Ran both in a proof-of-concept last year. Elastic's TCO looked better on paper, but the extra compute for a decent retention window ate that difference. We needed a dedicated ES admin too - that's another 20% FTE cost you can't ignore.
Cortex's workflows were faster to close alerts, but slower to actually understand them. We spent more time later reconstructing why things fired.
On discounts, treat firewall and EDR as separate deals. Get the firewall renewal signed first, then talk to a different Palo Alto rep for Cortex. Their sales orgs are siloed. Mentioning one kills your leverage on the other.
Ship it, but test it first
The operational workflow bit everyone's focusing on? It's incomplete.
They're comparing "clicks to close" vs "clicks to understand." But for a team of 1000 endpoints, you need to measure "clicks to trust." If your analysts can't easily trace an alert back to the raw data and the rule logic, they'll keep second-guessing the system. That's where the real time sink is, not in the daily triage count.
Elastic gives you that raw data access natively. Cortex keeps it behind their analytics. The "comfort tax" of learning Kibana is real, but the "distrust tax" of opaque alerts costs more over three years.
Separating firewall and EDR negotiations is good advice. But the real trick is to force them into separate fiscal years if you can. Their internal quota cycles matter more than you'd think for discount approval.
You're worried about clicks, but that's the wrong metric. It's not about how many clicks to close an alert, it's how many clicks it takes to be confident you didn't just dismiss a real threat. Cortex lets you close things fast, but you'll spend those saved clicks later digging around their analytics trying to figure out what you missed.
For your TCO, remember the hidden cost is the learning curve. If your team isn't already fluent in Elastic's stack, you're buying a part-time job for someone. Cortex might be expensive, but you're paying for them to handle the backend.
And forget bundling with firewalls. Get the firewall quote locked down with a different sales rep first. They absolutely do compare notes internally, and mentioning Cortex will kill your leverage on the firewall price.
If it ain't broke, don't 'upgrade' it.
You've hit on the real hidden cost with "clicks to trust." That opaque layer in Cortex doesn't just waste time during investigations, it creates a permanent dependency. Once the engineer who built the analytics leaves, you're stuck with a black box you can't debug.
The separate fiscal year trick is good, but it's even more effective if you can get the Cortex eval to straddle their quarter-end. Their sales reps will be more desperate to book anything.
Automate everything. Twice.
That "poor data presentation" point is key. It's not just clicks, it's cognitive load. Elastic dumps a ton of raw data, but organizing it into a usable story still takes work.
We had the same issue where finding a parent process meant jumping between the event timeline, process lineage graphs, and raw _source fields. It felt like building knowledge through archaeology.
The difference is, once you do piece it together in Elastic, you *really* understand the alert. With Cortex, you might close it faster but you're left with a vague "this seemed malicious" feeling that doesn't help you tune the next one.
edge cases matter
You're absolutely right about sizing being the hidden labor cost, but even with a consultant, the operational burden doesn't end there. We found that Elastic's data tier requires continuous tuning as your telemetry volume changes. The initial sizing gets you running, but a 20% growth in endpoint count or a new data source can force a complete re-architecture of your hot-warm-cold phases. That's ongoing, not a one-time cost.
The point about choosing based on reducing alerts versus building skills is crucial. However, I'd add that "building investigative skills" in Elastic often means building Elastic skills, which aren't fully transferable. The time invested in mastering Lucene queries and index lifecycle management is a form of vendor lock-in itself, just of the human capital variety.
-- bb42
You think you're watching the budget. You're not. You're watching the license cost, which is maybe 40% of the TCO.
The real cost is the time your team spends not trusting the alerts it closes. Both platforms are a time tax, just levied at different parts of the process. Elastic charges you upfront with admin work. Cortex bills you later with vague anxiety and re-investigations.
And for the love of god, don't bundle with the firewall. That's just volunteering to pay more. Get the firewall deal done. Wait a quarter. Then talk to a different sales desk about Cortex. They're separate P&Ls and you can use that.
CRM is a necessary evil