Try our new research platform with insights from 80,000+ expert users
Mostafa-Ahmed - PeerSpot reviewer
Cybersecurity incident response team lead at a tech vendor with 51-200 employees
Real User
Oct 1, 2023
Helps to address multiple cybersecurity and operational needs
Pros and Cons
  • "What I like most about Palo Alto Networks Cortex XSOAR is how user-friendly it is for development. It is much simpler to work with compared to similar tools I've used."
  • "It doesn't offer automatic internet reports out of the box."

What is our primary use case?

As an integrator, I have used Palo Alto Networks Cortex XSOAR in various customer environments for a wide range of purposes. This includes improving IT security, streamlining operations, automating incident response actions, creating playbooks with approvals, and enhancing integrations with different security tools. In essence, Cortex XSOAR serves as a versatile platform that helps address multiple cybersecurity and operational needs in organizations.

What is most valuable?

What I like most about Palo Alto Networks Cortex XSOAR is how user-friendly it is for development. It is much simpler to work with compared to similar tools I've used. If you can think of it, you can probably do it. However, there are some limitations, but speed isn't one of them.

What needs improvement?

One limitation I have noticed with Cortex XSOAR is that it doesn't offer automatic threat intel reports out of the box. However, you can achieve this through coding, and we have managed to do it in our own environment using scripts and playbooks. It is not a built-in feature, but it is possible with some coding skills. The good news is that Palo Alto Networks plans to make this process more automated in the future, but it is not available yet.

For how long have I used the solution?

I have been using Palo Alto Networks Cortex XSOAR for three years.

Buyer's Guide
Palo Alto Networks Cortex XSOAR
January 2026
Learn what your peers think about Palo Alto Networks Cortex XSOAR. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,821 professionals have used our research since 2012.

What do I think about the stability of the solution?

Cortex XSOAR's stability depends on the right sizing. When sized correctly, it is very stable and I would rate it a strong nine out of ten. But if the sizing is wrong, performance problems can arise. For instance, customers with closed storage systems had issues during heavy workloads. To keep it stable, having at least 3,000 IOPs is advised, especially for customers with high storage needs. So, sizing is key for a successful and stable experience.

What do I think about the scalability of the solution?

Cortex XSOAR is generally scalable and I would rate the scalability an eight out of ten. It is a bit challenging to migrate it from a regular database to a high-availability Elastic database, but it is possible. The ease of migration depends on how well it was planned from the start. Overall, it is a good option for scalability, but careful planning is essential for smooth transitions. The engine, which acts as a broker for connections and integrations in Cortex XSOAR, is highly efficient and reliable.

How was the initial setup?

The initial setup of Cortex XSOAR is generally straightforward, but it can get a bit tricky when dealing with a lot of use cases. If you plan to create large playbooks, it is crucial to size the system correctly from the start. Otherwise, you might run into performance issues. Apart from that, there aren't many problems with the implementation process. The challenge mainly revolves around sizing the system correctly, especially when customers have lots of ideas that could make playbooks complex and resource-intensive. So, it is important to plan carefully in such cases. In the best-case scenario, deploying Cortex XSOAR can be done in about 30 minutes when everything is prepared and ready. However, for full integration into the customer's environment, assuming no restrictions or communication issues, it might take roughly two and a half hours.

What other advice do I have?

Overall, I would rate the solution an eight out of ten. My advice to new users would be to plan ahead before implementing Cortex XSOAR. Understand your use cases well and have a solid strategy because the implementation is an ongoing process that you can always improve. Consider creating an adoption plan for what you will do this year and next year in terms of integration and use cases. Keep it user-friendly and introduce use cases gradually to your team instead of overwhelming them all at once. It's about taking steps to make it effective over time.

Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
Cemil Altug - PeerSpot reviewer
Hybrid Cyber Security Team Lead at a security firm with 11-50 employees
Real User
Top 10
Sep 4, 2023
Easy to use and scalable
Pros and Cons
  • "Palo Alto is easy to use."
  • "The dashboard could be better."

What is our primary use case?

The solution is used for security. 

What is most valuable?

Palo Alto is easy to use. 

What needs improvement?

The dashboard could be better. 

For how long have I used the solution?

I have used Palo Alto Network Cortex for six months. 

What do I think about the stability of the solution?

There are issues with stability as it was giving false positives and has bugs. I rate the stability a seven out of ten. 

What do I think about the scalability of the solution?

It is a scalable solution. There are two hundred users using the solution at present. I rate the scalability an eight out of ten. 

What about the implementation team?

The solution was deployed by analysts. 

What other advice do I have?

I rate the overall solution an eight out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Palo Alto Networks Cortex XSOAR
January 2026
Learn what your peers think about Palo Alto Networks Cortex XSOAR. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,821 professionals have used our research since 2012.
reviewer2125281 - PeerSpot reviewer
Intern Cybersecurity at a computer software company with 10,001+ employees
Real User
May 23, 2023
The drag-and-drop interface enables analysts with no programming knowledge to create playbooks easily
Pros and Cons
  • "The drag-and-drop interface enables analysts with no programming knowledge to create playbooks easily."
  • "XSOAR could have more integration options."

