I am familiar with Palo Alto Networks Cortex XSOAR products, particularly with Cortex. Palo Alto Networks Cortex XSOAR is primarily used for IOC enrichment, IOC harvesting, and correlation, followed by automation.
Solutions Architect at ostec
Automation has reduced incident response times and improves early detection of security threats
Pros and Cons
- "The playbook automation helped streamline my incident response time by removing delays from the human side and reducing the mean time to respond."
- "I did notice some drawbacks, as it is a bit complex."
What is our primary use case?
How has it helped my organization?
The integration has positively impacted my organization's mean time to resolution, as both mean time to detect and respond have improved, enabling earlier detection and response.
The playbook automation helped streamline my incident response time by removing delays from the human side and reducing the mean time to respond.
What is most valuable?
Some advantages I would like to mention include automation which was really helpful for IOC harvesting. It actually reduced the response time by approximately 60 percent.
What needs improvement?
I did notice some drawbacks, as it is a bit complex. The deployment and implementation are complex in nature.
Integration with third-party tools had some issues, particularly with open source platforms, but enterprise tools integrated just fine. The exact platform we integrated required custom solutions, especially with open-source tools.
Buyer's Guide
Palo Alto Networks Cortex XSOAR
July 2026
Learn what your peers think about Palo Alto Networks Cortex XSOAR. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,800 professionals have used our research since 2012.
For how long have I used the solution?
I have been using this solution for over two years.
How are customer service and support?
I have come across technical support and found their response to be fast and helpful.
How was the initial setup?
The deployment requires a huge amount of time, approximately five to six months since it was a national project.
I was also involved in the deployment of Palo Alto Networks Cortex XSOAR project.
What about the implementation team?
We had two people from our side who took part in it, including a PM and another technical person while I was the technical architect and solutions architect.
What's my experience with pricing, setup cost, and licensing?
For the capability, I think the pricing and licensing cost for Palo Alto Networks Cortex XSOAR is reasonable.
What other advice do I have?
Overall, I am satisfied with how Palo Alto Networks Cortex XSOAR works for me, as it had a positive impact on my organization's performance.
Most of the tools we integrated into the solution also had AI, and the efficiency started from a couple of places, not just starting from Cortex.
The analytical features of Palo Alto Networks Cortex XSOAR streamline my ability to gain insights and visibility into security threats, especially due to integrations with threat intelligence sources.
I have utilized Palo Alto Networks Cortex XSOAR's playbook automation, which was part of the automation we implemented. I give this solution a rating of 9 out of 10.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
Last updated: Jul 31, 2026
Flag as inappropriateSecurity Engineer at a financial services firm with 51-200 employees
Automation has accelerated incident triage and has strengthened on-premises threat response
Pros and Cons
- "Palo Alto Networks Cortex XSOAR has positively impacted our organization by making us faster in the incident response process and allowing us to focus on more innovative things instead of just doing the same things repeatedly because of its amazing automation."
- "An improvement for Palo Alto Networks Cortex XSOAR could be adding management of custom resources through Terraform or infrastructure as code, making it more scalable from an end-user perspective."
What is our primary use case?
My main use case for Palo Alto Networks Cortex XSOAR involves working in a security team with a very complicated, large on-premises infrastructure where we needed some automated triage and response to cybersecurity threats, which is why we decided to onboard Palo Alto Networks Cortex XSOAR.
A specific example of how I used Palo Alto Networks Cortex XSOAR for automation or response is when we had a public-facing endpoint for payment authentications, which was under constant brute force attacks. We identified certain patterns using Palo Alto firewall and used Palo Alto Networks Cortex XSOAR to automatically detect and block these brute force attempts toward that endpoint.
What is most valuable?
Palo Alto Networks Cortex XSOAR offers features that are simple and easy to use with many integrations, making it quite a complete stack in the security field right now.
The integrations that I found most valuable included those with the Linux operating system, different types of servers, databases, and other network devices such as switches and routers. We were also able to create custom integrations and understand logs while processing a lot of custom data.
Palo Alto Networks Cortex XSOAR has positively impacted our organization by making us faster in the incident response process and allowing us to focus on more innovative things instead of just doing the same things repeatedly because of its amazing automation.
As a result of using Palo Alto Networks Cortex XSOAR, I believe we saved around two hours of man labor just by using the automations it offered, and this time saving increased exponentially over time as the tool matured in our environment.
What needs improvement?
