No more typing reviews! Try our Samantha, our new voice AI agent.
Bandi Rakesh - PeerSpot reviewer
Cyber Security Analyst at HALA INFOSEC
Real User
Top 20
Sep 1, 2024
Helps find bugs and prevents attacks by hackers
Pros and Cons
  • "The solution helps find bugs, and it is safe to use to prevent attacks by hackers."
  • "The solution should add unwanted malicious hash values to a block list so that whenever the action is triggered, it will automatically prevent the malicious content."

What is our primary use case?

We use the solution to deduct from the endpoints any files in the network or any suspicious thing happening in the host machine or servers. We have the Palo Alto Networks Firewall team, and we check the connection from the Palo Alto Networks Firewalls using Cortex XDR by collecting all the information.

What is most valuable?

The best thing about Cortex XDR is that it has host servers, networks, and proxy servers. On the other hand, CrowdStrike has only hosts and servers. The solution helps find bugs, and it is safe to use to prevent attacks by hackers.

What needs improvement?

The solution should add unwanted malicious hash values to a block list so that whenever the action is triggered, it will automatically prevent the malicious content. We can even block the IP address in malicious content. If any host is affected, we can isolate the host, rectify that problem, and prevent it from happening in the future.

For how long have I used the solution?

I have been using Cortex XDR by Palo Alto Networks for one year.

Buyer's Guide
Cortex XDR by Palo Alto Networks
August 2026
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
911,493 professionals have used our research since 2012.

What do I think about the scalability of the solution?

More than 15,000 people are using the solution in our organization.

How are customer service and support?

We contacted the technical support team for a downgrade issue with Cortex XDR. Due to some network errors, we worked with the support team. They rectified the problem, but it affected us for over two hours. We had to check all the hosts and servers connected to Cortex XDR. We rechecked and reinstalled Cortex XDR. I was happy with the support team’s fast response time.

Which solution did I use previously and why did I switch?

We are also using CrowdStrike. Compared to CrowdStrike, Cortex XDR gives more detailed information for us to work with. We can connect to the host's live terminal, work with that host in an emergency, and prevent that host.

How was the initial setup?

The solution's ease of deployment depends on the user's experience. It would be easy for someone with experience.

What's my experience with pricing, setup cost, and licensing?

Compared to CrowdStrike, Cortex XDR is an expensive solution.

What other advice do I have?

A beginner will take some time to learn to use the solution. I would recommend the solution to other users.

Overall, I rate the solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Saleh Bala Doma - PeerSpot reviewer
Head Of Information Technology at Diha Travels and Tours Limited
Real User
Top 20
Sep 6, 2024
Helpful for incident detection and response
Pros and Cons
  • "It is an easy-to-use tool."
  • "I would like to see improvement in the tool's user interface, particularly in the area of managing alerts and providing more reporting capabilities."

What is our primary use case?

I use the solution in my company for incident detection and response. We use it to address specific security challenges at work, like detecting and responding to incidents.

What is most valuable?

The most valuable feature of the solution stems from the fact that the tool provides real-time visibility of our network activity and allows us to detect threats early and respond quickly. It is an easy-to-use tool. The tool's interface is good and simple to use.

What needs improvement?

I would like to see improvement in the tool's user interface, particularly in the area of managing alerts and providing more reporting capabilities. The user interface should include a built-in compliance framework, and I think it will make the tool even more valuable for organizations with statistical regulatory requirements.

For how long have I used the solution?

I have been using Cortex XDR by Palo Alto Networks for two years. I don't remember the version of the solution. I am a customer of the tool.

What do I think about the scalability of the solution?

Around three people in my company use the tool.

How are customer service and support?

I have contacted the solution's technical support once. I know of the support team, but I don't think we have ever contacted them multiple times.

Which solution did I use previously and why did I switch?

Although I have some experience in some intrusion detection software, I have not used them practically, such as Cortex XDR.

How was the initial setup?

The product's initial setup phase is not difficult to do. Anyone can follow the tool's manual to install it.

What's my experience with pricing, setup cost, and licensing?

The tool's price is moderate.

What other advice do I have?

I can recommend the tool to others, especially to organizations that need a robust integration solution for threats, detection, and response.

