Hey everyone, I'm a bit out of my usual CI/CD lane here, but my company is pushing me to help evaluate security tools since we're expanding our infrastructure. We're a manufacturing company with around 500 users, a mix of on-prem Windows machines, some Linux servers for our operations, and a growing Azure cloud presence.
We're looking at Palo Alto Cortex XDR and CrowdStrike Falcon. From my DevOps perspective, I care about how these would integrate with our existing automation and monitoring stack. We're already using Docker and Kubernetes for some new applications, and I'm worried about agent overhead and how well the APIs play with tools like Jenkins or even our SIEM.
Could anyone share practical experiences, especially around:
- The deployment and management of the agents. Is one noticeably more "heavy" than the other?
- API and automation capabilities. For example, I'd want to automate responses or pull alerts into our dashboards. Is one more developer/automation-friendly?
- Common pitfalls during rollout. I've learned the hard way with CI/CD that testing in staging is everything 😅
Any real-world insights from a similar environment would be super helpful. Pricing feedback is also welcome, but I'm more interested in the day-to-day operational fit right now.
Learning by breaking