An improvement for Palo Alto Networks Cortex XSOAR could be adding management of custom resources through Terraform or infrastructure as code, making it more scalable from an end-user perspective.
For how long have I used the solution?
I have used Palo Alto Networks Cortex XSOAR for around eight to ten months.
What do I think about the stability of the solution?
Palo Alto Networks Cortex XSOAR is stable.
What do I think about the scalability of the solution?
Palo Alto Networks Cortex XSOAR's scalability is pretty good and it is easy to scale up according to the infrastructure requirements.
How are customer service and support?
The customer support for Palo Alto Networks Cortex XSOAR is good.
Which solution did I use previously and why did I switch?
We were not using any enterprise solution before opting for Palo Alto Networks Cortex XSOAR.
Before choosing Palo Alto Networks Cortex XSOAR, we evaluated Rapid7, but we decided to move on with Palo Alto.
What was our ROI?
I would say that time saved is the first metric to evaluate our return on investment, with the comfort level we now have because of this good tool being the real benefit we have.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing indicates that I believe it is a little bit expensive; however, being among the market leaders, it is worth the money, though still a bit pricey.
What other advice do I have?
My advice for others looking into using Palo Alto Networks Cortex XSOAR is to be aware of what you need and focus on your goals first when deploying it, as it is a very vast tool with unlimited features that can take time to explore.
Regarding Palo Alto Networks Cortex XSOAR's AI capabilities, I have not touched that part, but I know that Palo Alto is a very secure and compliant company, which makes me comfortable using this tool even in a regulated environment, so I trust Palo Alto on that governance part.
I have not used Palo Alto Networks Cortex XSOAR's AI capabilities much in my career, but other than that, the analysis, hypothesis building, triage of alerts, and integrations were pretty nice. I would rate this product an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jul 22, 2026
Flag as inappropriateBuyer's Guide
Palo Alto Networks Cortex XSOAR
July 2026
Learn what your peers think about Palo Alto Networks Cortex XSOAR. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,800 professionals have used our research since 2012.
Information Security Senior Advisor at Eskom Ltd
Automation has improved security workflows but user experience still needs refinement
Pros and Cons
- "I have not faced any challenges with the deployment of Palo Alto Networks Cortex XSOAR at this stage."
- "I believe ease of use would be an improvement for Palo Alto Networks Cortex XSOAR, as I see this as a valuable feature for future iterations."
What is our primary use case?
I only use Palo Alto Networks Cortex XSOAR product, which means I'm not familiar with the XSOAR component. I am familiar with Palo Alto Networks Cortex, which includes the XSIAM portion. I have been using Palo Alto Cortex for approximately a year.
What is most valuable?
I confirm that I'm using the cloud version of Palo Alto Networks Cortex XSOAR. I am the Information Security Senior Advisor at Eskom Limited, confirming my current position.
What needs improvement?
I believe ease of use would be an improvement for Palo Alto Networks Cortex XSOAR, as I see this as a valuable feature for future iterations. For queries, I believe improvement in that area could enhance Palo Alto Networks Cortex XSOAR further.
For how long have I used the solution?
I have been using Palo Alto Cortex for approximately a year.
What do I think about the stability of the solution?
I have not faced any challenges with the deployment of Palo Alto Networks Cortex XSOAR at this stage.
Which solution did I use previously and why did I switch?
We no longer use our previous solution as I have been familiar with the current product for more than a year, and it was replaced by another product. It has been out of our environment for more than a year. We do not use any Trellix products at this stage, which confirms we are currently not utilizing any of their offerings.
What about the implementation team?
Service providers looked after the implementation, so I spent limited time on deployment. It was taken care of by a service provider, confirming it was managed by a third party.
Which other solutions did I evaluate?
We are currently using Palo Alto Networks Cortex XSOAR solution.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jul 31, 2026
Flag as inappropriateAnalyste Soc at a comms service provider with 10,001+ employees
Building playbooks has been challenging but automation now streamlines incident closure
Pros and Cons
- "In my opinion, the best features offered by Palo Alto Networks Cortex XSOAR are the automation, the graphical incident interface, the assignment functionality, and automatically closing the incident with closure reasons."
- "Palo Alto Networks Cortex XSOAR has not had a positive impact on my organization or my work personally because we are currently in the process of putting Palo Alto Networks Cortex XSOAR into production to improve it, so I do not yet know the full impact."
What is our primary use case?
My main use of Palo Alto Networks Cortex XSOAR is as a SOAR to resolve incidents automatically. I close the incident by clicking approve, and everything is approved. I do not put the automation into production since I am a student.
