Assistant Superintendent with 51-200 employees
Real User
Straightforward to set up and the support is highly-rated
Pros and Cons
  • "The interface is easy to use and it is more up to date than our previous solution."
  • "Although I would say this product is highly-rated, it could probably do more because nothing does everything that you want."

What is our primary use case?

This product is part of a package that makes up our security solution.

What is most valuable?

The interface is easy to use and it is more up to date than our previous solution.

What needs improvement?

Although I would say this product is highly-rated, it could probably do more because nothing does everything that you want.

For how long have I used the solution?

We have been using this product for about four months.

Buyer's Guide
Cortex XDR by Palo Alto Networks
May 2024
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
772,127 professionals have used our research since 2012.

What do I think about the scalability of the solution?

We think that this product will help us grow. We think that it meets our needs currently, and we can grow with it over time. There 12 people in the IT department who currently manage it. 

How are customer service and support?

The support is excellent. We had a couple of issues that we had to call for and I would say that they are highly rated.

Which solution did I use previously and why did I switch?

Our older solution was from Fortinet. It was out of date and more difficult to use. The IT staff say that the Palo Alto product is better.

How was the initial setup?

The initial setup was straightforward.

What about the implementation team?

We worked with a reseller. They came in, we told them what we wanted to do and they set it up to our spec. The person who came in and helped support us was highly skilled and it worked seamlessly.

What's my experience with pricing, setup cost, and licensing?

We pay about $50,000 USD per year for a bundle that includes Cortex XDR.

Which other solutions did I evaluate?

We evaluated Palo Alto and Trend Micro, and we opted for the Palo Alto Cortex XDR.

What other advice do I have?

I don't use this product on a daily basis but we like what we have so far and I would definitely recommend it to other users.

My advice is to make sure that you have a good implementor and that the reseller you're purchasing from gives you a highly-qualified engineer.

Overall, we are happy with this product but that said, nothing does everything that you want.

I would rate this solution a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Security Engineer at U.S. Acute Care Solutions
Real User
We've had a significant increase in blocking with a decrease in false positives
Pros and Cons
  • "We've had a significant increase in blocking with a decrease in false positives, because it's looking at how the files work, not just a list of files that it's been told to look for."
  • "The anti-exploit is impenetrable. We chose Traps because it is the only product that we were not able to get anything past."
  • "They have the worst support, as a company, that I have ever worked with, as they are difficult to get a hold of and keep on the phone. They don't know what they are talking about when you get them on the phone. They don't like to respond to messages when you send them to them. They like to "research problems" for weeks on end, then pass you off to somebody else."

What is our primary use case?

Our primary use case is anti-malware and anti-exploit.

How has it helped my organization?

Traditional anti-virus is signature-based, whereas Traps is behavior-based. Therefore, it doesn't necessarily whitelist things, it looks for anything with bad behavior. Thus, we've had a significant increase in blocking with a decrease in false positives, because it's looking at how the files work, not just a list of files that it's been told to look for.

What is most valuable?

The anti-exploit is impenetrable. We chose Traps because it is the only product that we were not able to get anything past.

What needs improvement?

Going from version 4 to version 5, they had a major change in their user interface. Version 5 is now all cloud managed, while it has a very intuitive, useful interface, it doesn't have all the features that were in the version 4 interface. For example, we lost being able to automatically trigger upgrades, like creating manual groups to upgrade with. It doesn't currently have the ability to use the Active Directory to create groups. 

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

It's fairly stable. They do have bugs which come up every once in a while, but they're usually good about getting them taken care of within a release.

What do I think about the scalability of the solution?

It is definitely scalable.

Primarily, it is just being used by myself. The help desk also uses it. There are probably a total of around ten users.

We've deployed it to about 1500 endpoints so far. There is a possibility that we may expand our usage, but not in the foreseeable future. We are at pretty much at 100 percent deployment at this point.

How are customer service and technical support?

I would describe Palo Alto's technical support as audio waterboarding. They have the worst support, as a company, that I have ever worked with, as they are difficult to get a hold of and keep on the phone. They don't know what they are talking about when you get them on the phone. They don't like to respond to messages when you send them to them. They like to "research problems" for weeks on end, then pass you off to somebody else.

Which solution did I use previously and why did I switch?

We were previously using Sophos for antivirus, and are still using Sophos for antivirus, but we're using Traps to augment it.

How was the initial setup?

The initial setup was pretty straightforward on version 4, but on version 5, it is almost idiot-proof.

The initial deployment of getting the servers and everything up took about a week, but getting everything deployed was somewhere closer to six weeks.