The tool is easy to learn as the interface is simple to understand, especially if you have some experience with server security and a little bit of knowledge of it. It is a very easy-going platform.

I rate the tool a nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Cortex XDR by Palo Alto Networks
August 2026
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
911,493 professionals have used our research since 2012.
Mohammad Qaw - PeerSpot reviewer
Senior Security Consultant at helpag
MSP
Dec 30, 2022
Perfect correlation and XDR capabilities for network traffic plus endpoint security
Pros and Cons
  • "From a single pane of glass, you can easily manage all of your endpoints."
  • "The solution should force customers to integrate with network traffic to see the full benefits of XDR."

What is our primary use case?

Our company uses the solution for endpoint protection, detection, and response. The solution has antivirus and EDR capabilities. Our SOC analysts use it to investigate incidents. We currently have 300 to 400 users with two admins for management. The solution is installed on all user laptops to protect workstations.

We also implement the solution for customers as a service. Most customers buy the solution for registry reasons and compliance standards. It gives you all the compliance points and improves how your SOC functions because it provides comprehensive visibility over the entire network and endpoints. It is called XDR because it not only looks at endpoints but also network traffic. 

The solution is offered on Palo Alto's private network. I think the underlying provider is Google Cloud, but that doesn't really matter. You are asked the region of your instance for connection such as Europe or the Middle East. 

What is most valuable?

The solution perfectly correlates with Palo Alto's Networks Firewall to perform XDR capabilities such as network traffic plus endpoint security. This is what distinguishes the solution from other products. 

From a single pane of glass, you can easily manage all of your endpoints.

The dashboard is intuitive so you can easily investigate or track incidents. 

The solution has a fair amount of integrations with certain intelligence tools or third-party products. 

What needs improvement?

The solution should force customers to integrate with network traffic to see the full benefits of XDR. If you are not integrating it or feeding in your network traffic, then you are just buying a normal antivirus which doesn't make any sense. You are paying double the price to use the antivirus feature or to say you have XDR, but in reality you are not using it. 

The solution should include an on-premises option because some customers want only on-premises. It would be hard, but good to do if possible. 

Open XDR would be beneficial in the future. Right now, the solution is Closed XDR so cannot communicate with the few new vendors in the Open XDR market. 

For how long have I used the solution?

I have been using the solution more than two years. 

The solution used to be called Traps when it was on-premises only. It was rebranded as Cortex XDR when it became a cloud solution. 

What do I think about the stability of the solution?

The solution is stable so I rate stability a nine out of ten. 

What do I think about the scalability of the solution?

The solution is very scalable. You can have 500 users and scale tomorrow to 10,000 with no extra work but just purchasing the licenses needed. 

I rate scalability a ten out of ten. 

How are customer service and support?

The level of support fluctuates but on average is rated an eight out of ten. 

How would you rate customer service and support?

Positive

How was the initial setup?

The setup is very easy because it is a cloud solution. You just log in and use it immediately. I rate setup a nine out of ten. 

What about the implementation team?

We are a third-party integrator and implement the solution for customers. One staff person can handle an implementation. 

As a customer, you receive a link which is your tenant for login. From there, deployment time is just how long it takes to get the installer agent and put on all of your endpoints. For example, if you are a corporation that has 300 laptops, then you install the agent on each and every server. 

You will need about three hours to configure the solution and then it is up to your admins to install the agent on all endpoints. There is usually a way to automatically install agents from the Active Directory or other tools.

You need to integrate your network traffic to the XDR itself. If you have a Palo Alto Firewall, it is easy to navigate through integration. If you have FortiGate or Cisco firewalls, then you can configure the firewall to send the log to the cloud. It is sometimes hard to convince customers to send or keep their logs on the cloud. 

What's my experience with pricing, setup cost, and licensing?

The solution has one subscription for endpoint protection and one subscription for detection and response. The two licenses combined give you the BRO version. 

The solution is neither inexpensive nor expensive, so I rate pricing a three out of ten. 

Which other solutions did I evaluate?

Nowadays, CrowdStrike, Cortex XDR, and the solution are rebranding and selling their products as XDR. Everyone hears about antivirus but now XDR is available to protect endpoints and get intelligence from the network. 

Most customers who have an XDR product only use the antivirus features. They are not correlating the network traffic with the XDR itself, so they are not getting the full benefit. 