What is most valuable?
In my opinion, the best features offered by Palo Alto Networks Cortex XSOAR are the automation, the graphical incident interface, the assignment functionality, and automatically closing the incident with closure reasons.
Regarding the graphical part, I appreciate that you can see who closes incidents most often and the number of incidents that remain to be handled.
Palo Alto Networks Cortex XSOAR has not had a positive impact on my organization or my work personally because we are currently in the process of putting Palo Alto Networks Cortex XSOAR into production to improve it, so I do not yet know the full impact.
The tool has simplified some tasks. Everything that we put into a playbook, even if it is not all in production, still allows us to follow our guide to close an incident.
What needs improvement?
In my opinion, what is missing to improve Palo Alto Networks Cortex XSOAR is a closure note each time we close an incident. Even though there is a form and closure note available, I have not seen this feature implemented in Palo Alto Networks Cortex XSOAR.
For how long have I used the solution?
I have been using this solution for a few months, six months in total.
What other advice do I have?
My advice to someone who is considering using Palo Alto Networks Cortex XSOAR is that it is a good automation tool for building playbooks.
The specific skills or training I would recommend to use this tool effectively is the Palo Alto Networks Cortex XSOAR training that was offered in October or November.
In my opinion, the main challenge encountered when setting up or configuring Palo Alto Networks Cortex XSOAR is building the playbook. I would try to understand how to properly configure the playbooks without adding unnecessary and repetitive things. It is easy if you clearly understand how it works, but for another beginner user, they can get lost quite easily in understanding how it works.
I give this product a rating of five out of five.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Jul 27, 2026
Flag as inappropriateManager at Deloitte
Ability to multiple playbooks to fetch data from multiple firewalls and utomated several tasks, including vulnerability scans and SOCL (Security Orchestration, Automation
Pros and Cons
- "The orchestration in XSOAR is significantly easier compared to other SOAR tools I've used."
- "The user interface (UI) is quite heavy and takes time to load, which is a major drawback."
What is our primary use case?
I have worked on multiple use cases related to network security and cybersecurity. In network security, I've created multiple playbooks to fetch data from multiple firewalls.
We can also upgrade them in parallel to Axon. Apart from that, we can block URLs and IPs in real time. It takes less than five minutes to block something. You don't have to push a policy or create a rule on the firewall directly. You just upload the IOC (Indicator of Compromise), URL, or IP into a SharePoint sheet, and it gets blocked within five minutes.
Those are the kinds of use cases I've created. In addition, we've automated several tasks, including Nikto vulnerability scans and SOCL (Security Orchestration, Automation, and Response) tasks.
We've also created multiple threat intelligence playbooks, fetching data through the MITRE framework and following compliances like HIPAA. It's a very good tool.
How has it helped my organization?
XSOAR support the company's compliance and regulatory requirements. For example, I'm working with multiple clients from different industries—one from manufacturing, another from healthcare, and one from banking. Each of these clients has its own compliance policies. XSOAR is a product that allows you to meet all regulatory requirements effectively. The flexibility in XSOAR is much greater compared to other tools.
Security-wise, the integration of IAM and SSO in XSOAR is straightforward. For example, I'm currently working with an Indian client that must adhere to RBI regulations. These regulations require that data remain within the Indian subcontinent and not be sent overseas when using cloud services.
For instance, FortiSOAR has data centres in Dallas and Australia. Google Chronicle has data centres in Europe, Japan, and the US. However, XSOAR also has a data centre in India, which is essential for meeting local regulatory requirements. This makes XSOAR a very suitable option for such needs.
What is most valuable?
The best feature is the CLI part. If you want to execute any command or something like that, it is very easy. You can get a tab, and you just type the command there, and it will run. The playground feature is very good. You don't need a separate development environment; you can use it directly within XSOAR. These are the things that make XSOAR stand out compared to other products.
For orchestration, the processes are very user-friendly. Even if I'm not an XSOAR admin, I can quickly become proficient with it. You just have to navigate through the various options in Palo Alto Networks Cortex XSOAR, and it becomes easy to manage. For instance, if you are a SOC analyst and want to start using XSOAR, it's very easy to access and retrieve the details you need.
To put it in simpler terms, using XSOAR is like using a Fire Stick, where you have all your OTT platforms available. Similarly, in XSOAR, you get all the related alerts, whether from SIEM, EDR, or XDR, all consolidated in one place. You can analyze the data, make decisions, and even automate certain processes based on the data you receive. XSOAR assists in automating workflows, making decision-making processes easier.
