Palo Alto Networks, Inc. (PANW) Earnings Call Transcript & Summary

January 11, 2024

NASDAQ US Information Technology Software special 38 min

Earnings Call Speaker Segments

Carlo Tarantini

executive
#1

Welcome to a New Paradigm for the Modern SOC. Hope you're ready for an inspiring discussion. Now security operations centers struggle to keep pace with an ever-evolving threat landscape and ever-increasing digital attack surface and the need to manage a multitude of security tools. On the other hand, we've seen the emergence of many interesting technology trends for the SOC like security analytics and generative AI, for instance. Today, we're going to take the chance to discuss with Forrester analyst, Allie Mellen, a few of these challenges of the modern SOC and the opportunities to revolutionize it. But let me introduce Palo Alto Networks SOC transformation philosophy first. Security operations centers of yesterday were pretty easy to operate, at least in comparison with a modern day equivalents, a trained security analyst had a few simple screens with a few simple sensors, and they could manually operate their SOC tools pretty easily. But today's SOCs are a remarkably complex combination of people, process, technology and data. The problem is today's SOC architectures have a security analyst at the center, and they are challenged with having to deal with all of these siloed tools and data. And there are so many point products, so many different consoles that they have to go and check, and data and insights are just scattered around. This hinders efficiency, generates frustration and weakens threat defense significantly. When an analyst has to handle an incident, they have to check all these different dashboards and try and piece all this information together in their head. There's a heavy reliance on manual work and manual workflows when analysts have to detect and respond to threats. And threats hide in the noise of data. In fact, on average, an enterprise generates more than 11,000 alerts per day, and a sizable fraction of them are completely ignored. They're not investigated because our heroic SOC analysts are overwhelmed with way too much manual work, way too many alerts. At Palo Alto Networks, we're solving this problem with Cortex XSIAM. Cortex XSIAM is driving unprecedented security outcomes for our customers. We are simplifying security operations with a converged platform, bringing together all of the security data and SecOps capabilities into a single product. We're able to stop threats at scale by using AI at the foundation of Cortex XSIAM, and we dramatically accelerate incident remediation by using an automation-first approach. Let me double-click on each of these in a little more detail. Firstly, what do we mean by a converged platform? Well, it's really 2 things. One, we're bringing together all the security data from across the enterprise. It doesn't matter if it's on the network, on the endpoints, in the cloud, whether it attacks surface management data or any other data source. We convert it all into the Cortex XSIAM data lake. We correlate it, we stitch it together. All the security data is in one place with Cortex XSIAM. Then we reduce operational complexity by converging all the tools that were once upon a time, separate point products and separate management consoles for that painstaking SOC analyst to have to deal with. We bring all of that together into a single management console with Cortex XSIAM. We have a customer, a Fortune 50 retailer, and they're seeing this advantage in real life with their XSIAM deployment. We've significantly expanded the visibility that the SOC analysts have with additional data compared to the old SOC platform, to that old theme. Now with Cortex XSIAM, they have 40 terabytes of data per day. They're seeing much more context all in one place with Cortex XSIAM. Next, what do we mean by stopping threats at scale with AI-driven outcomes? What XSIAM does is again bring together all of that data from across the enterprise. There are so many alerts from so many different systems, and these are low-quality signals that we bring together and stitch to give a unified view of the security incidents, turning those low-quality alerts into high-fidelity incidents. This enables security operation centers to accelerate threat analysis. Instead of having to try and find a needle in a haystack looking for threats in this enormous amount of data, we use AI and ML to bring it all together, to stitch it, to enable them to find threats much more easily. It also enables them to detect and respond to threats much more easily. Again, what were thousands of alerts end up being stitched and correlated into just a few