Try our new research platform with insights from 80,000+ expert users
reviewer2159517 - PeerSpot reviewer
Mdr of Presales & Customer Success Head at a financial services firm with 1-10 employees
Real User
Apr 21, 2023
A stable and scalable solution with good customer support
Pros and Cons
  • "The solution allows us to make investigations. Other XDR solutions also provide similar capabilities but for investigation, Cortex XDR is better."
  • "The product's pricing could be better."

What is our primary use case?

We use the solution for telemetry and for its anti-virus capability.

What is most valuable?

The solution allows us to make investigations. Other XDR solutions also provide similar capabilities but for investigation, Cortex XDR is better.

What needs improvement?

The product's pricing could be better.

For how long have I used the solution?

I have been using the tool for several years.

Buyer's Guide
Cortex XDR by Palo Alto Networks
January 2026
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.

What do I think about the stability of the solution?

The solution is stable. I would rate its stability a nine out of ten. 

What do I think about the scalability of the solution?

The product is scalable. 

How are customer service and support?

The technical support team is good.

How was the initial setup?

The initial setup was easy.

What was our ROI?

The tool is worth its money. 

What other advice do I have?

I would rate the solution an eight out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Mantu Shaw - PeerSpot reviewer
Project Manager at a outsourcing company with 1,001-5,000 employees
MSP
Top 5
Dec 21, 2021
A stable part of our security solution that correlates logs from relevant sources
Pros and Cons
  • "The most valuable for us is the correlation feature."
  • "There are some third-party solutions that are difficult to integrate with, which is something that can be improved."

What is our primary use case?

We use Cortex XDR as part of our security solution.

How has it helped my organization?

its a very good solution and single solution for entire infrastructure, give us good co-relation of incident. Single solution for Network, Endpoint, Servers. 

What is most valuable?

The most valuable for us is the correlation feature. You are able to correlate data that is coming from the firewall, network, server, and endpoints. This is one of our main requirements and makes for a good product.

It works with the data lake in an agent-based or agentless manner.

It is easy to integrate most with network devices, including firewalls, and Active Directory. We use firewalls from different vendors including Palo Alto and Check Point, and it supports them.

What needs improvement?

There are some third-party solutions that are difficult to integrate with, which is something that can be improved.

What do I think about the stability of the solution?

We have not experienced any issues with respect to stability at this point.

What do I think about the scalability of the solution?

Scalability has not been a problem.

How are customer service and support?

We have been in contact with technical support and are satisfied with them.

How would you rate customer service and support?

Positive

How was the initial setup?

its a Straightforward

What about the implementation team?

We have an in-house team for deployment and maintenance.

What was our ROI?

It replace multiple solution and due to this it will reduce the Administrative effort.

Which other solutions did I evaluate?

I have run a PoC with both CrowdStrike and Cortex XDR, and from my observation, I felt that Cortex was much better at meeting our requirements. It is also easier to use.

CrowdStrike was difficult when it came to integrating with other products and it does not work on mobile devices.

What other advice do I have?

My advice for anybody who is considering Cortex XDR is that it is a complete solution, and has very good features. From my experience, it is one of the better ones in the market. That said, no product is 100%.

I would rate this solution a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Cortex XDR by Palo Alto Networks
January 2026
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
reviewer1530651 - PeerSpot reviewer
EMEA IT Infrastructure Manager at a consumer goods company with 5,001-10,000 employees
Real User
Nov 18, 2021
Good management capabilities but has poor performance
Pros and Cons
  • "The management capabilities, allow an IT organization to get quite a good picture of attempted cyber attacks."
  • "Impact on system performance is horrible, adding a lot of delays for users."

What is our primary use case?

My primary use of this solution is as an endpoint security client.

How has it helped my organization?

This product has not improved my organization - in fact, we are in the process of moving back to another product as a result of Cortex's horrible impact on system performance.

What is most valuable?

The most valuable features of this product are the management capabilities, which allow an IT organization to get quite a good picture of attempted cyber attacks, and its out-of-the-box investigation capabilities.

What needs improvement?

The product's impact on system performance is horrible, adding a lot of delays for users. 

For how long have I used the solution?

I have been using this solution for four months.

How was the initial setup?

The onboarding process was quite cumbersome. It took some time to deploy as we had to investigate about 500 cases of clients who did not get the agent immediately.

What about the implementation team?

I implemented using a vendor team.

What other advice do I have?

I would rate this solution as five out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
CyberSecurity Consultant at a tech vendor with 51-200 employees
Real User
Nov 15, 2021
A stable and scalable solution with an easy setup and out-of-the-box playbooks and integration
Pros and Cons
  • "The integrations are out-of-the-box, as are the playbooks."
  • "The solution should offer more dashboards and they should be better customized."

What is our primary use case?

I have deployed some customized playbooks and modified ones which are out-of-the-box with more integration with SIEM solutions such as ArcSight, QRadar, ADRs and Trend Micro.

What needs improvement?

The solution should offer more dashboards and they should be better customized. The case number of items should be addressed. 

I have found the interface of Azure to be more simple and customizable than that of the solution. 

For how long have I used the solution?

I have worked on Cortex XDR by Palo Alto Networks with my customers for a number of weeks. 

What do I think about the stability of the solution?

The stability is good. 

What do I think about the scalability of the solution?

The scalability is fine. 

We have plans to increase the usage. 

How was the initial setup?

The initial setup was simple. 

The deployment took no more than two hours. 

What's my experience with pricing, setup cost, and licensing?

So far, I have made use of the free license which is offered. Once it ended, I was able to buy a license based on the number of users or divisions. The license varies with the number of users or applications involved. 

If one wishes to work with another team or large number of users at a future point, he must purchase a license for them. 