What about the implementation team?

We implemented it in-house. We incrementally did some systems to make sure that it wouldn't block anything that it shouldn't. After that, we used Active Directory to push it to everything else.

Very little staff is required for deployment and maintenance, as Traps is self-maintaining.

What was our ROI?

I feel that we have seen ROI. There have been a number of blocked, bad files that could have gotten through, but were stopped by Traps.

What's my experience with pricing, setup cost, and licensing?

The pricing seems fair, and I do like the licensing model. You use wherever they are, and it is elastic. So, if you have 1100 computers today, you can license that. Therefore, as long as you're below your licensing cap, you're fine.

Which other solutions did I evaluate?

We looked at Palo Alto vs Sophos, which has a anti-malware system called Intercept X, but it did quite literally nothing. We thought about Symantec, but we didn't end up testing them against Traps.

What other advice do I have?

The implementation is fairly straightforward and easy. With version 5, everything is now on the cloud. It is easy to work with and use. I would use mobile device management (MDM) or Active Directory (AD) to push the file everywhere when installing it, as it will auto go from there. The management is pretty low. Thus, it will be set it, and for the most part, you can forget it.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
Cortex XDR by Palo Alto Networks
May 2024
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
772,127 professionals have used our research since 2012.
MartinPulpan - PeerSpot reviewer
Owner and Executive Director at Cloud 9 s.r.o.
Real User
Good features, strong protection, and very scalable and stable
Pros and Cons
  • "Cortex XDR is a very capable solution for protecting large networks and a lot of endpoints. It's very useful because the automation is very high, and if you combine it with the features on Palo Alto firewalls, it provides very strong protection."
  • "It's more focused on network communication. If a customer wants to increase the level of protection and start working with documents, it's impossible to integrate these features into the system. It's more of a communication-oriented system than a content security-oriented system."

What is our primary use case?

It's mainly for protection against malware. We work very closely with a major partner of Palo Alto in the Czech Republic, and we have experience with the whole XDR solution. It's very useful for us and a very capable solution.

How has it helped my organization?

Clients have a big problem with phishing campaigns and phishing attacks. Cortex XDR provides some level of protection against malware spreading in the network with a wrong click of users.

What is most valuable?

Cortex XDR is a very capable solution for protecting large networks and a lot of endpoints. It's very useful because the automation is very high, and if you combine it with the features on Palo Alto firewalls, it provides very strong protection.

What needs improvement?

Its price is too high. That's a big problem for customers.

It's more focused on network communication. If a customer wants to increase the level of protection and start working with documents, it's impossible to integrate these features into the system. It's more of a communication-oriented system than a content security-oriented system.

In terms of additional features, there is very strong development. I have seen the roadmap, and we will see what happens. The roadmap looks nice, but it's still more of a network security solution than a content-security solution. The development in network security is quite strong. I'm very happy with that, but if a customer would like to implement a zero-trust security concept, it's necessary to combine this solution with other vendors. There is some part of the integration that is not so easy because you have to integrate rules and some features. It's not so automatic in network communication. You have to make some appropriate automation there, or you have to do it manually. It's time-consuming and it's also expensive.

For how long have I used the solution?

I have been using it from the beginning. It has been more than six years.

What do I think about the stability of the solution?

It's a very stable solution. I would rate it a nine out of ten in terms of stability.

What do I think about the scalability of the solution?

It's a very scalable solution. If you compare it with a SIEM solution from Palo Alto, it's very powerful. I would rate it a nine out of ten in terms of scalability. It's definitely for enterprises.

How are customer service and support?

Their technical support is not bad, but sometimes, when we have some issues, the support teams from Europe or Central Europe are not able to help us. We have to escalate the issue somewhere else, such as to the US. They have a very strong support team there, but it's time-consuming. Sometimes, it takes them days or weeks to solve some tricky problems, but their support for standard issues is okay. There is a very good response, but for a technical issue, it's sometimes more difficult. I would rate their support a seven out of ten.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I also worked a little bit with SentinelOne. Cortex XDR is very similar to the SentinelOne solution from the features point of view. It's a little bit different technology, but both solutions are very capable.

How was the initial setup?

It's somewhere in the middle. It's not for beginners, but if you know what to do, it's quite easy.

It's a cloud-based solution, which sometimes is an issue for customers. In the past, it was on-prem, but Palo Alto decided to change the policy and everything is cloud-based or located in the cloud. It's not a security problem from my point of view, but a few customers feel uncomfortable with sending data to the cloud and back.

What about the implementation team?

Very often, it's an in-house implementation.