The orchestration in XSOAR is significantly easier compared to other SOAR tools I've used, like Siemplify, Splunk Phantom, and FortiSOAR. The processes are much more streamlined in XSOAR, which is what I appreciate most about it.
So, when it comes to automation and playbooks, it is very easy. XSOAR is the only platform that supports three scripting languages: Python, JavaScript, and PowerShell. So you don't have to worry much about compatibility. If someone knows Python, they can easily create a playbook for automation. They can write the automation scripts and handle everything. Even if you're like me, coming from a Windows background and only familiar with PowerShell scripting, you can still create automation within XSOAR. This flexibility is something that XSOAR provides, unlike other tools that only support Python.
XSOAR uses machine learning and generative AI, particularly in threat intelligence. In security, threat intelligence is the only area where AI and machine learning are truly effective. Aside from that, whatever vendors are claiming about AI is often just marketing hype. They might suggest that AI can be used everywhere, but security compliance is a crucial factor.
For example, if I request AD admin access, it's unlikely anyone would grant it due to security concerns. This demonstrates the limits of AI in certain aspects of security. They may have chatbots and other features, but their necessity is questionable. For instance, if I need details about a particular IP or URL, I can retrieve it myself by running a command. Human intervention is still necessary in these cases.
We can definitely use AI in incident response, but the major thing is in managing case notes. We recently initiated a project focused on ensuring that case notes added by analysts follow a proper format. We can then utilize generative AI to improve this process. For example, if an alert is related to a DNS query, we can create different templates. Based on the best keyword match, AI can make decisions, which is part of our plan.
What needs improvement?
Recently, they started implementing microservices in XSOAR, which has improved quality and addressed previous issues. However, they should focus more on licensing costs. The user licensing fees are quite high.
For example, I received a quote for XSOAR, and it was $12,000 per user per year. If you have a SOC team of 30 members/analysts, you're looking at a substantial expense. They should consider reducing these costs since this high pricing seems to be more about profit.
So, there is room for improvement in the pricing.
Moreover, the reporting and dashboard features are decent but could be improved. The user interface (UI) is quite heavy and takes time to load, which is a major drawback.
For how long have I used the solution?
I have been working with the XSOAR product for almost four four and a half years.
What do I think about the scalability of the solution?
I've mostly worked on the SaaS side and haven't encountered any major issues.
So, it's highly scalable. But in practice, scalability is often underutilized. It's only leveraged when fully necessary, such as when the system becomes protected and fully operational.
If you use the case management module of XSOAR, then you need to cover all the SOC personnel. If you just want to automate tasks and send details via email, then three or four licenses are more than enough.
How are customer service and support?
Technical support varies. If you have premium support, they treat you well. If not, it might be frustrating. But it depends on the person handling it.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have used Fortinet, Splunk, and other vendors.
How was the initial setup?
The implementation strategy varies. You start by ingesting alerts from various sources and then begin creating playbooks. The process depends on what the client needs first.
Typically, I start by setting up Single Sign-On (SSO) and the user base. After that, I proceed with the deployment, which is the most efficient approach. Meanwhile, I also allow SOC analysts some time to familiarize themselves with the system.
Typically, a single resource can manage the entire deployment process. You don't need a large team.
The time frame depends on the client. If the client is proactive and has all the data and processes in place, it can take one to two months. Otherwise, it can be a more tedious process.
Both versions are available—SaaS and on-premises. I’ve worked on both, but mostly with the SaaS-based version. However, both versions are almost identical in functionality.
Maintenance is very easy. If you want to upgrade XSOAR, you just have to open a ticket with support. They will give you a specific window, and it takes less than five minutes to get updated, and everything works fine.
What about the implementation team?
I currently manage XSOAR end-to-end, from giving demos to customers to implementing it in their environments. I handle everything, including the automation part.
What was our ROI?
XSOAR can automate nearly anything. Compared to any other SOAR tool, it's more powerful and provides more control to automate tasks across various areas, whether it's network security, IAM, server management, or other infrastructure levels. XSOAR offers seamless integrations with around 80+ integrations available in the marketplace. The layouts are customizable, and you can create multiple layouts or custom incident schemas. These features make XSOAR the market leader in its category.
ROI becomes evident when your SOC is mature. The problem many businesses face is that they receive a budget and immediately purchase products without focusing on processes. The process is more important than the tools.