The solution does not force you to correlate so you can use it without integrating with your network. But again, this is not how XDR is supposed to work. 

For example, if you buy a Bugatti but only drive it at 80 kilometers per hour, then you should just go and buy a Nissan. If you buy XDR but do not integrate it with your network traffic, then you just have a Nissan antivirus. 

What other advice do I have?

I recommend the solution and rate it a ten out of ten. 

Which deployment model are you using for this solution?

Private Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Google
Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
Kush Kumar - PeerSpot reviewer
IT Specialist at RateGain IT Solutions Private Limited
Real User
Top 20
Sep 1, 2024
Scans for unwanted and malicious activity on endpoints and servers, creating alerts and incidents
Pros and Cons
  • "The most valuable features are incident creation, policy-based protection, IP whitelisting, and device encryption. These are beneficial for endpoint and server security."
  • "There's room for improvement with Mac device installations, which can be challenging."

What is our primary use case?

We use Cortex XDR by Palo Alto Networks for endpoint security. It scans for unwanted and malicious activity on endpoints and servers, creating alerts and incidents.

What is most valuable?

The most valuable features are incident creation, policy-based protection, IP whitelisting, and device encryption. These are beneficial for endpoint and server security.

What needs improvement?

There's room for improvement with Mac device installations, which can be challenging.

For how long have I used the solution?

I have been using the tool for two years. 

What do I think about the scalability of the solution?

About 20 people in our company use Cortex XDR by Palo Alto Networks across the country.

How was the initial setup?

We've had some issues isolating endpoints and have sought support from Palo Alto for that.

What's my experience with pricing, setup cost, and licensing?

The cost depends on your chosen license type, like Pro or other licenses.

What other advice do I have?

I'd recommend using Cortex XDR by Palo Alto Networks for security purposes. It's good at detecting malware and is a better strategy than other antivirus solutions. I rate the overall solution a seven out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Vyshnavi Jyothermai - PeerSpot reviewer
Sr. Endpoint Security Engineer at iOPEX Technologies
Real User
Aug 28, 2024
Easy-to-use and easy-to-install
Pros and Cons
  • "The tool is easy to use."
  • "When it comes to malware files, it should be a little quick because, at times, it would give a wrong result in the sense of what it might be on malware, even if it still might be a normal one."

What is our primary use case?

I am a tech support engineer or an endpoint security engineer who works with Cortex XDR's team itself, looking after all the support cases related to our technical stuff, specifically malware cases.

What is most valuable?

The most valuable feature of the solution is Broker VM, which is the best functionality, as I haven't found such a feature in any other product I have worked on till now.

What needs improvement?

Some feature requests are coming up from the customers. I feel like there should be a quick improvement. There is a little gap in implementing the tool's features as the team needs to do an investigation, which would take more time than expected, leaving the customers frustrated. The product team's investigation to decide on the features to be introduced in the solution should be a little quick. When it comes to malware files, it should be a little quick because, at times, it would give a wrong result in the sense of what it might be on malware, even if it still might be a normal one. At that point in time, we need to change the tool's version, and it generally needs to be changed from our end with Java and Jira. Maybe it should be a little improved in that case.

For how long have I used the solution?

I have been using Cortex XDR by Palo Alto Networks for two years. I am an endpoint security engineer for Cortex XDR's team. I worked with a client company as a foreign technical support engineer.

What do I think about the stability of the solution?

So far, I haven't found any stability issues in the tool. Right now, I am on post-maternity leave, so I left the company six or seven months ago. To date, I haven't found any stability issues with the tool. Stability-wise, I rate the solution an eight and a half out of ten.

The tool is not used in my organization because I work within the tool's XDR team related to Palo Alto. I don't have an exact count of the users because we have different customers on a larger scale.

What do I think about the scalability of the solution?

It is a scalable solution. Scalability-wise, I rate the solution a nine out of ten.

How are customer service and support?

I am not required to contact the solution's technical support since I handle the customers' tickets.

How was the initial setup?

My company was involved in mass deployment. I am not involved in the deployment stuff because we work as a break-and-fix team. We generally don't go ahead with a mass deployment. For individual deployment, it is a quick and easy-to-install tool. Cortex XDR by Palo Alto Networks is not like every other antivirus product, and I think it is an easy-to-install tool. There is a team for the tool to help you out, but certain pre-requirements need to be filled. If all the pre-requirements are met, there will be no issue with the installation.

