No more typing reviews! Try our Samantha, our new voice AI agent.

Palo Alto Networks Cortex XSOAR vs Splunk SOAR vs VMware Carbon Black Cloud comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
5.6
Torq users reported reduced alert management time with automation, enhancing productivity and showing potential for $600,000 annual ROI.
Sentiment score
4.4
Cortex XSOAR delivers high ROI by automating tasks and integrating seamlessly, ideal for mature SOCs despite initial costs.
Sentiment score
5.0
Splunk SOAR enhances ROI and efficiency by automating tasks, saving time, and integrating into systems for improved operations.
Sentiment score
5.2
VMware Carbon Black Cloud offers cost savings, improved security, centralized protection, better efficiency, and quick ROI with automation features.
Since we started working with Torq, I am handling much fewer alerts. It is becoming really easy for me to handle an alert.
SOC Analyst at AppsFlyer
We have seen a return on investment, targeting a $600,000 ROI for the year.
Cyber Security Engineer at a real estate/law firm with 5,001-10,000 employees
By the time we officially bought Torq, we already had two workflows that were very helpful to us.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
We are positioning Palo Alto Networks Cortex XSOAR, which can be used in the SOC and do a lot of automation for the customer.
Vice President, Technology at Cache Digitech Pvt Ltd.
Since deploying Splunk SOAR, there has been a notable reduction in time spent on monotonous security tasks, which I estimate to be around 95%, enabling my team to focus on more strategic initiatives.
Identity and Access Management Specialist at a university with 10,001+ employees
We've seen a decrease in false positives and a significant increase in our containment.
Cyber Security Network Security Engineer at Cirrus Logic
Monthly, around 300 hours of effort, it is saving with Splunk SOAR.
Manager cybersecurity at Hexion Inc.
 

Customer Service

Sentiment score
7.3
Torq offers highly rated customer service, known for quick, effective responses and knowledgeable support, though feature requests may delay.
Sentiment score
6.6
Palo Alto Networks Cortex XSOAR support is responsive and knowledgeable but could improve friendliness and initial response times.
Sentiment score
6.4
Splunk SOAR receives high praise for responsive support and community resources, but improvement is needed for niche telecom and IoT issues.
Sentiment score
6.2
VMware Carbon Black Cloud's support is effective but could improve regionally, with mixed customer satisfaction and costly services.
My impression of their technical support during the initial setup was that they were helpful, responded within a reasonable timeframe, and provided exactly what we needed.
Security Consultant at Integrity360
The speed and quality of their answers have been pretty good, as I usually get a response within 24 hours, and they follow up well.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
We can always get an answer, and the support team are experts in their own system.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
Eight out of ten times, they provide valuable help.
Lead Application Security Engineer Iv at a financial services firm with 5,001-10,000 employees
Their support has been better than Anomali's and they are more responsive.
Enterprise Security Architect V at FirstEnergy
The technical support provided by Palo Alto Networks Cortex XSOAR is good.
Vice President, Technology at Cache Digitech Pvt Ltd.
Discovering different troubleshooting methods is harder to do with Splunk SOAR than with Enterprise Security or other Splunk services.
Cyber Security Network Security Engineer at Cirrus Logic
We always have a customer support representative who will come in the picture and help us to direct any ticket or any issue that we are facing to the right team.
Manager cybersecurity at Hexion Inc.
I have worked with Splunk SOAR's technical support or customer service, which I find to be as perfect as Splunk SIEM
Global Head Of Security Architecture Digital & Technology at Aramex
 

