Try our new research platform with insights from 80,000+ expert users

Cortex XSIAM vs Swimlane comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XSIAM
Average Rating
8.6
Reviews Sentiment
6.7
Number of Reviews
15
Ranking in other categories
Security Information and Event Management (SIEM) (12th), Identity Threat Detection and Response (ITDR) (7th), AI-Powered Cybersecurity Platforms (7th)
Swimlane
Average Rating
7.6
Reviews Sentiment
7.0
Number of Reviews
10
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (10th), AI-Powered Security Automation (3rd)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Cortex XSIAM is designed for Security Information and Event Management (SIEM) and holds a mindshare of 2.1%, down 2.5% compared to last year.
Swimlane, on the other hand, focuses on Security Orchestration Automation and Response (SOAR), holds 2.9% mindshare, down 3.3% since last year.
Security Information and Event Management (SIEM) Market Share Distribution
ProductMarket Share (%)
Cortex XSIAM2.1%
Splunk Enterprise Security7.1%
Wazuh6.4%
Other84.4%
Security Information and Event Management (SIEM)
Security Orchestration Automation and Response (SOAR) Market Share Distribution
ProductMarket Share (%)
Swimlane2.9%
Microsoft Sentinel12.4%
Palo Alto Networks Cortex XSOAR9.0%
Other75.7%
Security Orchestration Automation and Response (SOAR)
 

Featured Reviews

reviewer2666148 - PeerSpot reviewer
Associate Director at a financial services firm with 5,001-10,000 employees
Integration challenges highlight the need for manual workflows
The standard integrations are very limited, and the integrations available are not listed in the marketplace. Obtaining validation for integrations from Palo Alto takes around eight months, which is quite long. The solution would benefit from having more standard playbooks and templates available, as in other partners. Currently, everything must be created from scratch. In terms of incident response automation, it is quite poor due to the lack of integration with all security tools, making manual intervention necessary.
MD
Software Engineer III at a financial services firm with 10,001+ employees
Task persistence and integration ease have been key benefits
The best part of Swimlane is the persistent notifications and its ease of integration, requiring minimal coding. While it lacks response features, it can be integrated with messaging or queue services to achieve this. Any incident response requires additional integration since Swimlane itself doesn't react to incidents. Real-time data in terms of persistence is configurable, and without config, tasks persist indefinitely until completion. If using Appian versions below 11, integration features for Swimlane aren't available. By default, Swimlane lacks built-in intelligence, needing coding for integration. Although the Swimlane is beneficial and reduces manpower requirements, it's hindered by its lack of exposure. If exposed through services or endpoints, its functionality could be accessed without needing a local standalone application. On a scale of one to ten, this solution deserves a rating of nine.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Since implementing Cortex XSIAM, incident response times have been significantly reduced by approximately twenty percent."
"Cortex XSIAM enhances our ability to apply endpoint protection policies, implement restrictions, conduct scans, and engage in sandboxing."
"The most valuable features of Cortex XSIAM are the machine learning used to identify threats, the complexity of the environment of products, and efficiency."
"The product integrates seamlessly with third-party solutions."
"It does a better job of identifying anomalies that are more likely to be incidents of compromise without as many false positives or false negatives."
"One of the valued aspects of the product is its use of artificial intelligence to detect security vulnerabilities."
"The way the solution responds to detections and warnings is really impressive."
"One of the valued aspects of the product is its use of artificial intelligence to detect security vulnerabilities."
"Swimlane enables two SOC analysts to work efficiently as much as ten analysts would without Swimlane, which translates to significant manpower savings."
"Swimlane saves us 80 to 90 percent of our time by quickly helping us design the journey and efficiently passing information to various components."
"On a scale of one to ten, this solution deserves a rating of nine."
"The most valuable feature of the solution is the support."
"The technical support from Swimlane is very good."
"We are using it for a SOAR platform at a Cyber Security company which is MSSP."
"Swimlane is a very effective way to represent workflows involving multiple users."
"Our primary goal was to reduce analyst time, and we have been successful in that."
 

Cons

"The support could be a bit faster."
"Cortex XSIAM is on the expensive side and requires substantial improvement in pricing."
"It could provide more integration with a large variety of products."
"The standard integrations are very limited, and the integrations available are not listed in the marketplace. Obtaining validation for integrations from Palo Alto takes around eight months, which is quite long."
"Cortex XSIAM needs improvements in terms of data onboarding, parsers, and third-party integration supports."
"The platform isn't very developer-friendly and it should provide more flexibility and ease."
"Cortex could improve the detection and online resolution of security vulnerabilities."
"There is room for improvement in expanding integrations to include more cybersecurity solutions."
"We faced a lot of issues with the product’s stability."
"There is a need for enhanced version control in Swimlane. Currently, our version does not support it, making it tough to move changes between environments during significant updates."
"Swimlane is not scalable because it is not exposed. Currently, it's a manual component that requires configuration through coding."
"I would prefer to have more colors added to represent different risks or notations, which can be used for the prioritization of risks and the significance of information."
"I would like to see improvements in the minor bugs that occur with each update, as some features might have issues."
"One of the disadvantages of Swimlane is that to manage the platform, we need hardcore developers."
"The stability of the solution has room for improvement."
"The initial setup and deployment are complex."
 

Pricing and Cost Advice

"The solution comes at a significant cost."
"The solution is expensive compared to its competitors."
"The product cost could be considered value for money compared to other solutions in the market, though it is quite high."
"Since Palo Alto is trying to get as many new customers as possible, they're offering very competitive pricing."
"In terms of pricing, we found Cortex XSIAM to offer a very reasonable and competitive rate."
Information not available
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
881,665 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
11%
Financial Services Firm
10%
Manufacturing Company
9%
Government
7%
Financial Services Firm
13%
Computer Software Company
11%
Manufacturing Company
10%
Government
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise2
Large Enterprise4
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise1
Large Enterprise6
 

Questions from the Community

What is your experience regarding pricing and costs for Cortex XSIAM?
I did not participate in pricing discussions for Cortex XSIAM solutions, so I cannot provide a review regarding prices for this solution.
What needs improvement with Cortex XSIAM?
Cortex XSIAM is on the expensive side and requires substantial improvement in pricing. There are other features that could be improved, including integration with vendors such as CyberArk. I would ...
What is your primary use case for Cortex XSIAM?
With Cortex XSIAM, we installed an agent on Active Directory on-premise. We connected our Firewalls to the Data Lake and the Active Directory, and protected the Firewalls with another authenticatio...
What needs improvement with Swimlane?
One of the disadvantages of Swimlane is that to manage the platform, we need hardcore developers. We have recently seen new products such as Tines and Blink Ops coming into the market, where a pers...
What is your primary use case for Swimlane?
We are using Swimlane for automation purposes and security orchestration. We are using Swimlane's Playbook Automation. One of the major playbooks that we use in Swimlane is for phishing email autom...
What advice do you have for others considering Swimlane?
I would rate Swimlane a seven out of ten as a product.
 

Overview

 

Sample Customers

Information Not Available
LinkedIn, TransUnion, Citrix, Aetna, Perspecta
Find out what your peers are saying about Splunk, Wazuh, IBM and others in Security Information and Event Management (SIEM). Updated: January 2026.
881,665 professionals have used our research since 2012.