What's my experience with pricing, setup cost, and licensing?

I am not sure about the tool's pricing because we are not from the accounts team. The tool's pricing is managed by the accounts department.

What other advice do I have?

I recommend the tool as it is an emerging or upcoming product with a set of features. My recommendation of the tool surely depends upon the scale of the business.

The tool is easy to use. We even have an accounts team where they can help you from scratch. We have a tech support team who would definitely suggest it to you over the session, so nothing as such is required as they will definitely help the users with the tool.

I rate the tool an eight and a half or nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Information Security Manager at a financial services firm with 1,001-5,000 employees
Real User
Feb 17, 2023
Numerous available AI modules and very effective communication methods
Pros and Cons
  • "The solution is a new generation XDR that has a lot of artificial intelligence modules."
  • "The server sometimes stops continuously to check things so it would be helpful to receive access updates or technical reasons."

What is our primary use case?

Our company uses the solution to detect behaviors and provide difficulty remediation for malware. The solution acts like a terminal that allows for the renewal of malware directly from the terminal in any meeting room. 

We also have an IOP configuration that allows us to compare our own indicators and compromise rules. This is very efficient because anytime there is an IAP release on the web page, we can update or create a repository of different notification alerts. 

What is most valuable?

The solution is a new generation XDR that has a lot of artificial intelligence modules. 

The solution's communication methods are very effective. 

Configuring or eradicating terminals is easy. 

What needs improvement?

The server sometimes stops continuously to check things so it would be helpful to receive access updates or technical reasons. 

For how long have I used the solution?

I have been using the solution for 18 months. 

How are customer service and support?

Technical support was very responsive. You can present a critical configuration issue and they provide a solution as quickly as possible. 

The Linux agent was a little bit sketchy on our side but we got good support. 

How was the initial setup?

The setup is very straightforward. 

What about the implementation team?

We implemented the solution in-house and worked with one telecom rep for network permissions. 

Two of our cybersecurity engineers deployed to 4,000 endpoints in two months. We had a little bit of an issue with Linux but resolved it so all endpoints were fully operational within three months. 

What's my experience with pricing, setup cost, and licensing?

The pricing is a little bit on the expensive side so is rated a seven out of ten. 

What other advice do I have?

The solution is solid and measures up against other products. I rate the solution an eight out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
EhabAli - PeerSpot reviewer
Sr. Cybersecurity Solutions Architect at BMB
Real User
Dec 13, 2022
It provides a whole new level of visibility and integrates with most other vendors
Pros and Cons
  • "Cortex covers everything I need. It's a perfect solution. Cortex provides a different level of visibility because it's an extended EDR, allowing you to grab logs from the network and firewalls. Palo Alto invented the concept of the extended EDR or XDR."
  • "The price could be a little lower."

What is most valuable?

Cortex covers everything I need. It's a perfect solution. Cortex provides a different level of visibility because it's an extended EDR, allowing you to grab logs from the network and firewalls. Palo Alto invented the concept of the extended EDR or XDR.

What needs improvement?

The price could be a little lower. 

For how long have I used the solution?

I have been using Cortex for four years.

How are customer service and support?

Palo Alto provides on-the-ground and remote support. They have a local team on the ground and teams in India or other countries. Their support is excellent, and they know what they're doing. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Some of my customers have McAfee, Symantec, or Kaspersky. Palo Alto can integrate with other vendors, so it's not locked to one single vendor. Other vendors like Trend Micro, Bitdefender, CrowdStrike, etc. have limitations on log collection from other places. On Palo Alto's datasheet, it tells you that it can talk to Check Point, Fortinet, etc. It's pretty awesome. I believe this is a huge advantage that allows us to implement Cortex anywhere. 

How was the initial setup?

I rate Cortex XDR 10 out of 10 for ease of setup. It can be deployed on-prem or on the cloud. It's an easy process that doesn't take long. 

What other advice do I have?

I rate Cortex XDR 10 out of 10. 

