Try our new research platform with insights from 80,000+ expert users

Cortex XSIAM vs Swimlane comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XSIAM
Average Rating
8.6
Reviews Sentiment
6.7
Number of Reviews
15
Ranking in other categories
Security Information and Event Management (SIEM) (13th), Identity Threat Detection and Response (ITDR) (6th), AI-Powered Cybersecurity Platforms (7th)
Swimlane
Average Rating
7.6
Reviews Sentiment
7.0
Number of Reviews
10
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (10th), AI-Powered Security Automation (3rd)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Cortex XSIAM is designed for Security Information and Event Management (SIEM) and holds a mindshare of 2.0%, down 2.6% compared to last year.
Swimlane, on the other hand, focuses on Security Orchestration Automation and Response (SOAR), holds 2.9% mindshare, down 3.4% since last year.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
Cortex XSIAM2.0%
Splunk Enterprise Security7.2%
Wazuh5.8%
Other85.0%
Security Information and Event Management (SIEM)
Security Orchestration Automation and Response (SOAR) Mindshare Distribution
ProductMindshare (%)
Swimlane2.9%
Microsoft Sentinel12.2%
Palo Alto Networks Cortex XSOAR8.8%
Other76.1%
Security Orchestration Automation and Response (SOAR)
 

Featured Reviews

JohnTamakloe - PeerSpot reviewer
Solutions Architect at ostec
Efficient coordination improves operations with seamless integration and rapid automation
The typical use cases for Cortex XSIAM are diverse I would describe the impact of Cortex XSIAM's automation on my security operations center as efficient. I use Cortex XSIAM's behavior analytics, and it helps identify unusual activities. I leverage Cortex XSIAM's incident management features for…
MD
Software Engineer III at a financial services firm with 10,001+ employees
Task persistence and integration ease have been key benefits
The best part of Swimlane is the persistent notifications and its ease of integration, requiring minimal coding. While it lacks response features, it can be integrated with messaging or queue services to achieve this. Any incident response requires additional integration since Swimlane itself doesn't react to incidents. Real-time data in terms of persistence is configurable, and without config, tasks persist indefinitely until completion. If using Appian versions below 11, integration features for Swimlane aren't available. By default, Swimlane lacks built-in intelligence, needing coding for integration. Although the Swimlane is beneficial and reduces manpower requirements, it's hindered by its lack of exposure. If exposed through services or endpoints, its functionality could be accessed without needing a local standalone application. On a scale of one to ten, this solution deserves a rating of nine.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable aspect is that Cortex XSIAM doesn't generate excessive alerts, refines all search results effectively, and filters out incidents where SOC intervention isn't necessary, allowing engineers to focus only on what matters."
"The flexibility for creating manual workflows stands out."
"The most valuable features of Cortex XSIAM are the machine learning used to identify threats, the complexity of the environment of products, and efficiency."
"The most valuable feature is the integration capability."
"It is an effective solution in terms of performance and functionalities."
"I would give Cortex XSIAM a rating of ten out of ten."
"The product integrates seamlessly with third-party solutions."
"It does a better job of identifying anomalies that are more likely to be incidents of compromise without as many false positives or false negatives."
"On a scale of one to ten, this solution deserves a rating of nine."
"Our primary goal was to reduce analyst time, and we have been successful in that."
"The most valuable feature of the solution is the support."
"The technical support from Swimlane is very good."
"This is the best SOAR product available on the market right now and I recommend it."
"Swimlane is a very effective way to represent workflows involving multiple users."
"Swimlane saves us 80 to 90 percent of our time by quickly helping us design the journey and efficiently passing information to various components."
"It provides us with a single portal for our logs from different solutions."
 

Cons

"The support could be a bit faster."
"I am not sure if any improvements are needed right now."
"Cortex XSIAM needs improvements in terms of data onboarding, parsers, and third-party integration supports."
"Cortex XSIAM is pretty expensive, and the licensing process is not very comfortable compared to CrowdStrike."
"Further integration capabilities with various other software products that can seamlessly tie into Cortex XSIAM would be advantageous."
"Cortex XSIAM is on the expensive side and requires substantial improvement in pricing."
"There is room for improvement in expanding integrations to include more cybersecurity solutions."
"The solution’s pricing and technical support could be improved."
"The stability of the solution has room for improvement."
"One of the disadvantages of Swimlane is that to manage the platform, we need hardcore developers."
"There is a need for enhanced version control in Swimlane. Currently, our version does not support it, making it tough to move changes between environments during significant updates."
"The initial setup and deployment are complex."
"We faced a lot of issues with the product’s stability."
"The initial setup and deployment are complex."
"Swimlane's search bar is not working effectively, and there is no option to differentiate between two cases at the same time."
"I would prefer to have more colors added to represent different risks or notations, which can be used for the prioritization of risks and the significance of information."
 

Pricing and Cost Advice

"The solution comes at a significant cost."
"In terms of pricing, we found Cortex XSIAM to offer a very reasonable and competitive rate."
"The solution is expensive compared to its competitors."
"The product cost could be considered value for money compared to other solutions in the market, though it is quite high."
"Since Palo Alto is trying to get as many new customers as possible, they're offering very competitive pricing."
Information not available
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
884,933 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
11%
Financial Services Firm
10%
Manufacturing Company
10%
Government
6%
Financial Services Firm
13%
Manufacturing Company
12%
Computer Software Company
10%
Government
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise2
Large Enterprise4
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise1
Large Enterprise6
 

Questions from the Community

What is your experience regarding pricing and costs for Cortex XSIAM?
I did not participate in pricing discussions for Cortex XSIAM solutions, so I cannot provide a review regarding prices for this solution.
What needs improvement with Cortex XSIAM?
Cortex XSIAM is on the expensive side and requires substantial improvement in pricing. There are other features that could be improved, including integration with vendors such as CyberArk. I would ...
What is your primary use case for Cortex XSIAM?
With Cortex XSIAM, we installed an agent on Active Directory on-premise. We connected our Firewalls to the Data Lake and the Active Directory, and protected the Firewalls with another authenticatio...
What needs improvement with Swimlane?
One of the disadvantages of Swimlane is that to manage the platform, we need hardcore developers. We have recently seen new products such as Tines and Blink Ops coming into the market, where a pers...
What is your primary use case for Swimlane?
We are using Swimlane for automation purposes and security orchestration. We are using Swimlane's Playbook Automation. One of the major playbooks that we use in Swimlane is for phishing email autom...
What advice do you have for others considering Swimlane?
I would rate Swimlane a seven out of ten as a product.
 

Overview

 

Sample Customers

Information Not Available
LinkedIn, TransUnion, Citrix, Aetna, Perspecta
Find out what your peers are saying about Splunk, Wazuh, IBM and others in Security Information and Event Management (SIEM). Updated: March 2026.
884,933 professionals have used our research since 2012.