- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-26-2023 02:34 PM
Its XDR plus supposedly SIEM replacement functionality plus automation. So think single pane for XDR, SIEM and SOAR. Though as much as they claim its a SIEM replacement, it clearly is not.
09-27-2023 07:35 AM
Hi Winston,
Cortex XSIAM is logical progression, as it were, of several Cortex solutions including XDR, and XSOAR. It also includes many SIEM like components including a standard data model, allowing you to ingest all of your security solution data into a single platform and then apply our AI driven Analytics Engine for anomoly detection, and XSOAR-style automation to perform tasks like enrichment and automated response actions. While XSIAM does include many components of XDR including the XDR agent itself for endpoint protection, many of it's features, especially around 3rd party data collection and automation, are not.
While it is accurate to say that XSIAM's goal is to displace customer's existing SIEM solutions, it is not a traditional SIEM itself. Instead, it is designed to be a single location to ingest security related data, apply our advanced analytic capabilities, and automate your response process to ensure that analysts spend time only on incidents which need further triage or response actions.
Of course, this is a very high-level overview and there are many other great inclusions like attack surface management, threat intel management, the data model, etc. Please reach out to your account team for a more detailed discussion of your use cases and pain points to see how Cortex XSIAM can help you get closer to our vision of the automated SOC.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!