incidents. And the AI and ML models over time get better and improve as they see threats as they learn more. And this protection is dynamic. It improves over time. And we have a large oil and gas company that's enjoying these benefits using XSIAM today. They went from having over 1,000 incidents per day being flagged from their SOC to having less than [ 150 ]. And they can finally clear through the backlog and ensure that all incidents are responded to across the enterprise. With Cortex XSIAM, we accelerate incident remediation by using an automation-first approach. This significantly reduces the manual effort that SOC analysts need to perform. So we bring alerts into XSIAM and we stitch them together into incidents, and then the automation engine automatically results, in many cases, the vast majority, leaving just a few for SOC analysts to manually investigate and respond to. This frees the SOC analysts up from triaging alerts and sifting through alerts to being able to spend more time on proactive security, like threat hunting and other sorts of activities that actually help improve the security posture of their organization. It also speeds up the investigation and response process. By using automation to either completely automate or partially automate most of the incident response process, we're able to reduce the MTTR pretty significantly. And the automation, it does get better over time. As SOC analysts perform manual workflows, XSIAM will ask them if they would like to turn those into automation so that next time the system can take care of it for them. And for this IT services customer, this has enabled them to dramatically speed up their incident response. Before XSIAM, the median time to resolution for their incidents was measured in days. And now with XSIAM, the MTTR is 15 minutes. So to bring it all together, Cortex XSIAM is the AI-driven security operations center's platform that brings together all the security data from across the enterprise: network, endpoint, identity, cloud, attack surface, it doesn't matter. We can ingest any data into XSIAM. XSIAM will stitch that together. It will normalize it. Then our AI, ML and automation engines will automatically resolve many of those incidents, leaving the SOC analysts and empowering the SOC analysts to do just the work that only humans can do, things that require reason and judgment. And finally, SOCs can clear through their entire backlog of incidents on any given day. We're seeing dramatic improvements in SOC metrics across our XSIAM deployments. With XSIAM, customers are ingesting more data but that's leading to fewer incidents. So we're taking in more data from more places across the enterprise. And normally in a typical SOC architecture, more data means more alerts, more false positives. That's not the case with XSIAM. Using our AI and ML and our data stitching technology, we're flagging fewer incidents, and the majority of which are completely automatically resolved, leading to -- with our XSIAM customers today, on average, 100% of their incidents being closed out compared to less than 20% with their legacy architectures. And the bottom line, XSIAM customers are now measuring their MTTR in minutes to hours versus weeks to months with their previous solution. At Palo Alto Networks, we believe it's time to transform the SOC. Cortex XSIAM will elevate your SOC teams to perform at their best. It will simplify security operations, it will stop threats at scale, and it will accelerate incident remediation. So this is a pretty big transformation. And we're certainly seeing a lot of customers completely transforming their SOC today with Cortex XSIAM. They're replacing their team, they're replacing their endpoint security, they're adding automation and attack surface management. But you don't have to do it all at once. You can start with Cortex XDR, replace your legacy endpoint security and start to bring in more data into XDR. You could start with XSOAR and begin to automate some of your manual SOC processes, or you could start with Xpanse where you can start to manage your attack surface and proactively shrink it. All of these are great first steps towards Cortex XSIAM, and we provide neat and easy upgrade parts where you can start today to solve your most immediate problem and then upgrade to XSIAM in the future when you're ready. For a quick run-through of all the exciting features and all the innovation coming up in XSIAM 2.0, you can check out the recording of our virtual launch event. And now let's welcome Forrester analyst, Allie Mellen, for an exciting chat about the future of the SOC. We're joined tonight by Forrester Principal Analyst, Allie Mellen. Allie, do you want to introduce yourself?