Scalability Issues

Sentiment score
6.4
Torq is praised for impressive scalability, adaptability, and effective workflow management, though requires careful management with large workflows.
Sentiment score
7.1
Cortex XSOAR offers high scalability and flexibility, efficiently integrating third-party APIs despite potential complexities in large deployments.
Sentiment score
6.6
Splunk SOAR is scalable, integrating tools seamlessly to improve efficiency and reduce workloads in varying organization sizes.
Sentiment score
7.1
VMware Carbon Black Cloud is praised for its scalability and effectiveness in large environments, with minor integration suggestions.
Our case management is super scalable.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
In terms of scalability, you can do as long as you can build it, and they can support it.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
Regarding the ability of the solution to grow in your work environment, if it is scalable, if it fits your business requirements, and if there is room to scale up, the answer is yes, for sure.
Global IT Director at OpenWeb
The scalability of Palo Alto Networks Cortex XSOAR supports our growth and security needs because we can integrate various tools and continuously add more capability.
Enterprise Security Architect V at FirstEnergy
Palo Alto Networks Cortex XSOAR has very good application capabilities and is highly scalable.
Assistant Security Architect at Cloudnomics
The issues with scalability arise from the speed of some integrations, as not all are perfectly tuned by Palo.
Lead Application Security Engineer Iv at a financial services firm with 5,001-10,000 employees
This solution is very much scalable, so I would rate it a ten.
Citius Tech at a outsourcing company with 5,001-10,000 employees
It can be extended and adapted as necessary.
Splunk/SOAR Engineer
Regarding scalability, I find it to be a nine, as we have had no issues with scaling Splunk SOAR.
Advance Data Engineer(Cyber Security) at Novo Nordisk
 

Stability Issues

Sentiment score
6.7
Torq offers high stability and reliability with minimal downtime, quickly resolved issues, and significant improvements over other solutions.
Sentiment score
7.5
Cortex XSOAR is considered stable, reliable, and performs well, but requires careful sizing and regular updates for optimal use.
Sentiment score
7.3
Users praise Splunk SOAR for stability and efficiency, with minor issues mostly stemming from integration partners rather than the software.
Sentiment score
7.0
VMware Carbon Black Cloud is stable, with minor issues, resolves bugs quickly, but needs better support and availability for large deployments.
We have been using Torq for one and a half years, but we have experienced no downtime.
Angular Developer at Flourish Software
Most of the time, the system is stable as long as the components that they integrate with are stable.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
I have never faced any downtime or issues.
Senior Information Technology Security Consultant at Mideast Data Systems
The system works smoothly even when I navigate deep into the playbook section.
Assistant Security Architect at Cloudnomics
I would rate the stability and reliability of Palo Alto Networks Cortex XSOAR as a nine.
Lead Application Security Engineer Iv at a financial services firm with 5,001-10,000 employees
We have not experienced any downtime, crashes, or performance issues.
Cyber Security Network Security Engineer at Cirrus Logic
We have not seen any impact in the work that we do with Splunk SOAR or the SIEM platform.
Manager cybersecurity at Hexion Inc.
I have not encountered any outages or glitches within my experience with Splunk SOAR.
Global Head Of Security Architecture Digital & Technology at Aramex
 

Room For Improvement

Torq users request improved AI integration, search functionalities, dashboards, transparency, templates, data manipulation, bulk editing, and playbooks.
Cortex XSOAR requires improved documentation, intuitive UI, modularity, integration, costs, setup, licensing, performance, and usability for efficiency.
Splunk SOAR users face integration challenges, UI issues, scalability concerns, and desire AI development, customizable tools, and better support.
VMware Carbon Black Cloud struggles with intelligence, usability, performance issues, inadequate support, and high costs, affecting its efficiency.
Torq should offer default templates that can directly scan firewall data and automate actions.
Senior Information Technology Security Consultant at Mideast Data Systems
The AI value depends on maturity. Real value depends heavily on telemetry, integration depth, and workflow design, all of which rely on how mature customers are in their SOC department.
Security Consultant at Integrity360
It was able to capture data but was unable to differentiate between the agent hostname we are using and the hostname that resides on the back end of the Internet.
Senior Consultant at a university with 10,001+ employees
The deployment requires integration and the development of integration modules.
Presale Engineer at Westcon-Comstor
One of the significant issues we encounter is system slowdown when we receive an influx of alerts, which inhibits how quickly we can access the information needed for investigation.
Enterprise Security Architect V at FirstEnergy
To improve the solution, it needs to have complete features that are low-code, no-code, and should be plug-and-play.
Vice President, Technology at Cache Digitech Pvt Ltd.
If we start ingesting those data to Splunk SOAR or SIEM with some sort of integration with threat intelligence feed, that will also improve our detection and prediction method or help us with the investigation.
Manager cybersecurity at Hexion Inc.
Torq is better than Splunk SOAR because Torq has a no-code UI where we can accomplish anything through drag and drop.
Senior Information Technology Security Consultant at Mideast Data Systems
Visibility into automated response actions and investigation workflows that help analysts to quickly identify threats and understand attack patterns.
Soc Analyst at Softcell Technologies
I recall we couldn't upgrade because the sensor was not compatible, and the latest VMware Carbon Black Cloud version was not compatible with the latest Red Hat version.
Sec consultant at a tech services company with 5,001-10,000 employees
 

