, and it will automatically trigger an email to the end user."
"The solution is available over the cloud and is easy to manage."
"The solution is stable."
"​Integration to other security tools allows for a consolidated view of all vulnerabilities, incidents, etc. for all sorts of leverage in a single platform to assess governance risk and compliance as well as an enhanced, enriched intelligence.​"
"Multiple projects use the ServiceNow tool because it is a low-cost and open-source tool."
"I will recommend it to others as it is an enterprise application used by large companies for ticketing purposes."
"ServiceNow Security Operations provides significant control over vulnerabilities, allowing users to mark false alarms as false positives and ignore them, which is important because many vulnerabilities are not real but appear as such."
"Reduces time to closure and closure metrics for vulnerabilities."
 

Cons

"The standard integrations are very limited, and the integrations available are not listed in the marketplace."
"Cortex XSIAM is pretty expensive, and the licensing process is not very comfortable compared to CrowdStrike."
"The solution’s pricing and technical support could be improved."
"Cortex XSIAM needs improvements in terms of data onboarding, parsers, and third-party integration supports."
"Further integration capabilities with various other software products that can seamlessly tie into Cortex XSIAM would be advantageous."
"The support could be a bit faster."
"It could provide more integration with a large variety of products."
"The platform isn't very developer-friendly and it should provide more flexibility and ease."
"The dashboard and playbook creation will need to improve"
"It's very slow. When you click a button or update a field, it takes forever to actually react."
"There is room for improvement in terms of developer support and documentation."
"Report generation within ServiceNow can take some time. Additionally, there are occasional issues when raising a ticket, which can also consume time."
"We'd like customization to be easier in terms of the UI and using the dashboards."
"Customer awareness and understanding of ServiceNow's SecOps capabilities could be improved."
"The solution needs to make customization easier. You cannot do much customization immediately. It requires an extensive workload. If the customization process was user-friendly, it would be much better."
"​Process framework and best practices for ease of integration between IT and security teams via incident, problem, and change.​"
 

Pricing and Cost Advice

"The solution is expensive compared to its competitors."
"The solution comes at a significant cost."
"Since Palo Alto is trying to get as many new customers as possible, they're offering very competitive pricing."
"In terms of pricing, we found Cortex XSIAM to offer a very reasonable and competitive rate."
"The product cost could be considered value for money compared to other solutions in the market, though it is quite high."
"Compared to competitor tools, ServiceNow Security Operations is more affordable"
"The solution is more expensive than BMC Remedy, the other ITSM tool available in the market."
"The product is more expensive than other solutions."
"This product is a good value for the money."
"It is an expensive product."
"If you're going to implement it on your own, there would be internal costs. If you're going to implement it through a contractor or consultant, you have to pay for that."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
865,295 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
13%
Manufacturing Company
10%
Financial Services Firm
10%
Government
7%
Financial Services Firm
20%
Manufacturing Company
13%
Computer Software Company
9%
Government
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Cortex XSIAM?
It is an effective solution in terms of performance and functionalities.
What is your experience regarding pricing and costs for Cortex XSIAM?
The licensing cost of Cortex XSIAM is more or less the same as Splunk, making it quite expensive compared to other tools. There are additional expenses for more functionalities.
What needs improvement with Cortex XSIAM?
Cortex XSIAM needs improvements in terms of data onboarding, parsers, and third-party integration supports. Additionally, a future update request is to enable tagging of endpoints in groups, simila...
What do you like most about ServiceNow Security Operations?
The most valuable aspect of working with ServiceNow is its meaningful and feature-rich product.
What is your experience regarding pricing and costs for ServiceNow Security Operations?
The product is more expensive than other solutions like Archer but offers more features, making the pricing justifiable.
What needs improvement with ServiceNow Security Operations?
In terms of improvements, there are several things that could enhance ServiceNow Security Operations in the future, especially regarding false positives or exceptions, which usually require filling...
 

Overview

 

Sample Customers

Information Not Available
DXC Technology, Freedom Security Alliance, Prime Therapeutics, Seton Hall University, York Risk Services
Find out what your peers are saying about Splunk, Wazuh, Microsoft and others in Security Information and Event Management (SIEM). Updated: August 2025.
865,295 professionals have used our research since 2012.