Allie Mellen

attendee
#2

Yes. Thank you so much for having me. I'm, as you mentioned, Principal Analyst at Forrester. I cover Security Operations, so people, process, technology in the SOC. In addition to that, I also cover nation-state threats and AI and its use in security tools. Very happy to be here.

Carlo Tarantini

executive
#3

Allie, you contributed to defining the whole concept of security analytics. And in your work, I feel you highlighted that security analytics is basically seen an evolution spanning 2 decades. How did we transition from SIEM a whole bunch of solutions to end up -- land on security analytics. What have been the milestones in that transition?

Allie Mellen

attendee
#4

Great question. Yes. So I've been with Forrester for almost 3 years now. And actually, we defined the term back in 2015, so before my time, thankfully. But it was my boss's responsibility to define it at the time. And what he was seeing ultimately was a big transition in the market from where we think of SIEM classically as log storage, taking a lot of that data into what's now security analytics platforms, which is really very focused around the detection and response use case, in addition to addressing some of those compliance requirements. And so what we see in security analytics platform that's so different is it has the basis in the SIEM or in data lake, and then it combines a series of other technologies on top of it to become more holistic and to really make it the center of the SOC. That includes user behavior analytics, store capabilities, threat intelligence platform capabilities, all brought together based on all of that data that's either being ingested or accessed so that you can do more interesting things with it and take response actions ultimately from the same platform.

Carlo Tarantini

executive
#5

So while defining security analytics in a way even back then in 2015, you saw beyond the SIEM, didn't you, you guys at Forrester?

Allie Mellen

attendee
#6

Yes, absolutely. That was a key piece of this. I mean, the SIEM has been a fundamental part of security operations pretty much since its inception. It's been a very big part of this. But at the end of the day, because of that it's evolved a lot over time, right? We've seen it move from, hey, we're just going to throw a bunch of information in here into, okay, now we can expand beyond the traditional log formats that we saw which were originally very focused on the network into other areas. Now we can start doing analytics on top of that, start doing retrospective search. And into the platforms today, which have navigated from on-premise environments to now cloud native platforms, cloud-based platforms that are able to scale much more effectively than what we saw on premise. There's been a ton of changes in this market. And it's really interesting because I see a lot of teams that talk about legacy SIEM this, legacy SIEM that. But in reality, there's been so much changing and so much shifting in the market that, that transition to security analytics platforms makes a huge difference from where we were 10, 15, 20 years ago.

Carlo Tarantini

executive
#7

So what are your thoughts about the security analytics landscape in EMEA in particular?

Allie Mellen

attendee
#8

Yes. In our data, we actually see that the European market is very focused on using security analytics platforms and SIEMs more so than any other tool in security operations. It really is the center of their operations when it comes to detection and response. And the main difference that we see or the main thing that stands out is just the importance of having the data hosted and accessed within the EU and making sure that, that is an opportunity for them, at least within the EU but sometimes within country as well. We see this in other countries and it's picked up quite a bit since, but the EU is really the one to [ lead ] that charge to. We need to make sure that even if we're using a cloud-native platform, the data is being hosted in our region or in our country.

Carlo Tarantini

executive
#9

But speaking of the outcomes that security analytics can generate, one of my favorite ones is threat hunting. And I'd like to focus on threat hunting now and on the fact that we at Palo have a philosophy of elevating an analyst capability so they can transition to a Level 1 Analyst type role, kind of a human gatekeeper in charge of triaging alerts and investigating incidents, to more of a threat hunter, a more sort of sophisticated kind of more all-encompassing role. So my question to you is, what are the key signals and the key capabilities that practitioners and SOC leaders should look for when selecting solutions that enable those advanced outcomes, that enable threat hunting?