Many companies spend heavily on CapEx but neglect operational optimization. If you focus on improving operational processes, you will see better results. For example, many organizations pay for a high EPS (events per second) rate on their SIEM, but 99% of the events are false positives. This is wasteful.
Once your SOC processes are mature and you have a high number of true positive alerts, that's when XSOAR can be truly effective. Automation is the last step in the process; you have to take it step by step. XSOAR comes into play when you're ready to automate efficiently.
Before you proceed, it's important to trim down the false positives and establish a robust process. You need to orchestrate multiple things. These are the elements currently missing with the client. Once your SOC (Security Operations Center) is matured, and you start receiving accurate, true positive alerts, XSOAR will provide a significant ROI.
You can automate almost 90% of the playbooks that SOC analysts manage. The remaining 10% would involve decision-making tasks, which can be handled by L3 or L2 analysts. L1 tasks have already been automated, allowing L1 analysts to focus on L2 responsibilities.
What other advice do I have?
Overall, I would rate it a nine out of ten. The main drawbacks are the dashboard and reporting features—they could be better. Also, the user licensing fee is quite high. Apart from that, I don't think there are any major issues.
If we’re paying for premium support, they should consider providing some complimentary private keys or licenses. It's like buying an Amazon Fire Stick and expecting free Amazon Prime and Netflix for a few days. But they’re not giving anything for free.
I would recommend this product to other users, if they have a decent budget to spend. Further, I would advise to ensure your processes are robust. Once your process is stable, you can buy XSOAR, and it can do wonders. It's just a tool, after all.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Integrator
Presale Engineer at Westcon-Comstor
Automate security event orchestration with tailored integration capabilities
Pros and Cons
- "Each incident collected is orchestrated with automation that selects the security analyst to be involved, or provides complex execution plans for managing security incidents."
- "I would rate the stability of Cortex XSOAR as nine out of ten."
- "The product can be tailored for each deployment to respond to specific customer needs, and this complexity may be seen as a downside."
- "The complexity of Cortex XSOAR has a trade-off with its versatility. The deployment requires integration and the development of integration modules."
What is our primary use case?
The primary use case for Cortex XSOAR is as an orchestration automation platform. I use it to execute automatic tasks for collecting, enriching, and correlating security events from hundreds of different technologies. It involves incident orchestration and automation in the selection of security analysts to be involved in event handling.
What is most valuable?
The solution is an orchestration automation platform. Three main features can help me: execution of automatic tasks for collecting, enriching, and correlating security events from hundreds of different technologies that I can integrate into the platform. Each incident collected is orchestrated with automation that selects the security analyst to be involved, or provides complex execution plans for managing security incidents.
What needs improvement?
The complexity of Cortex XSOAR has a trade-off with its versatility. The product can be tailored for each deployment to respond to specific customer needs, and this complexity may be seen as a downside. The deployment requires integration and the development of integration modules. Deployment is not easy, requiring significant tuning and building of integrations over weeks.
For how long have I used the solution?
I have been working with Cortex XSOAR for about three years.
What do I think about the stability of the solution?
I would rate the stability of Cortex XSOAR as nine out of ten.
What do I think about the scalability of the solution?
I would rate the scalability of Cortex XSOAR as nine out of ten.
How are customer service and support?
Customers who purchase Cortex XSOAR usually receive kickstart services provided directly by the vendor, ensuring initial setup and tuning is well-supported. In daily operations, the support service follows Palo Alto's standards, which I rate as eight out of ten.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is assisted by kickstart services provided by the vendor to ensure a smooth start, including the initial setup and tuning of Cortex XSOAR.
What about the implementation team?
My deployment experience is key. A strong interaction with the customer’s engineers for integration is critical for successful deployment. Maintenance is usually provided either by the vendor or third-party resellers.
What's my experience with pricing, setup cost, and licensing?
Even though customers often comment on the price, the potential savings come from managing a large number of security events with a limited number of analysts. This leads to economic advantages despite the product's cost not being low.
What other advice do I have?
I would recommend Cortex XSOAR to customers with an internal SOC team or who deliver SOC services for third parties.
I would rate the overall solution an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer.
Cyber Security Analyst at Altisec Technologies Pvt Ltd
Enhanced security operations through automation and advanced playbook creation
Pros and Cons
- "The most valuable features of Cortex XSOAR include its vast library of plugins, which allow us to integrate various tools and solutions seamlessly."
- "Creating complex playbooks using coding languages, such as Python, could be easier."