What is our primary use case?

I'm currently evaluating XSOAR to see what the solution can do. I'm playing around with the various features. 

What is most valuable?

The drag-and-drop interface enables analysts with no programming knowledge to create playbooks easily. 

What needs improvement?

XSOAR could have more integration options. 

For how long have I used the solution?

I have used XSOAR for two months.

What do I think about the stability of the solution?

XSOAR is stable. 

How was the initial setup?

Setting up XSOAR is straightforward and takes about 30 minutes. It doesn't require any special technology to implement it in any architecture.  You create a virtual machine, move the file to it, launch the installer, and let it run. It doesn't require any complex tasks. 

What other advice do I have?

I rate Palo Alto Networks Cortex XSOAR nine out of 10. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Business Development Manager at a tech services company with 51-200 employees
Real User
May 9, 2023
Has good stability and an easy initial setup process
Pros and Cons
  • "The solution is easy to deploy."
  • "The solution's technical support could be better."

What is our primary use case?

We use the solution to create playbooks for all the operational programs.

What needs improvement?

The solution's integration with non-security solutions will be helpful.

For how long have I used the solution?

We have been using the solution for almost two years now.

What do I think about the stability of the solution?

The solution is stable. I rate its stability an eight.

What do I think about the scalability of the solution?

I rate the solution's scalability as an eight. It is complex to scale.

How are customer service and support?

The solution's technical support team takes longer to reply to the queries.

How would you rate customer service and support?

Neutral

How was the initial setup?

The solution's initial setup process is straightforward.

What's my experience with pricing, setup cost, and licensing?

The solution's cost is reasonable. I rate its pricing as a five.

What other advice do I have?

I rate the solution an eight.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer1940673 - PeerSpot reviewer
Security Project Manager at a retailer with 10,001+ employees
Real User
Sep 1, 2022
Reliable, overall beneficial capabilities, but feature improvement needed
Pros and Cons
  • "The most valuable features of Palo Alto Networks Cortex XSOAR are its overall track record and features that fit our use case."
  • "Palo Alto Networks Cortex XSOAR could improve the Panorama feature. We had to turn it off because it was not working properly."

What is our primary use case?

We are using Palo Alto Networks Cortex XSOAR for automation.

What is most valuable?

The most valuable features of Palo Alto Networks Cortex XSOAR are its overall track record and features that fit our use case.

What needs improvement?

Palo Alto Networks Cortex XSOAR could improve the Panorama feature. We had to turn it off because it was not working properly.

For how long have I used the solution?

I have been using Palo Alto Networks Cortex XSOAR for approximately six months.

What do I think about the stability of the solution?

Palo Alto Networks Cortex XSOAR is a stable solution.

What do I think about the scalability of the solution?

The scalability of Palo Alto Networks Cortex XSOAR is fine for what we are using it for.

We have our SecOps department of user 50 people that are using the solution for alerts. We plan to increase usage in the future.

How are customer service and support?

The support from Palo Alto Networks Cortex XSOAR could improve. However, a lot of the support is poor.

What about the implementation team?

We have three people in the security operations that do the maintenance and support of Palo Alto Networks Cortex XSOAR.

What's my experience with pricing, setup cost, and licensing?

The price of Palo Alto Networks Cortex XSOAR is comparable to other solutions in the market.

What other advice do I have?

I rate Palo Alto Networks Cortex XSOAR a six out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Senior Information Technology Support Engineer at a energy/utilities company with 51-200 employees
Real User
Jul 28, 2022
Easy to install, able to expand, and reliable
Pros and Cons
  • "It’s easy to install."
  • "The integration could be better. Cortex, for example, does not work with iPhone."

What is our primary use case?

We primarily use the solution for network inspection.

What is most valuable?

The solution works well.

It’s easy to install.

It’s stable.

The solution can scale as needed.

What needs improvement?

The stability could be better.

The integration could be better. Cortex, for example, does not work with iPhone.

For how long have I used the solution?

I’ve been using the solution for less than one year.

What do I think about the stability of the solution?

Right now, it’s been stable for us. We may consider something from Microsoft in the future. It’s possible it could be more stable.

What do I think about the scalability of the solution?

The solution is quite scalable. If a company needs to expand it, it can do so.

How are customer service and support?

At the moment, we don’t actually get support from Palo Alto as we’ve never needed any help. I can’t say how helpful or responsive they would be.

Which solution did I use previously and why did I switch?

We’ve also worked with CrowdStrike. We switched as we weren’t happy with their detection capabilities.

How was the initial setup?

The installation is very easy to set up. It’s not overly complex or difficult.

The deployment took less than a week. I recall we had it up and running within a couple of days.

What about the implementation team?

In our case, we went to a consultant for installation assistance. However, a company might likely be able to handle it on its own.

What's my experience with pricing, setup cost, and licensing?

I can’t speak to the exact cost of the solution.