Allie Mellen

attendee
#10

That was a great question. Because at the end of the day, what every security operation center wants, that every SOC manager wants is to make sure that their team can up-level quickly, can have the skills that they need to make it to the next level and start taking on other tasks. One of the things that we talk about at Forrester is the importance of giving your analysts the time to focus, maybe like even 15% of their time ideally, on other things like you mentioned, like threat hunting. There's a lot on the process side that has to happen to make sure that, that can take place. But the biggest thing from a technology perspective that we see that buyers need to look at and focus on is how analyst experience is being enabled. We talk about analyst experience as a security analyst perception of the tools, processes, pretty much anything having to do with their role in the SOC and the ways that we can improve that. Technology is a huge part of that. And ultimately, it's about understanding the workflow that the analyst goes through and making it so that they can go through that workflow faster and more effectively. There's a lot that can be done from an investigative standpoint to make sure that we're not just delivering them an alert, but it's a contextualize alert. It is a combination of different alerts that have all the context that we need, maybe it's multiple stages of an attack. And if we know that they're going to need access to certain data or they're going to need to take a certain action as part of the investigator process, bringing that to the forefront so they have it immediately and can make that decision faster. That is what's going to ultimately give them more time to focus on additional things like threat hunting. And when it comes to threat hunting, what we really look for is how can analyst experience be applied to threat hunting. One of the things that we found and one of the values of the approach that we've taken to analyst experience is making sure that it can be applicable across multiple tasks that an analyst is going to work on. So not just, hey, investigation and response, how can we improve the analyst workflow? But also detection and engineering, how can we take a look at improving the way that an analyst goes about formulating an idea for a new detection and then implementing it. Or threat hunting, how can we improve things like the query interface and the way that they manage the threat hunts that they've developed so that they can do it more effectively and so that they can ultimately turn those queries into rules that then completes the threat hunting process. A lot of times with many implementations that we see, the extent of threat hunting features or capabilities is pretty much limited to, hey, here's a search bar. You have access to all the data, start using it. But there's a lot of features around providing some level of understanding of risk around each process or entity that can really help support the threat hunters mission and give them a little context clues for what might not be where they want it to be or what might indicate some potential malicious activity.

Carlo Tarantini

executive
#11

So you touched on analyst experience. The process of providing analysts with a unified interface to perform their tasks, I believe, started with XDR and now continues, as far as we're concerned at Palo Alto, with XSIAM, which is where we provide a unified interface for all the core workflows in the SOC from detection, investigation and response. So my question to you is, what do you think what defines good analyst experience?

Allie Mellen

attendee
#12

In an ideal world, having one view where you could access and take action and investigate, would be ideal. We've been kind of searching for that for a long time. It's so challenging to find that but it's definitely ideally what we can get to. It's the kind of the vision for what we want to get to within the SOC. Now when it comes to analyst experience around that, ultimately, at the end of the day, we see that analysts have a lot of friction in their workflows and in their jobs in general, right? It's not just the thing that they see when they are using a particular platform. It's also the work that they have to do to even get to the point where they can use that platform, whether it's the integrations they're dealing with or the other products that they're dealing with that are in conjunction with that product, whether it's making sure the data is getting collected and input and transformed in a way that is going to make sense and help them achieve the outcomes that they want to. And so making all of these aspects of the analyst job easier or really making what I call the dependencies that the analyst has on using the products that they're trying to get value out of, simpler is fundamental to improving analyst experience. And letting them ultimately do what they're [ there ] for, what they're -- what they've really done all of their work in their careers to do, which is the security part of this job instead of a lot of the IT and tool management aspects that we've talked a lot about. The other factor here that is very important, and I want to make sure that I call out because I was very focused on the technology piece in the last question is, as I mentioned before, analyst experience goes way beyond just the technology that you're working in. It's also about how you, as the CISO, as the security leader, are making sure that your staff can get to the next level in their careers. They come down to things like thinking about how training is going to support them, thinking about what training is going to support them, thinking about their career path and their ability to get to the next level. When you take it from a holistic view and make this a key qualifier for success for your SOC, you will not only help your team be more efficient and effective, but you're also going to help retain that talent in the longer term and get them up leveled faster because at the end of the day, one of the biggest challenges, internal enterprises have, or internal SOCs within an enterprise have is that the people that they hire don't stick around for long enough. They stick around for a couple of years and then they're like, I'm off to work at a vendor and make a ton of money or I'm off to go work in tech and have better hours. And so anything that we can do to differentiate on analyst experience as a security operations function, that will help retain people. It will help keep them more interested in the field and it will help them get to the next level, which are all things that go on to support the business more effectively and support your team more effectively.