What is our primary use case?
I have created a couple of playbooks for a few clients using Cortex XSOAR. For example, we created a phishing playbook that checks the reputation of IP addresses or URLs using various reputation checker platforms. We've integrated Firepower Threat Defense, as well as Aviso IPTP and Cisco Talos for comparing the results. These were some of the use cases we worked on.
How has it helped my organization?
Using Cortex XSOAR has helped us create complex playbooks and streamline our security operations through automation. The integration capabilities with other solutions, like Cortex XDR and various SIEM solutions, have improved our incident management and detection capabilities.
What is most valuable?
The most valuable features of Cortex XSOAR include its vast library of plugins, which allow us to integrate various tools and solutions seamlessly. Additionally, the ability to create complex playbooks tailored to our needs and the option to incorporate user input within the workflows are highly beneficial.
What needs improvement?
Creating complex playbooks using coding languages, such as Python, could be easier. Sometimes the process becomes tedious and requires manual tasks.
For how long have I used the solution?
I have worked with Cortex XSOAR for approximately five to six months.
What do I think about the stability of the solution?
I have not experienced any performance or stability issues with Cortex XSOAR.
What do I think about the scalability of the solution?
Cortex XSOAR is scalable. We had around 50 to 60 playbooks created by my colleagues, and the solution scaled well up to a certain extent and beyond.
How are customer service and support?
I would rate the technical support 9.5 to ten out of ten. Palo Alto Networks provides concrete and to-the-point solutions to our issues.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Before using Palo Alto Networks Cortex XSOAR, I used a product called Sequium SOAR. It was not up to the mark as we could not insert any code or create complex playbooks.
What about the implementation team?
The setup was done by another team.
What's my experience with pricing, setup cost, and licensing?
I do not know about the pricing as it was handled by the salespeople.
Which other solutions did I evaluate?
We evaluated other products such as SplunkSource, SecondSource, and Stream LensSource. However, we chose Cortex XSOAR because of its scalability and flexibility.
What other advice do I have?
To create your own customized playbooks, it's important to be well-versed with Python.
I'd rate the solution ten out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Delivery Manager at a tech services company with 1,001-5,000 employees
Scalable, with the ability to handle a large number of integrations and inbuilt ITSM management
Pros and Cons
- "For organizations that are stable with their security operations, like those with around 50 members in their security team running full-phased operations 24/7, Cortex is necessary."
- "Previously, when Demisto was, there was a community edition; we could use it, reinstall it, and customize it. Since Palo Alto took over, it has become more financially oriented. It's business, but they could offer a pro model and a lighter model for different needs."
How has it helped my organization?
For organizations that are stable with their security operations, like those with around 50 members in their security team running full-phased operations 24/7, Cortex is necessary. They can automate many processes and build their own scripts. Then, we use it for Flashflakes.
But for a smaller organization with binding budgets and who is unaware of security, they may end up wasting money on it. This is an expensive tool. We have to use it wisely, or it’s easy to mistrust its value.
What needs improvement?
Previously, when Demisto was, there was a community edition; we could use it, reinstall it, and customize it. Since Palo Alto took over, it has become more financially oriented. It's business, but they could offer a pro model and a lighter model for different needs.
For example, creating a pro model alongside a lighter model could be beneficial, like FortiSOAR or others providing a lighter model that focuses on the automation segment, where you could integrate maybe five or ten playbooks and integrations for day-to-day operations. This would make it more accessible to everyone.
Currently, Cortex XSOAR operates on a larger scale, which may not be necessary for all. If there's a minimum budget of around 50k or 80k for SOAR, having a scaled-down version of Cortex XSOAR would be advantageous. This would allow integration with current business operations at a minimal cost, saving money while still leveraging the capabilities of Cortex XSOAR.
And if there's a need to scale up later, moving to a pro model could be an option. That's something that's missing on the business side but could greatly aid incident response, as we're all trying to secure organizations from threats. Having such an option would make it a more socially viable cost and still provide widespread use.
In future releases, I would like to see more differential models could be implemented, instead of having a one-size-fits-all approach.
For how long have I used the solution?
What do I think about the stability of the solution?
It is a stable solution.
What do I think about the scalability of the solution?
It is a scalable solution. The best part was the working model when it transitioned from Demisto to Palo Alto Networks. Demisto had around 220 plus integrations when they launched. That was back in 2018 before it was acquired by Palo Alto Networks. But automation can be increased.
How are customer service and support?