Which other solutions did I evaluate?

The interface of Azure is more simple and customizable than Cortex XDR by Palo Alto Networks.

What other advice do I have?

I have found the solution to be very easy in respect of the integration and configurable. The integrations are out-of-the-box, as are the playbooks. 

The solution is deployed solely on-premises on a single server. 

As of now, there are six users making use of the solution. 

My advice is that the on-premises environments for the product's use should be increased. 

I rate Cortex XDR by Palo Alto Networks as an eight out of ten. 

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Pre-sales engineer at a tech services company with 51-200 employees
Real User
Sep 20, 2021
Best support and good interface, price, and security
Pros and Cons
  • "Its interface and pricing are most valuable. It is better than other vendors in terms of security."
  • "It is not very strong in terms of endpoint management. It should have additional features like DLP, encryption, or advanced device control. Currently, Cortex is good in terms of the security of the endpoints, but it is not as good as other vendors in terms of the management of the endpoint."

What is our primary use case?

We are using it for a banking client.

What is most valuable?

Its interface and pricing are most valuable. It is better than other vendors in terms of security.

What needs improvement?

It is not very strong in terms of endpoint management. It should have additional features like DLP, encryption, or advanced device control. Currently, Cortex is good in terms of the security of the endpoints, but it is not as good as other vendors in terms of the management of the endpoint.

For how long have I used the solution?

I have been using this solution for two years.

What do I think about the stability of the solution?

It is very stable. I wouldn't recommend the latest version. Being a new version, it would have bugs, which is similar to the new versions of other products.

What do I think about the scalability of the solution?

In Peru, we have approximately 20,000 users. The banking client doesn't have any plans to expand the usage. We might increase its usage by 200 to 500 with new clients.

How are customer service and technical support?

Technical support of Palo Alto is the best.

How was the initial setup?

It is very easy to deploy. The deployment is quick. The deployment of the management console takes just two hours, but the deployment of the agent takes approximately a month.

We have five to eight engineers for deployment and maintenance.

What other advice do I have?

I would rate Cortex XDR a nine out of 10.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner.
PeerSpot user
reviewer1663611 - PeerSpot reviewer
IT manager at a computer software company with 11-50 employees
Reseller
Sep 8, 2021
Provides ability to see what's going on with your assets and react to cyber attacks
Pros and Cons
  • "Its ability to react to cyber data attacks is awesome. That is pretty much the use of it. What blows your mind is the ability to access your assets remotely and see what is actually going on with them. You can not only see them in a console. You can also react very rapidly to your assets that are compromised."
  • "It should support more mobile operating systems. That is one of the cons of their infrastructure right now."

What is our primary use case?

I use it for visibility, mitigation, and analysis of advanced threat attacks.

What is most valuable?

Its ability to react to cyber data attacks is awesome. That is pretty much the use of it. What blows your mind is the ability to access your assets remotely and see what is actually going on with them. You can not only see them in a console. You can also react very rapidly to your assets that are compromised.

What needs improvement?

It should support more mobile operating systems. That is one of the cons of their infrastructure right now.

For how long have I used the solution?

I have been using this solution for more than four years.

What do I think about the stability of the solution?

It has been extremely stable.

What do I think about the scalability of the solution?

It is easily scalable. For example, if you have version 2, Palo Alto upgrades it automatically. The agents for your assets are also scalable for new operating systems. So, it is very scalable.

How are customer service and technical support?

Their technical support is very agile and very good. I would rate them a nine out of 10.

How was the initial setup?

It is way too easy to deploy it and set it up.

What other advice do I have?

I would highly recommend it unless you have iOS assets on your network.

I would rate Cortex XDR an eight out of 10.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
Assistant PhD at a educational organization with 501-1,000 employees
Real User
Aug 2, 2021
Good technical support , reasonable pricing, and has good detection capabilities
Pros and Cons
  • "Threat identification and detection are the most valuable features of this solution."
  • "I would like to see some additional features related to email protection included."

What is most valuable?

Threat identification and detection are the most valuable features of this solution.

What needs improvement?

I would like the Panorama module included. It's another solution that is provided by Palo Alto and we are interested in that.

I would like to see some additional features related to email protection included.

For how long have I used the solution?

I have been working with Cortex XDR for a year and a half.

How are customer service and technical support?

Technical support is okay.

What's my experience with pricing, setup cost, and licensing?

I don't have any issues with the pricing. We are satisfied with the price.

What other advice do I have?

I would rate Cortex XDR by Palo Alto Networks a ten out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
AndyChan3 - PeerSpot reviewer
General manager at a tech services company with 201-500 employees
Real User
Top 10
Jul 31, 2021
Highly scalable, effective intelligence, and reliable
Pros and Cons
  • "One of the main benefits of the solution is its intelligence to correlate the events into an incident."
  • "The solution could improve by providing better integration with their own products and others."

What is our primary use case?

I use the solution for endpoint protection.

What is most valuable?

One of the main benefits of the solution is its intelligence to correlate the events into an incident.

What needs improvement?

The solution could improve by providing better integration with their own products and others.

For how long have I used the solution?

I have been using this solution for approximately one year.

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

It is one of the best in the market for scalability.

We have approximately 500 people using this solution in my organization and we plan to increase usage.

How was the initial setup?

The initial installation is easy.

What about the implementation team?

We did the implantation of the solution with integrators.

What's my experience with pricing, setup cost, and licensing?

The price of the solution is high for the license and in general.

Which other solutions did I evaluate?

We evaluated CrowedStrike and Darktrace.

What other advice do I have?

I would recommend this solution to others.

I rate Cortex XDR by Palo Alto Networks a nine out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros sharing their opinions.
Updated: January 2026
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros sharing their opinions.