Network and Information Security at a tech services company with 10,001+ employees
Real User
Top 20
Highly scalable solution
Pros and Cons
  • "It is quite scalable. I would rate it a ten out of ten."
  • "The dashboard performance could be improved."

What is our primary use case?

I work for a company, and we provide support and complete end-to-end management of the product for our customers who hold the product.

How has it helped my organization?

Over thirty users are currently using Palo Alto Networks Cortex XSOAR in your organization. The role is inclusive, like administrator and engineer.

What is most valuable?

According to Gartner, it's a leader in NID. Customers are investing more in it, and that's why we are using the product.

What needs improvement?

The dashboard performance could be improved.

Another area of improvement is a support team. Moreover, we need to pay for modifying anything with scripting in terms of customization. It can be a challenge if the person isn't 100% good with scripting.

Buyer's Guide
Palo Alto Networks Cortex XSOAR
April 2024
Learn what your peers think about Palo Alto Networks Cortex XSOAR. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
770,428 professionals have used our research since 2012.

For how long have I used the solution?

I have been using this solution for around four years and currently use the latest version.

What do I think about the stability of the solution?

It is a stable solution. I would rate it a nine out of ten.

What do I think about the scalability of the solution?

It is quite scalable. I would rate it a ten out of ten.

How are customer service and support?

Customer support could be better.

How would you rate customer service and support?

Neutral

How was the initial setup?

For maintenance, two or three engineers are involved.

What's my experience with pricing, setup cost, and licensing?

We use the yearly subscription.

What other advice do I have?

Overall, I rate the solution a nine out of ten.

Which deployment model are you using for this solution?

Private Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Google
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Security Professional at a tech services company with 51-200 employees
Real User
Top 20
Great scalability for medium size organizations, diverse automation opportunities, and professional technical support
Pros and Cons
  • "The most valuable feature is automation."
  • "I think they should increase their collaboration base."

What is our primary use case?

Our primary case issues are phishing, TI, and sensors.

What is most valuable?

The most valuable feature is automation. There is a huge variety of automation that can help any team and there is a threat model.

What needs improvement?

I think they should increase their collaboration base so that XSOAR can be utilized for any number of automation.

For how long have I used the solution?

I have been using Palo Alto Networks Cortex XSOAR for the past two years.

What do I think about the stability of the solution?

Stability takes around three to six months to achieve complete stability in the environment.

What do I think about the scalability of the solution?

The existing model is good, but if we go for big deployments, I think there are a few challenges in scalability. They use their internal BoltDB, which is good for a medium organization, but for large organizations, they support Elasticsearch, which is too costly. The DR capabilities are not good.

How are customer service and support?

Technical support is professional, but they are not very friendly. The overall remote support is not where it should be.

How would you rate customer service and support?

Neutral

How was the initial setup?

Palo Alto Networks Cortex XSOAR has a straightforward setup. Stability takes three months to six months, and then further stability, performance, and then complete utilization. Usually, it takes around a year to deploy it fully.

What about the implementation team?

Normally, we use a third-party team to help us with the deployment.

What other advice do I have?

I would rate Palo Alto Networks Cortex XSOAR an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Palo Alto Networks Cortex XSOAR
April 2024
Learn what your peers think about Palo Alto Networks Cortex XSOAR. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
770,428 professionals have used our research since 2012.
Regional Director, Customer Success (GTM Solutions & Services) at a tech services company with 51-200 employees
MSP
Easy to set up with good technical support and good stability
Pros and Cons
  • "The pricing is very good."
  • "The user interface could be a bit better."

What is our primary use case?

We primarily use the solution for automation and the orchestration of security.

What is most valuable?

We've only just installed the solution and need time to explore its functionality and capabilities. So far, we haven't experienced any issues.

The stability has been good overall.

The initial implementation wasn't overly complex. It was easy.

The pricing is very good.

Technical support is helpful and responsive.

What needs improvement?

Although we haven't used the solution for too long, we haven't come across any issues and haven't noticed any features that are lacking. We're largely satisfied with the offering. 

The user interface could be a bit better. It's the only aspect I've noticed that could possibly be improved. 

Other than that, we've been pretty happy with it.

For how long have I used the solution?

We've just implemented the solution. We've only been using it for a few weeks. It hasn't been too long just yet.

What do I think about the stability of the solution?