The customer service and support are very good. Palo Alto has scaled well.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We've worked with Cortex XSOAR. We haven't worked with other SOAR solutions much.
From my experience, Cortex XSOAR is a leading product in the market. While I haven't worked with competing products like Phantom to offer a comparative analysis, it's standing against Microsoft's Azure Sentinel SOAR solution.
Cortex XSOAR is indeed a market leader. It may come at a higher price point, but it supports a vast technology ecosystem and offers a comprehensive suite of features, such as inbuilt ITSM management, a war room, an advisory system, threat intelligence connections, and a lot of integrations. The communication capabilities are exceptional. When it comes to top-tier products like Cortex XSOAR, we're paying for premium quality.
What about the implementation team?
You have to spend a dedicated core engineer and a lead team to tune and tweak it. But once you do that, it all runs automatically. You will save money on a lot of analysts or multiple analysis jobs because a lot of automation will be done for savings, especially since it's all based on machine learning now.
At the end of the day, I cannot remove or unplug the analysts, but I can reduce the number. If I have 20 people managing and monitoring an endpoint solution or a SIEM solution for one organization, I can reduce it to at least one-fourth, and you will save a lot of money.
What's my experience with pricing, setup cost, and licensing?
The pricing is fair. The pricing reflects the value and feature set it offers.
For example, with the purchase of a license, a dedicated success team, professional support, and integration assistance are part of the package.
People pay for the right value, but the organization has to leverage it fully. If they don’t, it can be problematic. They might end up wasting money on something they don’t need.
Which other solutions did I evaluate?
When a client wants to economize on licenses—preferring development and technology investment over licensing fees—the Elastic SIEM tool is a zero-cost option we haven't fully explored yet, either as a company or personally.
Technologies like QRadar and cloud-based projects such as QRock are in the market.
Splunk is certainly costly, but it offers strong technology and cloud infrastructure. Sentinel is cloud-exclusive and a bit expensive but advanced. There's a trade-off.
However, if a customer has a limited budget for licenses but can afford operational expenses, we need to investigate Elastic, which operates like any data lake, offering quick searches and high data storage capacity depending on the computing power. One could manage hundreds of GB per hour, running analytics effectively.
Nonetheless, clients must invest in building their security technologies and partnerships, which is resource-heavy SIEM. Elastic is expanding its offerings, but it still leads to a platform-based model that many opt for due to its cost-effectiveness. So, I have evaluated all these SIEM solutions.
My company is involved with SOAR, but not to a great extent. Post-COVID, there are not many people who show interest in SOAR solutions and many customers are now reluctant to allocate budgets for this.
Open-source alternatives are gaining traction, which is why we're considering developing capabilities in that area. With Microsoft's Sentinel, we see a unique case where its SOAR capabilities are more cost-effective. Hence, it has seen some adoption.
However, my direct experience with a comprehensive SOAR solution is with Cortex XSOAR, which is a product of Palo Alto Networks—previously known as Demisto.
What other advice do I have?
Overall, I would rate the solution a nine out of ten. The platform is constantly evolving, offering freeware and community editions. You can clearly go for it. The advice is to opt for it and use it to the max.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Cybersecurity Engineer (Security Operations & Engineering) at a manufacturing company with 10,001+ employees
Automates tasks and reducing manual effort and efficient security orchestration
Pros and Cons
- "The most valuable feature is its capability to automate responses and collect information for any security event before you even delve into the details. It's a vast product with an active roadmap, so I'm satisfied with it for now. It's very efficient at data collection and correlation."
- "There is room for improvement in support. The response time could be faster."
What is our primary use case?
It is a security orchestration and automation tool.
It basically lets us automate and orchestrate tasks across all your security tools. Imagine integrating our vulnerability management tool with XSOAR. For example, we get a ServiceNow ticket requesting a scan for a specific server before it goes live. XSOAR can trigger that scan automatically, streamlining the entire process. That's the power of XSOAR—automating repetitive tasks and freeing up your security team for more strategic work.
What is most valuable?
The most valuable feature is its capability to automate responses and collect information for any security event before you even delve into the details.
It's a vast product with an active roadmap, so I'm satisfied with it for now. It's very efficient at data collection and correlation.
What needs improvement?
There is room for improvement in support. The response time could be faster.
For how long have I used the solution?
We have been using it for two years now. It's cloud-based and hosted by Palo Alto.
What do I think about the stability of the solution?
It's stable. The features and functionalities work as intended mostly. It's a good, reliable product.
