XDR isn't a SEIM... you aren't going to send all of the Windows logs, switch logs, etc. to XDR.
And you can't do your own raw searches into the data, nor can you write your own correlation rules across all of it.
The Automation engine could replace a SOAR, especially of you have mostly Cisco security tools, or the ones they're supporting direct integrations with.