What is our primary use case?
I started working with Splunk SOAR four years ago. I provide Splunk SOAR solutions to our customers as an MSSP. We work with two customers that have different solutions. They have defense-in-width with Trend Micro, Vision One, CrowdStrike, and Windows Event Logs, and all those logs are pushed into the firewall and Zscaler. All the logs are being pushed into Splunk, and we correlate all the logs, perform automation with those logs, integrate threat intelligence, and act on the notables that we get.
One of the biggest advantages is that since we are working with two different products—one is the enterprise solution and the other is Splunk SOAR—the SOC analyst effort is reduced at a huge margin when using Splunk SOAR. The response time and effort with the enterprise solution is less compared to Splunk SOAR. We have alerts generated, those alerts investigated, and all the correlation clubbed together, giving us the notables, which makes investigation quite easy. For example, in the enterprise solution, we may not have threat intelligence integrated, but with Splunk SOAR, we have two threat intelligences integrated—one is Cisco, and the other is VirusTotal. If there is an IOC found in their database, it clearly gives us a trigger, indicating this seems to be a true positive incident. This reduces our effort in the enterprise solution, as we usually need to check IPs manually, whereas in Splunk SOAR, we already have those results. If the enterprise solution takes 15 to 60 minutes, Splunk SOAR takes approximately less than 10 minutes.
The consolidation of tools does not have any negative impact. I found it very useful when it comes to Palo Alto, VirusTotal, and all the other threat intelligence platforms. It is very important and conclusive for us. We have integrated Cisco and VirusTotal, and these are quite helpful.
One particular example I can recall is that in enterprise, we get around 100 to 200 notables daily, which consumes approximately 16 to 40 hours per day for an analyst. Since we have Splunk SOAR, it is now just about five to seven minutes or five to 10 minutes per alert. Initially, we had a small team of around 17 members working on different products, and it was quite difficult to manage with the enterprise solution. When we onboarded Splunk SOAR, we effectively managed it without additional workload pressure or headcount. When it comes to a specific incident, for example, if there is an incident from Defender, in the enterprise solution, we need to log into Defender, open the incident, check the risk level, associated entities, sign-in logs, and also check the IOC in VirusTotal. With Splunk SOAR, about 70% of the information will be available here, so there is no need to navigate multiple platforms.
What is most valuable?
I am working with both Splunk SOAR and Splunk Enterprise Security. The biggest advantage I have found is that the SOC analyst effort is reduced at a huge margin when using Splunk SOAR. The response time and effort with the enterprise solution is less compared to Splunk SOAR. We have alerts generated, those alerts investigated, and all the correlation clubbed together, giving us the notables, which makes investigation quite easy. For example, in the enterprise solution, we may not have threat intelligence integrated, but with Splunk SOAR, we have two threat intelligences integrated—one is Cisco, and the other is VirusTotal. If there is an IOC found in their database, it clearly gives us a trigger, indicating this seems to be a true positive incident. This reduces our effort in the enterprise solution, as we usually need to check IPs manually, whereas in Splunk SOAR, we already have those results. If the enterprise solution takes 15 to 60 minutes, Splunk SOAR takes approximately less than 10 minutes.
What needs improvement?
When it comes to Splunk SOAR, in terms of improvement, I feel there should be some pre-deployed solutions available. If we want to enable Splunk SOAR capability, we need to process some playbooks and look at the process behind it. CrowdStrike provides pre-fetched information which we can pick up and schedule accordingly, making it easier. This aspect requires a bit of improvement, as the onboarding process for Splunk is quite demanding. It might happen that we design an automation that results in alert fatigue or multiple false positives because we are human and not 100% accurate. These issues need to be predefined. CrowdStrike and Trend Micro show fewer false positives compared to Microsoft, which has more. We also spend a lot of time on integration efforts, so a simpler way to integrate multiple log sources should be improved.
Pricing depends on how much we are consuming. When it comes to log sources, it can be expensive.
For how long have I used the solution?
I have been using Splunk SOAR for four years in total.
What do I think about the stability of the solution?
Latency does exist, but I would not say it is 99% stable. I would say it is about 95% stable.
What do I think about the scalability of the solution?
The solution is highly scalable. This is one of the biggest advantages of Splunk.
How are customer service and support?
The customer service from Splunk is fine but not exceptional. I would not say they are down or very good; it is okay. I would compare it to Microsoft. They do take time, but they do provide a clear and complete resolution. I would give them an eight for support on a scale from 0 to 10, with 10 being the best.
Which solution did I use previously and why did I switch?
I would not say Splunk is the leader. I prefer CrowdStrike, and the least expensive option is Microsoft Sentinel.
How was the initial setup?
It is a bit complicated, not that easy when it comes to the installation part of Splunk SOAR.
Which other solutions did I evaluate?
According to me, I would rather consider some different solutions. In cases where a customer has multiple log sources, like the one with approximately 20 different vendors, it works well for them. But for vendors with four to five log sources, or maybe up to 10, it can become quite expensive.
What other advice do I have?
We do not use Google Cloud as of now; we are fetching logs from AWS and Azure, two different cloud providers. We mostly use AI tools like Copilot when we get stuck.
From my perspective, there is no impact on the level of expertise and training needed to perform incident investigations because I probably have enough experience.
I have not worked with Splunk Observability Cloud for application performance monitoring yet, although I have heard about it and am yet to explore it. I am using Trend AI Vision One. I recently attended a workshop on it.
I would give this review an overall rating of 9 out of 10.