What's my experience with pricing, setup cost, and licensing?

It's the most expensive solution, but features-wise, it's quite strong. It's very good for protection, so the results are very good in the case of protection. I would rate it a two out of ten in terms of pricing.

What other advice do I have?

Overall, I would rate it an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Jitendra_Singh - PeerSpot reviewer
Senior Vice President at Chi Networks
Real User
Helps to secure your infrastructure
Pros and Cons
  • "Cortex XDR's most valuable feature is its intelligence-based dashboards."
  • "Cortex XDR could be improved with more GUI features."

What is our primary use case?

I primarily use Cortex XDR to protect end-users from ransomware, malware, spam, and phishing.

How has it helped my organization?

Cortex XDR alerts us on the dashboard when there's a threat, which allows us to restrict that user and helps secure our infrastructure.

What is most valuable?

Cortex XDR's most valuable feature is its intelligence-based dashboards.

What needs improvement?

Cortex XDR could be improved with more GUI features.

For how long have I used the solution?

I've been using Cortex XDR for a year.

What do I think about the stability of the solution?

Cortex XDR is quite stable.

What do I think about the scalability of the solution?

Cortex XDR is scalable.

How are customer service and support?

Cortex XDR's technical support is really good, though their knowledge of endpoint protection could be deeper.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup was quite straightforward, and deployment took two to three days.

What about the implementation team?

We used an in-house team.

What's my experience with pricing, setup cost, and licensing?

Cortex XDR's pricing is ok. We pay about $20 a year for our license.

What other advice do I have?

I would give Cortex XDR a rating of eight out of ten.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Mantu Shaw - PeerSpot reviewer
Project Manager at Incedo Inc.
MSP
Top 20
A stable part of our security solution that correlates logs from relevant sources
Pros and Cons
  • "The most valuable for us is the correlation feature."
  • "There are some third-party solutions that are difficult to integrate with, which is something that can be improved."

What is our primary use case?

We use Cortex XDR as part of our security solution.

How has it helped my organization?

its a very good solution and single solution for entire infrastructure, give us good co-relation of incident. Single solution for Network, Endpoint, Servers. 

What is most valuable?

The most valuable for us is the correlation feature. You are able to correlate data that is coming from the firewall, network, server, and endpoints. This is one of our main requirements and makes for a good product.

It works with the data lake in an agent-based or agentless manner.

It is easy to integrate most with network devices, including firewalls, and Active Directory. We use firewalls from different vendors including Palo Alto and Check Point, and it supports them.

What needs improvement?

There are some third-party solutions that are difficult to integrate with, which is something that can be improved.

What do I think about the stability of the solution?

We have not experienced any issues with respect to stability at this point.

What do I think about the scalability of the solution?

Scalability has not been a problem.

How are customer service and support?

We have been in contact with technical support and are satisfied with them.

How would you rate customer service and support?

Positive

How was the initial setup?

its a Straightforward

What about the implementation team?

We have an in-house team for deployment and maintenance.

What was our ROI?

It replace multiple solution and due to this it will reduce the Administrative effort.

Which other solutions did I evaluate?

I have run a PoC with both CrowdStrike and Cortex XDR, and from my observation, I felt that Cortex was much better at meeting our requirements. It is also easier to use.

CrowdStrike was difficult when it came to integrating with other products and it does not work on mobile devices.

What other advice do I have?

My advice for anybody who is considering Cortex XDR is that it is a complete solution, and has very good features. From my experience, it is one of the better ones in the market. That said, no product is 100%.

I would rate this solution a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Zubair Ahmad - PeerSpot reviewer
Senior Chief Manager at Arcil
Real User
Top 5
Stable, scalable, and best for avoiding security issues
Pros and Cons
  • "Best solution for avoiding security breaches, malware attacks, and other kinds of security issues."
  • "Limited remote connection."

What is our primary use case?

I primarily use Cortex XDR for endpoint security.

How has it helped my organization?

PALO ALTO CORTEX XDR brings visibility of all activity going in end point system and server. This helps us to investigate and take corrective action by blocking and allowing necessary services in the system. 

What is most valuable?

Alerts regarding the incidence happening in system and easy to block and allow the services and external device control.

What needs improvement?

An area for improvement is the remote connection for administrators - this is available in the current version but is limited as it's a command-based model rather than GUI-based.

For how long have I used the solution?

I have been using Cortex XDR for around four months.

What do I think about the stability of the solution?

Cortex XDR is stable.

What do I think about the scalability of the solution?

The product is really easy to scale.

How are customer service and support?