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner/Implementer
PeerSpot user
reviewer1389378 - PeerSpot reviewer
Divisional Operations Director at a tech vendor with 1,001-5,000 employees
MSP
Aug 19, 2022
Allows us to create queries for investigation, provides good visibility, and has been able to see every single threat
Pros and Cons
  • "The live terminal is probably the best thing ever. It gives you the access to get straight onto any machine."
  • "From the Palo Alto side, whatever they buy, they integrate that really well into their integration suite, and that makes a massive difference."
  • "It tends to do 99.9% of things. The only thing I'd like is single sign-on authentication into their cloud platform so that my users can be properly authenticated against it."
  • "The onboarding process could be better."

What is our primary use case?

Officially, I'm an MSP, but I also host it for our own internal software. I've got XDR installed on 26,000 devices. It is used for threat prevention, policy enforcement, firewall rules, and DLP. We use it for pretty much everything. Our firewalls also integrate with XDR.

We use XDR Pro. It is in the cloud, and we have got version 7 at the moment, which is probably the latest update of it.

How has it helped my organization?

The key thing is the visibility of what's going on in our networks and on our end devices. It gives us visibility.

It provides the ability to query. I can query for any file or any IOC on any of the devices installed, and it will search for a data link.

What is most valuable?

The live terminal is probably the best thing ever. It gives you the access to get straight onto any machine. 

In general, it has been able to see every single threat that has ever come up and it helps us stop it. 

I've used it for a great many years now, and it worked really well. From the Palo Alto side, whatever they buy, they integrate that really well into their integration suite, and that makes a massive difference.

What needs improvement?

The onboarding process could be better. 

It tends to do 99.9% of things. The only thing I'd like is single sign-on authentication into their cloud platform so that my users can be properly authenticated against it.

What do I think about the stability of the solution?

Its stability is very good.

What do I think about the scalability of the solution?

Its scalability is very good. It is on my servers as well as my end users. I've got five and a half thousand end-users plugged in, and they're all on, and then I have 26,000 servers on it as well.

How are customer service and support?

I would rate them a 9 out of 10. The only reason why they lose a point is that if I escalate, it gets done really quickly. I've got all the various contacts I could ever need inside Palo Alto, but some of my other colleagues don't have that same level of contact. So, if I'm doing it, it is rapid, but if they're doing it, it is slower.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I've worked with Carbon Black, which Cortex XDR beats hands down. The reason it beats it hands down is because of the ability to query. I couldn't do that with Carbon Black. For me, that was a genuine issue with Carbon Black. That was one of the main reasons why we've literally moved 22,000 devices off Carbon Black into Cortex XDR.

We also use Sophos, McAfee, and BitDefender. As a group, we buy multiple companies a year. So, we come across most of them.

If it is my own device, I would love to have Cortex, but I can't buy one license. I have to buy a minimum of 250 licenses. So, I normally go for something like BitDefender because it has the least amount of bloatware.

How was the initial setup?

It is straightforward. It is pretty much out of the box. It works how you want it to work. So, you can't really ask for more.

It is also easy to maintain.

What about the implementation team?

It was implemented in-house.

What was our ROI?

In the company I'm in, we make software. On that basis, we've gone for what we need to make sure our software and all of our customer data are secure. That drives us more than the ROI. It may sound a little weird, but it is the way we run because, for us, the ROI is almost pointless if we lose all our data.

What's my experience with pricing, setup cost, and licensing?

I have the full Pro Prevent license. So, I've got post analytics, forensics, and the whole lot of it.

What other advice do I have?

My advice to others who would like to start working with Cortex is to not dip your toe in the water. Go big or go home. If you integrate everything in, you'll get fantastic results. You shouldn't do some bits here and there. You need to use their ecosystem as a whole. If you're in their entire ecosystem, the results are amazing.

I would rate it a 10 out of 10.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Sudheer Kumar - PeerSpot reviewer
Lead Security Engineer at a tech services company with 1,001-5,000 employees
Real User
Top 5Leaderboard
Sep 3, 2024
Easy to deal with deployment and integration phases
Pros and Cons
  • "The tool is designed to scale for large enterprises and handle large volumes of data."
  • "I think sometimes Cortex XDR agent automatically stops event capturing from the device, and then even the dashboard does not get any notifications from the agent."

What is our primary use case?

I use the solution for endpoint security to capture endpoint security devices' logs and security events.

What is most valuable?