So far, we have found the stability to be very reliable. There are no bugs or glitches. It doesn't crash or freeze. The performance, in the few weeks we've used it, has been good.

How are customer service and technical support?

Technical support has been helpful so far. They are knowledgeable and responsive and we've been very satisfied with their level of support.

How was the initial setup?

The installation was very straightforward. It only took about a day. Not even that long. The deployment was fast. A company shouldn't have run into any issues with the initial setup.

What about the implementation team?

I was able to handle the implementation myself. I did not need the assistance of an integrator or consultant.

What's my experience with pricing, setup cost, and licensing?

We've found the pricing to be very reasonable. It's not particularly expensive.

The customers do not have to pay for licensing; we deliver it for free.

What other advice do I have?

We have the solution integrated into our QRadar.

In the time we've used it, from what I've experienced, I'd rate the product at an eight out of ten. We've had a very positive experience.

I would recommend the solution to other companies.

Disclosure: My company has a business relationship with this vendor other than being a customer: Implementer
PeerSpot user
CyberSecurity Consultant at Information Technology Solutions- ITS
Real User
User-friendly solution with good stability
Pros and Cons
  • "It is a scalable solution."
  • "Its dashboard features need improvement."

What is most valuable?

The solution is user-friendly and provides integration with multiple products.

What needs improvement?

The solution's features for reporting and dashboards need improvement. They need more customization options.

For how long have I used the solution?

We have been using the solution for two years.

What do I think about the stability of the solution?

The solution is stable. I rate its stability a nine out of ten.

What do I think about the scalability of the solution?

It is a scalable solution. I rate its scalability an eight out of ten.

How was the initial setup?

The solution's initial setup process with proxy environments is complicated. It takes an hour to two complete.

I rate the process a seven out of ten.

What's my experience with pricing, setup cost, and licensing?

The solution's cost is high. I rate its pricing a nine out of ten.

What other advice do I have?

I rate the solution a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Nicolo Corrado - PeerSpot reviewer
Consulente immobiliare at Libero
Real User
I have no complaints about the stability
Pros and Cons
  • "I have no complaints about Cortex's stability."

    What is our primary use case?

    I'm using Cortex XSOAR to manage our network security.

    For how long have I used the solution?

    I've been using Cortex XSOAR for about one year.

    What do I think about the stability of the solution?

    I have no complaints about Cortex's stability.

    What do I think about the scalability of the solution?

    As far as I know, Cortex XSOAR's scalability is okay. I'm just a user, so I don't know.

    How was the initial setup?

    Setting up Cortex is straightforward. This use case is the easiest to implement. I had help from two or three technicians.

    What other advice do I have?

    I rate Palo Alto Networks Cortex XSOAR eight out of 10. I would recommend it to others.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Cyber Security Analyst at a tech services company with 11-50 employees
    Reseller
    A scalable and easy-to-use tool that can be used for automation
    Pros and Cons
    • "The product is quite easy to use."
    • "We need a little hands-on experience to install the solution."

    What is our primary use case?

    Our customers use the product for automation.

    What is most valuable?

    It is a good tool for automation. The product is quite easy to use. It provides great integrations.

    What needs improvement?

    We need a little hands-on experience to install the solution. The installation process is technical.

    For how long have I used the solution?

    I have been working with the solution for six months.

    What do I think about the stability of the solution?

    The solution is quite stable. I rate the stability an eight out of ten. So far, the stability is okay.

    What do I think about the scalability of the solution?

    The product is scalable. I rate the scalability an eight out of ten. At a managed service level, the product can really scale well. So far, it’s good. Our clients are small, medium and enterprise businesses.

    How was the initial setup?

    We will need specific knowledge to install the product, depending on the use case.

    What about the implementation team?

    We need to maintain the solution from time to time, especially with the upgrades. One person is enough to maintain the product.

    What's my experience with pricing, setup cost, and licensing?

    The solution is a bit on the expensive side. I rate the pricing a seven out of ten.

    What other advice do I have?

    We are resellers and managed service providers of the product. The infrastructure is handled by someone else. I do the analysis. Overall, I rate the product an eight out of ten.

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
    PeerSpot user
    Consultant at a tech services company with 501-1,000 employees
    Reseller
    High level log overviews, integrates well, and effective orchestration
    Pros and Cons
    • "The most valuable features are the orchestration because of the way in which it coordinates the loss from all the devices and it provides us with a high-level overview of the critical log information."
    • "There should be an on-premise version available for customers to have different choices."