Good support and services

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Previously, I used McAfee Antivirus, Memory utilization very high which doesn't yet have virtualization or a dashboard. I found that product to be a little difficult, and it was not linked to a real solution, so I decided to go with Cortex XDR as it's one of the best XDR solutions for security.

How was the initial setup?

The initial setup is a little complex because it requires a lot of preparation in terms of understanding each system and going through the documentation and dashboards.

What about the implementation team?

I implemented with the help of one partner who did the basic configuration of our firewall. Deployment took approximately ten days.

What was our ROI?

Security of systems

What's my experience with pricing, setup cost, and licensing?

This is a very costly product.

Which other solutions did I evaluate?

We have evaluated Cynet, Crowed Strike and Sentinel.

What other advice do I have?

Cortex is the best solution for avoiding security breaches, malware attacks, and other kinds of security issues. I would rate this solution as eight out of ten.

Which deployment model are you using for this solution?

Private Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Digital Business Solutions Manager at Bahrain Telecommunication Company BSC (Batelco)
Real User
A stable and scalable extended detection and response platform, but it would be better if they educated their customers more
Pros and Cons
  • "It's a nice product that's stable and scalable."
  • "It would be better if they could educate the customers more. Some sort of seminars and roadshows will help educate the customers and show what the product can do. The price could be better. It would also help if they had a team for deployment and support."

What is our primary use case?

We don't have many customers moving to Cortex XDR by Palo Alto Networks. But recently, we started offering them both pro and basic options. 

What is most valuable?

It's a nice product that's stable and scalable.

What needs improvement?

It would be better if they could educate the customers more. Some sort of seminars and roadshows will help educate the customers and show what the product can do. The price could be better. It would also help if they had a team for deployment and support.

What do I think about the stability of the solution?

The product is stable. Palo Alto only works on security, and the product by default is stable. They are releasing new features, OS, and an ML-based thing on the firewall itself, which is quite impressive. Palo Alto is quite stable compared to other competitors in the market.

What do I think about the scalability of the solution?

It's scalable. I see whatever is written on their datasheets, and all it's real. If I talk to some other vendor and they say that they currently provide 20 Gbps reports, but when you activate it, IPSec and all, it goes to 2 Gbps. With Palo Alto, whatever is there is working, and it's scalable.

How are customer service and technical support?

Technical support is quite good. When compared to others, I feel it's quite impressive.

What's my experience with pricing, setup cost, and licensing?

The price is on the higher side, but it's okay.

What other advice do I have?

I would tell potential users that it's a complete solution from Palo Alto with firewalls and all to give you more precise logs and information. Product-wise, it's top of the line. If you have investment, always go for that and go for the best solution. 

Palo Alto is one of the tech vendors that always provides top-of-the-line products. Price-wise it will be on the higher side, but it depends on how you deal with the backend support or the account manager of Palo Alto to get that discount. 

On a scale from one to ten, I would give Cortex XDR by Palo Alto Networks a seven.

Disclosure: My company has a business relationship with this vendor other than being a customer: partner
PeerSpot user
Disha Shah - PeerSpot reviewer
Technical Associate at HTH Global Network
Real User
Top 20
Great threat detection capabilities and good internal threat intelligence
Pros and Cons
  • "Has great threat detection capabilities."
  • "The encryption is not up to the mark."

What is our primary use case?

This solution is a next-generation antivirus with more advanced capability and security. We have a partnership with Palo Alto.

What is most valuable?

Cortex XDR is very easy to deploy and has great threat detection capabilities and good internal threat intelligence.

It uses advanced AI analytics, behavior analytics, and custom-made detection to detect advanced threats before they occur.

If a customer says it's expensive- let's say I will say no it is not. Other values are added then it is more reasonable having strong features.

With a click, I can access the system and isolate it from other networks, and then go into a further forensic investigation of the current threat without compromising anything else.

Its stitches with external logs are perfect and enhanced.

What needs improvement?

1. Disk Encryption capability.

2. User group-wise admin role. They have module-wise roles but a user group-wise role is not available.

For how long have I used the solution?

We've been supplying this solution to customers for two years. 

What do I think about the stability of the solution?

I have found this solution as NG AV is most stable compare with other solution

What do I think about the scalability of the solution?

The scalability is perfect.

How was the initial setup?

The initial setup is very easy.

What about the implementation team?

We implemented the solution with a vendor team, HTH Global Network. Their expertise is an eight out of ten.

What other advice do I have?

I recommend this solution, it works well and I rate it a nine out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer:
PeerSpot user
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2024
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros sharing their opinions.