Setup Cost

Torq's pricing is seen as affordable by some, costly by others, but enterprises value its modern features.
Cortex XSOAR is costly but offers valuable features; small businesses may find discounts helpful in mitigating expenses.
Splunk SOAR's pricing receives mixed reviews, seen as justified by some, but costly for small to medium businesses.
VMware Carbon Black Cloud offers varied pricing experiences, but users often secure competitive rates through resellers with few surprises.
When they bring more and more value into the platform, it makes more sense to pay that price, but still, it is expensive.
Senior Cyber Architect at a manufacturing company with 10,001+ employees
Before deciding to implement Torq, I considered that compared to our old case management platform, Torq was a much better price and had a lot better value for what you get out of the platform, which was a key consideration for the company.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
It is an expensive solution, not an inexpensive solution, but we get through the flexibility.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
For customers, it is zero versus $20 million, which is why they have to make a decision.
Vice President, Technology at Cache Digitech Pvt Ltd.
It is way below what it costs to hire some professionals to do only that type of work.
Splunk Engineer at Data Elicit Solutions Pvt. Ltd.
Splunk SOAR is moderately priced, neither cheap nor overly expensive.
Splunk/SOAR Engineer
I am familiar with the pricing aspect, setup cost, and licensing cost of Splunk SOAR, and it is pretty much similar to what industries are offering these days.
Manager cybersecurity at Hexion Inc.
 

Valuable Features

Torq enhances efficiency by streamlining workflows with AI, automation, and seamless integrations, offering user-friendly customization and scalability.
Palo Alto Networks Cortex XSOAR excels in automation, integration, and ease-of-use, enhancing incident response and threat intelligence capabilities.
Splunk SOAR integrates seamlessly, enhances workflow efficiency through automation, and offers customization, improving visibility and incident response time.
VMware Carbon Black Cloud provides endpoint isolation, threat detection, and real-time protection with minimal disruption and efficient threat management.
Torq's unified platform approach to AI SOC automation and case management has significantly benefited us by integrating the case management platform with the automation, which saves time compared to managing multiple point solutions across our security stack.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
The fact that I can build whatever I want within my own imagination and skills without relying on code is the best thing about Torq.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
You can copy and paste a cURL command. If you have documentation or APIs, you usually have an example on the side. You basically have all the information on how the API call should be. You can just copy that and paste it into a step, and it will just build the step for you.
Global IT Director at OpenWeb
Execution of automatic tasks for collecting, enriching, and correlating security events from hundreds of different technologies.
Presale Engineer at Westcon-Comstor
If I already have an established process, I do not have to change my process to fit into the tool. I can modify the tool to fit into my process, which makes things considerably easier.
Enterprise Security Architect V at FirstEnergy
We have implemented automation features, such as automated responses to email threats and automatic configuration of target devices for blocking specific IPs.
Vice President, Technology at Cache Digitech Pvt Ltd.
Creating playbooks using the Playbook Editor in Splunk SOAR is easy. The editor is designed to be user-friendly with visual drag and drop features, allowing for easy workflows without writing any code.
Splunk/SOAR Engineer
Splunk SOAR saves time in threat response, and the time to solve an incident is currently the best in the market.
Strategic Account Executive at a computer software company with 51-200 employees
Splunk SOAR has improved our MTTD and MTTR both with the consolidation with a unified platform with Splunk.
Manager cybersecurity at Hexion Inc.
 