    What is our primary use case?

    We are using this solution to have a completely organized SOC from a list of devices in our environment. We are able to manage all of our devices, such as firewalls and endpoint protection solutions.

    What is most valuable?

    The most valuable features are the orchestration because of the way in which it coordinates the loss from all the devices and it provides us with a high-level overview of the critical log information. Additionally, this solution integrates very well, we have integrated a Palo Alto firewall and everything is working perfectly.

    What needs improvement?

    There should be an on-premise version available for customers to have different choices.

    For how long have I used the solution?

    I have been using this solution for approximately one year.

    What do I think about the stability of the solution?

    The solution is very reliable because it is on the cloud.

    What do I think about the scalability of the solution?

    The solution is scalable. We have already approximately 200 devices deployed into the cloud and we are planning to increase usage in the future. We have approximately 600 employees using this solution in my organization and the solution has been completely coordinating the logs of all these users well.

    How are customer service and technical support?

    The technical support is satisfactory. If we need any clarification or faced any issues we have been in contact with the support. However, there is room for improvement.

    How was the initial setup?

    The solution is easy to deploy and manage.

    What's my experience with pricing, setup cost, and licensing?

    There is a yearly license required for this solution and it is expensive.

    Which other solutions did I evaluate?

    We have evaluated other solutions but they do not compare with the number of features this solution provides. There is a wide range of features in this solution.

    What other advice do I have?

    I would recommend this solution to those that already have a SOC or a NOC. It will enhance their logs and XSOAR will handle their internet activities. 

    If they are not involved with SOCs or NOCs then I do not think they require this solution.

    I rate Palo Alto Networks Cortex XSOAR an eight out of ten.

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
    PeerSpot user
    Network Security Engineer at a tech services company with 201-500 employees
    Real User
    Very scalable, awesome automation, and awesome technical support
    Pros and Cons
    • "The automation part and the playbook creation part are awesome. The way it is responding to the customers and incidents is also very good. In the SOC environment, I guess it will carry out around 50% of the work."
    • "For building automation, there is not a lot of good documentation. The documentation is there, but it is not very good from my perspective. There should be an improvement in this area. I don't see issues with anything else. In terms of new features, I have heard that other products have EBA functionality. It would be good if this functionality could be added."

    What is our primary use case?

    The use cases basically came from the customers. Most of the time, the major concern is from a security perspective because various kinds of attacks are happening. To restrict or stop those attacks, we are building playbooks. We are also automating repetitive tasks.

    We are using on-premise as well as cloud deployments.

    What is most valuable?

    The automation part and the playbook creation part are awesome. The way it is responding to the customers and incidents is also very good. In the SOC environment, I guess it will carry out around 50% of the work.

    What needs improvement?

    For building automation, there is not a lot of good documentation. The documentation is there, but it is not very good from my perspective. There should be an improvement in this area. I don't see issues with anything else.

    In terms of new features, I have heard that other products have EBA functionality. It would be good if this functionality could be added.

    For how long have I used the solution?

    I have been working on this solution for the last four months.

    What do I think about the stability of the solution?

    Its stability is okay.

    What do I think about the scalability of the solution?

    It is very scalable. It can be easily integrated with other third-party APIs.

    How are customer service and technical support?

    Their technical support is awesome. It is far better than the technical support of any other company.

    How was the initial setup?

    The setup is very easy. It is very straightforward. The deployment took around 15 minutes.

    What's my experience with pricing, setup cost, and licensing?

    From the cost perspective, I have heard that its price is a bit high as compared to other similar products.

    What other advice do I have?

    For each SOC and MSS environment, I would recommend using Cortex XSOAR for better productivity, scalability, performance, and efficiency. A lot of manual work is happening right now, and that could be avoided. People can be utilized for more productive work.

    I would rate Palo Alto Network Cortex XSOAR an eight out of ten.

    Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
    PeerSpot user
    Buyer's Guide
    Download our free Palo Alto Networks Cortex XSOAR Report and get advice and tips from experienced pros sharing their opinions.
    Updated: April 2024
    Buyer's Guide
    Download our free Palo Alto Networks Cortex XSOAR Report and get advice and tips from experienced pros sharing their opinions.