What is our primary use case?
I use Palo Alto Networks AutoFocus for threat monitoring, and it is provided by the OEM itself.
I use the threat data correlation feature, which correlates with Cortex.
We can use it for data correlation, but we are mostly using a third-party solution for correlation.
How has it helped my organization?
Palo Alto Networks AutoFocus has had a positive impact on my company as we can reduce the cost for the SOC investment, and we can also get good feedback on how to strengthen our network from the expertise people available.
What is most valuable?
Without a dedicated SOC team, I find that most of the advantages come from the OEM itself.
For integrations with other Palo Alto products including Next-Generation Firewall and Cortex XDR, the integrations are easy and satisfactory.
Regarding integration, I don't have any issues with user-friendliness.
Some customers require the tagging and custom export features because troubleshooting is very easy for tagging. Different colors for tagging everything are a useful feature.
The search capabilities are satisfactory, and we are getting detailed reports from the search, which is fine compared to other firewalls.
The search for granular investigations works effectively.
What needs improvement?
I feel that Palo Alto Networks AutoFocus can improve, especially since most of the OEMs are implementing MDR, Managed Service feature, which is still not available with Palo Alto.
The MDR feature is the only aspect that bothers me today, as other OEMs such as Sophos are analyzing Palo Alto and providing recommendations on strengthening that part. Additionally, the earlier complimentary BPA practice assessment has now become chargeable, which means we cannot assess the posturing of our firewall.
They are providing a solution, but a separate license is required for the BPA.
For how long have I used the solution?
I have been dealing with products for about 11 years, and for the last five years I have specifically worked with Palo Alto Networks AutoFocus.
What was my experience with deployment of the solution?
The flexibility of deploying Palo Alto Networks AutoFocus in both cloud and on-prem environments is not an issue; we can deploy it without any problems.
What do I think about the stability of the solution?
The solution is both scalable and stable.
What do I think about the scalability of the solution?
How are customer service and support?
I would rate technical support for Palo Alto Networks AutoFocus five out of ten. This is primarily due to the response time, which is the main problem.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
I haven't worked with similar products from Cisco or Fortinet. Palo Alto Networks AutoFocus is the only product for this use case that I've been dealing with.
What was our ROI?
For ROI, I can give a rating of seven or eight. We can say there is about a 25% saving.
What's my experience with pricing, setup cost, and licensing?
Palo Alto Networks AutoFocus is not affordable.
Which other solutions did I evaluate?
Other OEMs provide similar functionality, but those are handled by a separate team.
What other advice do I have?
As a partner with Palo Alto Networks, my email is Sarvajit at bsrgroup.in. My job title is Technical Manager.
I confirm that we will publish these reviews on peerspot.com in written or audio format, which can be available to other people, but I can stay anonymous if I wish, and I will get notifications, while the use of the review is subject to PeerSpot's terms of use, accessible at peerspot.com/tos.
If Palo Alto has questions or comments about my reviews, they can reach me via email to confirm something. I am interested in being a reference for Palo Alto.
The solution is also for enterprise customers only.
I see some AI capabilities, such as machine learning, integrated into Palo Alto Networks AutoFocus. ML is present along with behavior analysis, and that is common among all the OEMs nowadays.
On a scale from one to ten, I rate this solution a six.