Mindshare comparison

Security Orchestration Automation and Response (SOAR) Mindshare Distribution
ProductMindshare (%)
Palo Alto Networks Cortex XSOAR8.8%
Microsoft Sentinel10.1%
Splunk SOAR7.4%
Other73.7%
Security Orchestration Automation and Response (SOAR)
Security Orchestration Automation and Response (SOAR) Mindshare Distribution
ProductMindshare (%)
Splunk SOAR7.4%
Microsoft Sentinel10.1%
Palo Alto Networks Cortex XSOAR8.8%
Other73.7%
Security Orchestration Automation and Response (SOAR)
Security Incident Response Mindshare Distribution
ProductMindshare (%)
VMware Carbon Black Cloud9.6%
ServiceNow Security Operations9.1%
SECDO Platform7.3%
Other74.0%
Security Incident Response
 

Featured Reviews

AD
Solutions Architect at Swimlane
Automation has streamlined multi-tenant SOC workflows and improves alert handling efficiency
Although the reporting within Torq is not that great, we did ask for many features regarding reporting in Torq, but due to some platform constraints, they could not make the whole dataset available for us to be used in reporting. Except for that, we used some basic reporting. When I used Torq, it was indeed in the early stages of AI capabilities. Only a few customers were allowed to use it, and we were among them. It functioned well as long as we summarized the data properly. If you input garbage, you would get garbage out. Thus, we had to do significant fine-tuning regarding what data context we provided to the AI orchestrator to get meaningful results. In terms of Torq's unified platform approach to AI SOC automation and case management compared to managing multiple point solutions across my security stack, I find it case-centric. The unified view in case management is good since it provides clarity, although there are limitations regarding how many items in case management can be modified at once. Bulk operations are very limited, potentially due to their back-end database or data retrieval processes that can be improved. Regarding improvements for Torq, when we were onboarded, there were aspects we were uncertain about, such as the number of cases that could be generated, what data we could bring in, how many clients we could onboard, and similar concerns. Initially, we also lacked clarity about the number of playbooks or workflows we could build. Different triggers like system triggers, case-based triggers, and others can be employed without restrictions, but when it comes to on-demand and scheduled jobs, there is a limitation based on the subscription and pricing tier that notably caps the number of workflows we can create. No bulk editing across cases was one issue, along with limited filtering related to single grouping constraints. Additionally, the out-of-the-box case templates provided require substantial modifications before they become usable. There is also a feature in the cases for notes that cannot be searched. They are only visible through the UI, which is another area for improvement. The workflow and execution-based charges seem misleading as this was not discussed initially. I am not sure if new customers are made aware of this. It seems that workflows revolving around cases hinder functionality outside of case management, as we have many use cases needing on-demand triggers and schedules for functions like reporting or polling devices. Creating additional workflows to achieve basic functionalities raises costs significantly, which disadvantages customers. While they facilitate optimization and scaling, the support received tends to be very basic. Improvements can be made in that area as well.
Sricharan R - PeerSpot reviewer
Lead Application Security Engineer Iv at a financial services firm with 5,001-10,000 employees
Security automation has transformed incident workflows and now reduces response time dramatically
I think the areas of Palo Alto Networks Cortex XSOAR that could be improved are mainly in UX. We have communicated with the vendor team about this, but they are prioritizing product functionality over usability because most target customers are technical and understand a primitive UI. They face difficulties in implementing UI changes as their team is stretched. Thus, the UI/UX of the tool needs significant improvement. There are plans on their roadmap, but a lot remains to be done. Parts of the tool run on an older framework, causing slowness. Usability is a broader issue than features alone. This usability problem is common in many cybersecurity tools, unlike customer-facing applications. Some integrations have speed issues and might not function seamlessly with different upstream configurations, requiring manual updates. These are the main pain points we encountered, particularly with UI/UX, integration speed, and the usability of certain inbuilt playbooks.
SS
Manager cybersecurity at Hexion Inc.
Automates threat response and reduces investigation time but needs better threat intelligence integration
One thing that we would like to see with Splunk SOAR is the expandability to the threat intelligence feed. Currently, we have limited ingestion to the threat intelligence feed for the correlation purpose. We would like to see it being integrated, with license cost or without license cost, to leading threat intelligence sources such as Recorded Future, Feedly, or Flare. That is something we would appreciate having integrated. The second thing on the improvement side is about exposed credential-related information. If we start ingesting those data to Splunk SOAR or SIEM with some sort of integration with threat intelligence feed, that will also improve our detection and prediction method or help us with the investigation.
reviewer2771742 - PeerSpot reviewer
Sec consultant at a tech services company with 5,001-10,000 employees
Has supported consistent deployment across departments but needs better OS compatibility and detection performance
I am not really looking for a new solution, actually, I was preparing for an interview and wanted to have a comparison between both tools. I have not worked with any of these products before, but we had a training demonstration yesterday with Dynatrace, and I have investigated the Wiz solution better. In terms of experience, it will be my first time with CDR. I am working with something for EDR, specifically, we have an EDR, it's VMware Carbon Black Cloud. They have a hybrid environment, both on-prem and cloud. I would usually recommend this product for big companies, because it's not cheap, so only big companies would I expect to pay for that. The review rating for VMware Carbon Black Cloud is 6 out of 10.
report
Use our free recommendation engine to learn which Security Orchestration Automation and Response (SOAR) solutions are best for your needs.
896,510 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Comms Service Provider
10%
Construction Company
9%
Manufacturing Company
9%
Financial Services Firm
12%
Computer Software Company
9%
Manufacturing Company
8%
Government
6%
Financial Services Firm
12%
Manufacturing Company
9%
Computer Software Company
7%
University
6%
Construction Company
12%
Comms Service Provider
11%
Financial Services Firm
8%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise5
Large Enterprise5
By reviewers
Company SizeCount
Small Business21
Midsize Enterprise9
Large Enterprise26
By reviewers
Company SizeCount
Small Business18
Midsize Enterprise7
Large Enterprise39
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise3
Large Enterprise9
 