Carlo Tarantini

executive
#13

Okay. But analyst experience involves addressing the challenges faced by many practitioners, especially those that have to deal with tools that, I believe, in Forrester's words are, hard to learn and hard to master. Now my question is, could generative AI be a game changer in improving the analyst experience and shortening that learning curve for cyber analysts?

Allie Mellen

attendee
#14

So I'll caveat this answer with if it's done the right way. The main thing that I'm seeing with a lot of applications of generative AI within security tools is that they're way more focused on things like the chatbot use case, which is flashy, it's novel, it's interesting. You get to talk to an AI. But at the end of the day, it's not built into the analyst workflow and into what they do every single day. There are some applications that I'm seeing of generative AI and security tools that are very tangibly focused on what the analyst is doing on how can we look at each part of the analyst workflow and makes sure that we're improving it. Things like handling reporting for them, building incident response reports based off of what happened during an incident. That's a really cool use case that can save hours of time for analysts. Another example that I find really interesting is [ query ] language conversion, being able to take human readable text or take queries that are in a different language and convert them into the language that you want. This is so helpful for practitioners because it enables them to spend more time focused on their security principles than necessarily on the product itself and how they need to use it and all of the different things they need to remember when it comes to the usage of the product. So I'm excited to see a lot of the applications of generative AI that we have the opportunity to build into security tools with the caveat that I want to make sure that they are impactful and that they really make a difference in the analyst workflow and what the analyst does on a day-to-day basis.

Carlo Tarantini

executive
#15

Awesome. In this new release of XSIAM, in XSIAM 2.0, we introduced copilot as a way to interact with the analysts, interact with the user and impact and improve that analyst experience. What are the benefits of copilots that you've observed? And will copilots transform security operations?

Allie Mellen

attendee
#16

On the one hand, I'm very excited for the possibilities with something like a copilot because practitioners are excited about it. I've never seen the excitement from security leaders as I have around the potential that a copilot could provide for them. On the other hand, I want to make sure that they're very integrated into the analyst workflow and that anything that is happening within a copilot is tailor-made to make sure that it is improving what an analyst is doing and fitting within their use case. If analysts have to go to a separate view or a separate screen to ask questions, it can pose challenges. In addition, there are underlying issues that prevent necessarily environment-specific questions from being as effective as we may want them. For example, if you don't have the access to all the information about the environment, then asking a question about the environment isn't going to yield the same level of results that you want. So having a caveat about what data access you have, what access to other tools you have and how that's providing those answers back to the practitioner becomes incredibly, incredibly important to make sure that they have the most accurate and up-to-date information possible.

Carlo Tarantini

executive
#17

We did touch on security analytics. We touched on analysts' experience and copilots and generative AI. Can I go back to AI one second? I wanted to ask you a more generic question. Are SOC managers making the most of AI? And what are the main challenges that they're facing in adopting AI, what do you think?

Allie Mellen

attendee
#18

It's a good question. It's difficult to say because at the end of the day, a lot of how they're using AI and Machine Learning is through the technology that they have access to. And so from that standpoint, they're honestly doing the best they can. Because they're using what's built into the technology, they're tuning it depending on what needs to be tuned. They're excited about new applications like generative AI and what those are going to provide for them. Their biggest gaps are, not everyone has the talent or the resources to have someone who can just write Machine Learning algorithms on their own or build their own AI. And so for those teams that are limited in resources, it's going to be difficult for them to get the maximum value that they could out of AI and machine learning and they are going to be limited to what the tools can provide for them and how they can better leverage those tools. So it comes back a lot to what the vendor can provide you from an AI and ML perspective, keeping in mind that the other fundamentals around security, things like detection and prevention based on signatures, detection engineering as a function and making sure that you have that in place to continuously update detections based on threat research and threat intel is still critically important as a part of this.

Carlo Tarantini

executive
#19

Okay. Allie, you've done some great work on XDR recently. And I have a question for you and it's generally about vendor consolidation. Now what are your thoughts on organizations purchasing separate solutions for XDR and SIEM versus integrated offerings? What do you think?