What other advice do I have?

This is a SaaS product.

I’d rate the solution nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Nicolo Corrado - PeerSpot reviewer
Consulente immobiliare at a comms service provider with 51-200 employees
Real User
Apr 2, 2022
I have no complaints about the stability
Pros and Cons
  • "I have no complaints about Cortex's stability."

    What is our primary use case?

    I'm using Cortex XSOAR to manage our network security.

    For how long have I used the solution?

    I've been using Cortex XSOAR for about one year.

    What do I think about the stability of the solution?

    I have no complaints about Cortex's stability.

    What do I think about the scalability of the solution?

    As far as I know, Cortex XSOAR's scalability is okay. I'm just a user, so I don't know.

    How was the initial setup?

    Setting up Cortex is straightforward. This use case is the easiest to implement. I had help from two or three technicians.

    What other advice do I have?

    I rate Palo Alto Networks Cortex XSOAR eight out of 10. I would recommend it to others.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer1469436 - PeerSpot reviewer
    Splunker, Networking and E-Mail Security Architect, Engineer and Guru at a healthcare company with 10,001+ employees
    Real User
    Sep 13, 2021
    Easy to use, stable, scalable, and has responsive support
    Pros and Cons
    • "It has an extensive list of integrations that are available out of the box which makes it easy to start."
    • "I would love to see more flexibility on what we can display and design on the dashboards."

    What is our primary use case?

    We use Palo Alto Networks Cortex XSOAR for several areas of security automation, such as phishing, investigating, mitigating, the detection of impossible travel, and consolidating threat information for our internal systems.

    How has it helped my organization?

    It reduces manual interactions of security analysts. Before they had to check on three, or four different websites to see if something was good or bad. Now, Cortex does all of that for us.

    What is most valuable?

    It is very easy to use.

    It has an extensive list of integrations that are available out of the box which makes it easy to start.

    What needs improvement?

    I would love to see more flexibility on what we can display and design on the dashboards.

    For how long have I used the solution?

    Palo Alto Networks Cortex XSOAR has been active for six months. 

    We are always on the latest version.

    What do I think about the stability of the solution?

    Palo Alto Networks Cortex XSOAR is pretty stable.

    What do I think about the scalability of the solution?

    It offers some architecture recommendations to make it really scalable if you choose.

    For example, hot standby, bond standby, clustering, and breaking out components in dedicated servers. You can go wild if you want to go wild, but we wanted to keep it easy and stable.

    Pretty much network security and SOC are the main users. I believe that we are licensed for 20 users.

    We are definitely extensively using this solution. We are currently training many additional teams to be self-sufficient in usage. The usage will increase more and more.

    How are customer service and technical support?

    With Palo Alto technical support, if you get to the right people, you get an answer very quickly. 

    What I like about the Cortex team is that they have a dedicated select center where you can get service in minutes and that's extremely helpful.

    Overall, I am satisfied with the technical support.

    Which solution did I use previously and why did I switch?

    We evaluated two or three other vendors. 

    We are a very big Palo Alto shop and we needed to have some Palo Alto features, which are implemented now in Cortex. We are pretty much guided in that direction for some of the security features we need for our firewalls.

    How was the initial setup?

    I would say the initial setup was really straightforward. 

    You need to be a little bit aware of Linux unless you buy the hosted version, then you don't need to know anything about it. If you decide you want to run it yourself, you should have some Linux skills because it's a Docker framework on Linux. Knowing a bit about that is handy.

    It was up and running in half a day.

    What about the implementation team?

    It only requires one person to maintain this solution. I do it myself along with many other tasks. In a larger environment, you split into two teams, OS maintenance and application maintenance.

    We had help from Palo Alto SE resource for the PoC, but the setup was completed on our own.

    What's my experience with pricing, setup cost, and licensing?

    We have a concurrent user license. 

    The licensing is a pretty high price for a user license per year.

    The base product is very cheap, you can even get it for free, but the fee per user is expensive. It is approx $10,000 or $20,000 per year for two user licenses.

    It's a great product, although it might become very pricey if you need several user licenses.

    They need to automate everything to reduce the number of user licenses needed. If it is an automated workflow, you don't need to be licensed.

    If Cortex sends an email asking a user to say yes or no, you don't need a license for that user. You just need a user license if you want to improve what Cortex does in terms of workbooks, cases, and more.

    Which other solutions did I evaluate?

    We evaluated Splunk for six months and decided against it three to six months ago.

    What other advice do I have?

    Have a very good understanding of what you want to automate. Define the process and make sure the integrations you need are available out of the box.

    I would also suggest starting simple. Try easy use cases first and until you feel confident before you get into more complex use cases.

    I would rate Palo Alto Networks Cortex XSOAR a nine out of ten.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free Palo Alto Networks Cortex XSOAR Report and get advice and tips from experienced pros sharing their opinions.
    Updated: January 2026
    Buyer's Guide
    Download our free Palo Alto Networks Cortex XSOAR Report and get advice and tips from experienced pros sharing their opinions.