Questions from the Community

What needs improvement with Torq?
To improve alert handling capability, there are ready-to-use playbooks available, but there are very few. Torq should...
What is your primary use case for Torq?
Torq is primarily used for security operations, mainly for the SOC team. I develop use cases based on requirements fr...
What advice do you have for others considering Torq?
The maintenance side is very good because we are using the product to reduce activities. For instance, sometimes ther...
What is your experience regarding pricing and costs for Palo Alto Networks Cortex XSOAR?
Comparing pricing to Micro Focus, they were offering bundles, making it free with their SIEM. For customers, it is ze...
What needs improvement with Palo Alto Networks Cortex XSOAR?
Regarding areas for improvement in Palo Alto Networks Cortex XSOAR, I want to highlight one concern about playbook cr...
What is your primary use case for Palo Alto Networks Cortex XSOAR?
My primary use cases for Palo Alto Networks Cortex XSOAR are malware incidents, specifically phishing-related inciden...
What is your experience regarding pricing and costs for Splunk Phantom?
My experience with pricing, setup cost, and licensing is that it is perfectly acceptable, helping us significantly wi...
What needs improvement with Splunk Phantom?
From the improvement point of view regarding Splunk SOAR, I suggest including more types of LLM models such as autono...
What is your primary use case for Splunk Phantom?
The use cases that I work with mostly in Splunk SOAR include phishing email responses automation, where Splunk detect...
What to choose: an endpoint antivirus, an EDR solution or both?
I can recommend Carbon Black, an award-winning next-gen anti-virus (NGAV) and endpoint detection and response (EDR) s...
What's the difference between Carbon Black CB Response and Carbon Black CB Defense?
Carbon Black offers two different levels of Endpoint Detection and Response. One is the VM Carbon Black Cloud Endpoin...
What needs improvement with Carbon Black CB Response?
I see room for improvement as I remember some problems on compatibility with some operating systems; I recall we coul...
 

Also Known As

No data available
Demisto Enterprise, Cortex XSOAR, Demisto
Phantom
Carbon Black CB Response
 

Overview

 

Sample Customers

Information Not Available
Cellcom Israel, Blue Cross and Blue Shield of Kansas City, esri, Cylance, Flatiron Health, Veeva, ADT Cybersecurity
Recorded Future, Blackstone
ALLETE belk
Find out what your peers are saying about Microsoft, Splunk, Palo Alto Networks and others in Security Orchestration Automation and Response (SOAR). Updated: May 2026.
896,510 professionals have used our research since 2012.