Cortex XSIAM tiers, ingestion economics, and what's bundled at each level.
Cortex XSIAM is sold in three tiers (NG-SIEM, Enterprise, Premium) with a shared ingestion baseline and add-on bundles. Knowing what's included at each tier lets you spot quotes that have you paying for things twice.
Read the full lesson with Pro.
The takeaways below are public so you know what is in the lesson. The full body, the negotiation script, and every other lesson unlock with Pro. Free 30 days, no card.
Takeaways
- →Three tiers: NG-SIEM (analytics + automation + UEBA), Enterprise (adds XDR agent + Host Insights), Premium (adds Cloud Posture + Cloud Runtime + WAAS).
- →Analytics tier ingestion: 100 GB/day minimum, GB/day-based pricing, feeds real-time detection.
- →Cortex Data Lake tier: 50 GB/day minimum (only on top of Analytics minimum), cost-efficient for retention and threat hunting, not for real-time detection.
- →Cloud Posture Security and Cloud Runtime Security are bundled into Premium; do not pay for them again as add-ons on a Premium quote.
- →Watch for under-sizing the Analytics tier to win the deal; the renewal-year price spike when you exceed the quoted volume is real.
- →Bring a partner in for custom log volume estimation, multi-cloud agent allocation, or Analytics-vs-Data-Lake portfolio decisions.
Copy-ready script
Pro“Can you split the rule scope into two phases? Phase one is enablement of the OOTB ruleset against my environment, ideally on a flat-rate or fixed-fee basis. Phase two is authoring custom rules where the OOTB set has gaps, billed hourly.”
See it in your own quote.
Paste a Palo Alto Networks quote. The engine will tell you, line by line, where the pattern in this lesson actually shows up.
Have Clarify read your SOW