What do I think about the scalability of the solution?
We have six users actively using XSOAR. XSOAR is specifically for security teams, it is not for everyone to use.
How are customer service and support?
The customer service and support are okay, not the best, not the worst. Their initial response time is quite long, and even after you get back to them, it takes them a while to provide troubleshooting steps and follow through.
How would you rate customer service and support?
Negative
Which solution did I use previously and why did I switch?
We actually did run a couple of POCs for other products. My company switched to XSOAR because it's a very stable product, and its integration capabilities with most security tools are fantastic.
If it wasn't available, we'd have to manually develop integrations for each tool, which would be incredibly time-consuming. So, that's the main reason we went with XSOAR.
How was the initial setup?
For cloud deployments, it's a breeze. No installation is needed; just access the provided link and start working.
But for on-prem, it's a different story. You need to install multiple components and provision servers and integrate them with Palo Alto's platform according to documentation. It's a lengthy process, not overly complex, but due to the tool's architecture, it's unavoidable for on-prem installations. Cloud-based is definitely the easier option.
On-premise installation is complex and time-consuming, with multiple servers and integrations to manage. So, on-premise installation is a hassle.
What's my experience with pricing, setup cost, and licensing?
It's expensive, but the value it offers makes it worthwhile.
What other advice do I have?
It's a very stable product, definitely worth the investment. You won't regret your spending.
Overall, I would rate the solution a nine out of ten. The only reason it loses a point is the support team. Their performance hasn't reached the same level as other Palo Alto offerings.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
BDM/Chief Information Officer at Afcor PLC
A user-friendly solution simplifying security with easy configuration
Pros and Cons
- "The solution is user-friendly and easy to configure."
- "Palo Alto needs to develop more AI-centric products."
What is most valuable?
The solution is user-friendly and easy to configure.
What needs improvement?
Palo Alto needs to develop more AI-centric products. Also, the price could be cheaper. It doesn’t have infinite connectors.
For how long have I used the solution?
I have been using Palo Alto Networks Cortex XSOAR for a couple of years.
What do I think about the stability of the solution?
The product is very stable.
What do I think about the scalability of the solution?
5,000-7,000 users are using this solution.
How are customer service and support?
Technical support is knowledgeable.
Which solution did I use previously and why did I switch?
We used to work on the IBM XSOAR product, which was well-developed and competitive. The IBM component was strong, but Palo Alto Networks Cortex XSOAR performed well. The main difference lies in the level of suggestions provided by the playbooks when analyzing logs. IBM's suggestions to be better.
How was the initial setup?
The initial setup is simple. Your level of understanding significantly impacts the effectiveness of implementation. People may learn the hard way, especially post-implementation, highlighting the importance of a comprehensive experience.
What other advice do I have?
I recommended Palo Alto Networks Cortex XSOAR to a friend, and they have been using it to access and respond to issues in their data center. So far, there have been no complaints, not even worth mentioning. They also requested repairs through the platform.
The playbook is very good and user-friendly compared to IBM.
There are always things missing in some of the boxes. In some instances, there appears to be a leak. There are inconsistencies. Solutions like Palo Alto Networks Cortex XSOAR or similar products are necessary.
Overall, I rate the solution an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Palo Alto Networks Cortex XSOAR Report and get advice and tips from experienced pros
sharing their opinions.
Updated: July 2026
Popular Comparisons
IBM Security QRadar
Microsoft Sentinel
Elastic Security
AWS Security Hub
Arctic Wolf Managed Detection and Response
Stellar Cyber Open XDR
NetWitness NDR
Sumo Logic Security
Google Security Operations
ThreatConnect Threat Intelligence Platform (TIP)
Alert Logic MDR
Buyer's Guide
Download our free Palo Alto Networks Cortex XSOAR Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which Do You Recommend, Phantom or Demisto?
- Which solution do you prefer: Microsoft Sentinel or Palo Alto Networks Cortex XSOAR?
- Which SOAR product has the better value: Palo Alto Networks Cortex XSOAR or Swimlane? Why?
- What are the Top 5 cybersecurity trends in 2022?
- What is the difference between SIEM and SOAR platforms?
- What is an incident response playbook and how is it used in SOAR?
- What are the latest trends in Security Operations Center (SOC)?
- What tools and solutions do you use for automated incident response in an enterprise in 2022?
- How to evaluate SIEM detection rules?
- Why a Security Operations Center (SOC) is important?