Allie Mellen

attendee
#20

XDR has been really interesting because it's really helped to bring to light a major problem that we've seen with security tools in the past, which is section and rule quality and investigation capabilities. Both of those have been a pivotal part of XDR and something that XDR has looked to solve. And as it's done that, we've seen more data be put into XDR, whether it's [ natively ] through other tools in the vendor's portfolio or -- but the challenge is, we already have a tool that takes in a bunch of data from third-party sources and from native sources and tries to consolidate them and do detection and response. And that has been the SIEM and security analytics platforms. Now XDR and the SIEM are fundamentally different because at the end of the day, XDR has very high-quality detections. They're very tailored to what the vendor knows they can build high-quality detections off of. They're based in EDR. And SIEM is more of the Wild West, you can build whatever you want with it. But you still need to -- and we see this with many practitioners, there's still a big drive for consolidation with these 2 products because you're basically paying for double. You're paying to storing the data in your SIEM or security analytics platform and you're paying to do the same thing with an XDR. And so we see a lot of vendors now that are offering a XDR product and a SIEM or security analytics platform or even a SIEM alternative or replacement as a bundled offering, still 2 separate products but you can buy them together so that you can have one data lake or one data access point for all of the data that's being used for XDR and for the security analytics platform. And this simplifies things from an analyst experience standpoint. It simplifies things from a cost standpoint. And we've seen a ton of interest from practitioners to take this type of approach so that they can consolidate that tool and hopefully reduce some of the costs that they have seen time and time again with the SIEM.

Carlo Tarantini

executive
#21

Allie, on the subject of automation, what recommendations do you have practitioners to leverage automation effectively? What best practices should they follow?

Allie Mellen

attendee
#22

This is a question that I get all the time. There are always teams that are looking to better leverage automation in the SOC. And it's to the point where we've done a lot of research on it. Automation, in particular, in the form of SOAR is a key part of the security analytics platform. And some of the things that we recommend are first, to be prepared that automation is not going to replace your people. You actually need more skilled people, particularly in automation to get the most use out of it. And that is a fundamental requirement for making better use of SOAR and of automation more broadly within the SOC. The second piece that's so important is to start with very small, almost atomic playbooks. And I highlight this because a lot of the -- a lot of the things that we see online show these extravagant huge playbooks that people are able to take action on. But in reality, it's the smaller, more targeted playbooks that can not only be used for more tasks but also can be stacked with other playbooks to create those much bigger, more complex playbooks. Having that balance is important because anytime you want to make any minute changes, you can do it at that atomic playbook level and have it affect every other playbook in the process. The third thing that I most often recommend when it comes to looking at playbooks is to start with investigation. Most of what I see from a lot of practitioners is the expectation that you're going to automate aspects of response, which many teams do get to. But at least to start, there's a huge gap from an investigative standpoint that can be filled with automation and with store playbooks. One of the things that we found as part of our analyst experience research is that at the end of the day, investigation takes up the most time out of any part of the incident response process. And so applying automation there to gather information to address parts of the incident response process is incredibly beneficial for our teams that want to speed up detection and response.

Carlo Tarantini

executive
#23

Allie, we at Palo have lots of conversations with customers and some hinged around threat intelligence. And I just realized that we realize that SOCs, big and small these days are trying to leverage and operationalize threat intelligence to elevate their capabilities. Now my question to you is on leveraging threat intelligence, what are the main challenges that SOCs would face or should face when trying to leverage or operationalize threat intelligence? And what are the outcomes they should expect if they're successful at leveraging threat intelligence?