The solution's most valuable feature is its general integration with various Palo Alto Networks products. The tool is a unified platform that includes a firewall, Prisma Cloud, and Cortex's storage. It is also a single data platform that consolidates data from endpoints and network traffic into a single data lake. For behavior analytics, the tool uses advanced behavior analytics and machine learning to detect sophisticated threats.

What needs improvement?

I think sometimes Cortex XDR agent automatically stops event capturing from the device, and then even the dashboard does not get any notifications from the agent. A particular endpoint message with the events captured gets stopped, making it an area where there is a need to improve the agent's real-time monitoring.

For how long have I used the solution?

I have been using Cortex XDR by Palo Alto Networks for around five years.

What do I think about the scalability of the solution?

The tool is designed to scale for large enterprises and handle large volumes of data. The tool has a scalable architecture, and accessing or processing data is leveraged by the tool, making it a robust infrastructure process that allows for efficient data analysis and timely detection and response.

In my company, around 15,000 employees use the tool.

How are customer service and support?

Many times, I raised requests for follow-up with the support team, but only sometimes there is a response. Palo Alto's team needs to work on its issues so that they can provide twenty-four hours and seven days of support to users.

How was the initial setup?

From a deployment and integration perspective, I can say it is an easy and user-friendly tool, so I don't face any challenges with the tool.

The solution is deployed on the cloud and in the on-premises model. Mostly, the tool was in the cloud for my previous client.

What other advice do I have?

One needs to look into the support and services, especially Palo Alto's support and professional services, which is an area that is not yet available. When it comes to the implementation and optimized XDR solutions, sometimes third-party integrations do not happen with XDR. When it comes to third-party integrations, a playbook in Palo Alto should be there for all the third-party tools, showing how we can implement them.

The tool is very easy and user-friendly.

I rate the tool an eight and a half out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Chandra Mohan - PeerSpot reviewer
Network Security Engineer at a tech services company with 10,001+ employees
MSP
Jul 18, 2024
Ability to mitigate ransomware issues and includes advanced threat analytics and behavioral analytics
Pros and Cons
  • "If any application performs suspicious activities, such as changing registries or modifying other applications, Cortex XDR detects and blocks the entire application."
  • "Product might have some bugs."

What is our primary use case?

Cortex XDR mainly focuses on endpoint protection. Unlike other antivirus products, it is way more advanced. It allows you to manage your endpoints and includes advanced threat analytics and behavioral analytics. For example, it offers a behavioral analysis, the main purpose of which is to identify suspicious activity.

If any application performs suspicious activities, such as changing registries or modifying other applications, Cortex XDR detects and blocks the entire application. This ensures that unauthorized actions are prevented.

Another feature of Cortex XDR is its ability to mitigate ransomware issues. It creates duplicate files on the endpoint, and if any ransomware attempts to access these files, it detects and identifies the ransomware attack. Cortex XDR offers many such advanced features in its cloud platform.

How has it helped my organization?

 

What needs improvement?

Product might have some bugs. But these will be fixed in the next version. They'll try to work on that and fix those issues. They won't let it go easily.

For how long have I used the solution?

I've been implementing and supporting this product for one year.

What do I think about the scalability of the solution?

The end users are around thousands.

How are customer service and support?

I am from the support team. I fix things. If customers have any issues with the product, they call me. That's the role of my job. I am from the partner side.

How was the initial setup?

The deployment and setup process is handled by a different team. So I have never deployed Cortex, but I know the steps. It is not easy, but at the same time, it is not very complicated.

It's cloud-based. You don't have to set up a server; it's all on the cloud. You have to set up your tenant on their dedicated server once you subscribe to the product.

What's my experience with pricing, setup cost, and licensing?

Price-wise, Cortex XDR is quite expensive compared to regular endpoints. It is a bit more expensive than other products, but it's worth the money.

What other advice do I have?

Cortex is a good product. But like every other product, it has some flaws. Not every product is ideal. Every product has its flaws. So when compared with other products, Cortex is one of the good products. I would suggest you take the product because it is really one of the good products, but it has some flaws.

So, I would rate it an eight out of ten. 

Disclosure: My company has a business relationship with this vendor other than being a customer. customer/partner
PeerSpot user
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2026
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros sharing their opinions.