
Cortex Data Lake
Cloud data security software
Cloud security software
- Features
- Ease of use
- Ease of management
- Quality of support
- Affordability
- Market presence
Take the quiz to check if Cortex Data Lake and its alternatives fit your requirements.
Contact the product provider
Small
Medium
Large
-
What is Cortex Data Lake
Cortex Data Lake is a cloud-hosted security data platform that centralizes and retains security telemetry (such as alerts, logs, and endpoint/network events) for search, investigation, and analytics. It is typically used by security operations teams to support threat hunting, incident response, and reporting across multiple data sources. The product focuses on collecting and normalizing security data into a single repository to enable correlation and analysis workflows.
Cloud-managed operational model
As a cloud service, it can reduce infrastructure management tasks such as scaling storage and compute for analytics. This can be useful for teams that want to avoid operating their own log storage clusters. A managed model also typically standardizes upgrades and maintenance windows under the vendor’s control.
Centralized security telemetry storage
It consolidates security-relevant data into a single cloud repository, reducing the need to query multiple point systems during investigations. This supports cross-source correlation when events span endpoints, network, identity, and cloud services. Centralization can also simplify retention management compared with distributing logs across many tools.
Supports investigation and hunting
The platform is designed for search and analysis of historical security data, which is a common requirement for incident response and threat hunting. Keeping data in one place helps analysts pivot between related events and build timelines. This aligns with SOC workflows that require fast access to normalized telemetry.
Not a dedicated data security platform
Its core purpose is security analytics and operations data management rather than data-centric controls like fine-grained data access governance, masking, or tokenization. Organizations primarily seeking cloud data security posture management or sensitive data governance may need additional tools. This can increase architecture complexity when compared with platforms purpose-built for data security controls.
Integration and ingestion effort
Value depends on ingesting a broad set of telemetry sources, which can require connector configuration, parsing/normalization work, and ongoing maintenance. Gaps in supported sources or inconsistent event schemas can limit correlation quality. Teams may need engineering support to onboard custom or niche data sources.
Cost tied to data volume
Cloud security data lakes commonly scale cost with ingestion volume, retention duration, and query/compute usage. High-cardinality logs and long retention requirements can materially increase spend. Budgeting can be difficult if data growth is unpredictable or if many teams run frequent analytics queries.
Plan & Pricing
Pricing model: Subscription/license-based (sized storage historically sold per TB; newer license tier: unlimited storage with one-year retention for first-time users).
Description & notes:
- Historically available as sized-storage subscription SKUs (examples on reseller catalogs: 1 TB storage, 1-year subscription). Palo Alto Networks documentation describes Strata Logging Service (the new name for Cortex Data Lake) supporting sized storage licenses.
- In 2024–2025 Palo Alto Networks introduced a new Strata Logging Service license tier that provides unlimited storage and one year of log retention (applicable to first-time users) and announced automatic migration paths for existing sized-storage licenses.
- Official Palo Alto Networks website and documentation do NOT publish public list prices for Strata Logging Service/Cortex Data Lake; pricing/quoting is handled through Palo Alto Networks sales or authorized partners. No official per-GB or per-TB public price table was found on paloaltonetworks.com.
Free tier/trial: No official public free tier or trial for Strata Logging Service was documented on the vendor site.
Seller details
Palo Alto Networks, Inc.
Santa Clara, CA, USA
2005
Public
https://www.paloaltonetworks.com/
https://x.com/PaloAltoNtwks
https://www.linkedin.com/company/palo-alto-networks/