Allie Mellen

attendee
#24

So I like to relate this back to me whenever I start to learn about a new topic. Whenever I start to learn about a new topic, I order like 16 different books. And so I'm like, I'm going to learn everything that I need to know about this topic through all 16 books. And then I go months and I read none of them. At the end of the day, one of the things that I see as the main challenges for teams and how I tie this back into my habit of trying to learn about things is that they try to get a ton of value by using as many threat intelligence [ fees ] as possible and throwing them all in at once. But that immediately actually causes a lot of issues. Because as great as it is to have that quantity, at the end of the day, the quality really matters. And doing things like duplication of threat intelligence becomes very important to managing it well. And so when I make recommendations about threat intelligence to security teams and security operations teams in particular, I recommend starting with the most important and vital threat intelligence feed you can, incorporating those into your SIEM capability, your security analytics platform, your XDR, building detections based off of those where applicable, especially once you get into things like indicators of behavior and then working from there and integrating more over time. More is not necessarily better in this scenario. And so making them very targeted, making sure that they are relevant to your use case will help you minimize any noise and get the most value out of them for your team.

Carlo Tarantini

executive
#25

All right. Final question to you, Allie. SIEMs have been the cornerstone of the security operations center for a decade -- for longer than a decade and SOCs have built and bolted-on solutions on top of SIEMs. And operationalizing SIEMs has been an [ engineering ] challenge for many SOCs. Now my question to you is, is it time to move beyond the SIEMs limitations?

Allie Mellen

attendee
#26

Ideally, yes, but it's easier said than done, right? I mean, it makes for a great talking point to say, let's move beyond the SIEM's limitations. But when you actually get into the meat of what that means, it becomes a lot more complex. I -- this is actually a topic that I'm very passionate about because a lot of vendors think that they can just replace the SIEM and that their approach is going to be easier. But especially given the transition that we've seen from SIEM to security analytics platform, there's a lot of features built into these products. It's just the reality that we deal with. And we're at the point where if you're doing an RFI, then you got to have all the features or you got to have an answer for why you don't. And in many cases, it means that the client is going to have to use 2 SIEMs to make sure that they can get all of those features. So as much as many [ teams ] made us like their SIEM or may be frustrated by the costs associated with it, there's a lot of features in that. It is the center of the SOC. And at the end of the day, they do need to use it. Now are there better ways to approach it? Absolutely. We've seen that shift with the shift to security analytics platforms, and in particular, the cloud. Because coming back to your limitations of the SIEM, a lot of the issues we saw on the engineering side were born out of the fact that it was not on-premise technology. You had to manage a lot of the actual management of the product, the operationalization of the product yourself. And so when you move that to the cloud, you reduce some of that, not all of it, but some of it. You still have issues with things like the log collectors and integrations that have to be addressed. And the more that we can simplify those problems and make those dependencies easier to deal with, the better. But we just don't currently have a tool that is going to be able to do that and replace the SIEM. And if we did, then practitioners would absolutely be using it as an alternative to existing SIEMs.

Carlo Tarantini

executive
#27

That was a great insight. That's a bit unexpected. We can now move beyond [indiscernible] limitations. Thanks, Allie Mellen, Principal Analyst at Forrester for being with us.

Allie Mellen

attendee
#28

Thank you so much for having me.

Carlo Tarantini

executive
#29

So we've come to the end of our webinar. I learned a lot today. How about you? We talked about security analytics and analyst experience, how important they are, how transformative they can be and how they can impact areas like threat hunting and detection engineering. And we discussed how to be brilliant at automation and how security operation centers can become proactive by leveraging threat intelligence. Thank you for sticking around, and thanks again to Allie Mellen for being with us. I encourage you to learn more about XSIAM and how we see SOC transformation at Palo Alto Networks. Do watch our XSIAM 2.0 launch event on demand, experience the XSIAM product on our website and follow our future sessions. See you later.

Read the full transcript via the API

You're viewing the first half of this call. Get the complete Palo Alto Networks, Inc. transcript — plus 251,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.

Get the API View API docs →

This call discussed

For developers and AI pipelines

Programmatic access to Palo Alto Networks, Inc. earnings transcripts and 251,000+ others is available through the EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments, full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.