No more typing reviews! Try our Samantha, our new voice AI agent.

Cofense Platform vs Splunk SOAR comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare One
Sponsored
Average Rating
8.6
Reviews Sentiment
6.5
Number of Reviews
23
Ranking in other categories
Email Security (20th), Secure Web Gateways (SWG) (12th), Data Loss Prevention (DLP) (23rd), Cloud Access Security Brokers (CASB) (12th), Distributed Denial-of-Service (DDoS) Protection (8th), Software Defined WAN (SD-WAN) Solutions (13th), Access Management (12th), Bot Management (3rd), ZTNA as a Service (8th), ZTNA (4th), Secure Access Service Edge (SASE) (9th), Remote Browser Isolation (RBI) (2nd)
Cofense Platform
Average Rating
0.0
Reviews Sentiment
7.1
Number of Reviews
1
Ranking in other categories
Email Security (33rd), Security Incident Response (12th), Threat Intelligence Platforms (TIP) (43rd), Security Awareness Training (11th)
Splunk SOAR
Average Rating
8.2
Reviews Sentiment
6.4
Number of Reviews
66
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (1st)
 

Mindshare comparison

Email Security Mindshare Distribution
ProductMindshare (%)
Cofense Platform1.2%
Proofpoint Email Protection6.3%
Microsoft Defender for Office 3655.7%
Other86.8%
Email Security
Security Orchestration Automation and Response (SOAR) Mindshare Distribution
ProductMindshare (%)
Splunk SOAR7.1%
Microsoft Sentinel9.3%
Palo Alto Networks Cortex XSOAR8.9%
Other74.7%
Security Orchestration Automation and Response (SOAR)
 

Featured Reviews

CV
Network Architect at IP Dimension
Cloud security has improved remote access and has reduced costs for smaller client sites
I have used Cloudflare One's Identity-Aware Proxy, and it is quite straightforward from what I have seen so far. The app registration on the Azure side integrates fully into Cloudflare, and I am very satisfied with that part because it is easy to set up. The integration of Cloudflare One's Secure Web Gateway and Zero Trust Network Access works without any issues. That part is pretty automatic, and if you complete the rest of the setup, it comes together by itself with no issues from my side. What makes it nice is that we can actually start replacing on-site firewalls at this stage for the smaller clients because it does not matter if they go to a coffee shop or work from home; they are still secured by the same connection. The hops get shorter and you get better latency. We have done testing to see if it is better. One thing that we did notice with our proof of concept with our current client is that they have people connecting from the UK. When they used their previous VPN solution, uploading CAD drawings and other files to the server took a long time. They mentioned that it is much quicker on Cloudflare One's solution. I definitely believe that is part of the improved performance, and I am satisfied with that as well. What is nice about Cloudflare One is that it makes the setup easier and also easier to train technicians to maintain it. Compared to legacy systems, we do not need to get fancy firewalls in place that are costly. That is definitely also a cost-saver with Cloudflare One.
MohamedShaker - PeerSpot reviewer
Sales Team Leader at ITVikings
Secures the business for customers quickly and accurately
It secures the business for the customers. For instance, if any phishing emails come into the environment and employees see it, we direct the email to Triage. The Triage system will investigate it through AI technology to see if it's a phishing email or not. If it is a phishing email, it will quarantine it and erase it from the environment.
Vikash Kushwaha - PeerSpot reviewer
Full Stack Software Engineer at mindpathtech
Automated playbooks have transformed incident response and now protect critical services
The biggest advantage I see from my personal experience as an integrator with Splunk SOAR is that it integrates with most of the security features among the Defenders, Microsoft Defender, firewalls, CloudWatch, and AWS security agents, as well as EC2 machines, firewalls, EDR, IAM, email security, and antivirus. It automates the security process over phishing emails and any other brute force attacks. It helps quite a lot because if 100 phishing emails were sent to a domain, a developer can only reach one, two, or five, but for hundreds of others, it actually supports better automated playbooks and provides major security. Splunk SOAR introduced some new and innovative capabilities or approaches that transformed the way my SOC operates. Splunk SOAR provides playbooks for automatic security features, such as for firewalls, phishing mails, and utilizing Defenders or virtual tools. A playbook maintains its algorithms or processes, so if any kind of security issue arises, the playbook automatically runs and handles actions such as IP blocking or resolving brute force attacks, notifying the admin about suspicious users. After implementing Splunk SOAR, the training process for my SOC team to use playbooks takes a long time during the whole integration part, as it retrieves all credentials from us, whether for an EC2 machine or any antivirus. It takes about one to two months for the team to fully sustain and know the processes of the playbooks and security, particularly for three or four individuals in the cyber security or DevOps team. Splunk SOAR significantly reduces the time spent on monotonous security tasks. In banking, insurance, or healthcare, automated services for addressing phishing emails and security threats are common. Having a manual workforce of two or three individuals can only handle five or ten security threats while Splunk SOAR automates the entire process across apps and machines, making it easier and notifying the admin about the threats. If someone tries to breach, Splunk SOAR immediately processes incoming requests, validating them and blocking any unsecured requests, which reduces a lot of time and effort. With the help of the playbook viewer, I assess the visibility provided by Splunk SOAR as very positive, especially for security purposes. If someone is attacked by 100 users, it blocks all the users, while individual developers such as myself can only handle two or three at a time. The automated process of Splunk SOAR handles all the processes concurrently, making it a game-changing solution. It helps reduce mean time to resolve (MTTR). It takes around 10 to 20 minutes to resolve one incident through the whole process and notify the admin of the issue. If there are multiple incidents, calculating the time taken for each, it generally requires around 40 to 50 minutes to resolve five incidents.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Enables me to work from two locations."
"I'm very satisfied with the environment and the dashboard."
"The tool also offers good scalability, and the dashboard, along with real-time analytics, is very good."
"It's the endpoint exposition. We don't need to expose our VPN server to the internet and need a zero-test solution. I can apply some conditional access to the endpoint that's connecting to our network to check their security policies or the security condition of their workstation. Once the workstation is trying to connect to my internal network, then I would like to check the discrete condition of these endpoints that are trying to access my internal network. We created some conditional access. We have CrowdStrike, to check if the CrowdStrike is installed, to check if it's updated, and to check for Windows updates. We created some conditional policies to check it."
"Cloudflare is simple to use."
"We mostly use Cloudflare WAF, and gets basic Cloudflaire DDoS, caching as extra bonus . We like the factor these features are all integrated into 1 console, simple to manage."
"Cloudflare One has assisted in securing my remote workforce through a SASE solution with Cloudflare One and the Workers part, although I am not currently using the Workers component."
"Cloudflare Access is part of the Zero Trust philosophy."
"It secures the business for the customers."
"For instance, if any phishing emails come into the environment and employees see it, we direct the email to Triage. The Triage system will investigate it through AI technology to see if it's a phishing email or not. If it is a phishing email, it will quarantine it and erase it from the environment."
"One particular example I can recall is that in enterprise, we get around 100 to 200 notables daily, which consumes approximately 16 to 40 hours per day for an analyst, but since we have Splunk SOAR, it is now just about five to seven minutes or five to 10 minutes per alert."
"Splunk SOAR's quick response to incidents is the most valuable part."
"The automation part of the product is great, Splunk SOAR can easily be connected with a lot of solutions that are available out there, and the in-built apps are pretty useful to me."
"It has definitely saved a decent amount of time for our analysts so they can focus on other tasks."
"Splunk SOAR is more user-friendly than those tools and provides more precise and advanced information that we require to analyze whether a case is a true positive or false positive."
"Very flexible integration with other tools"
"Splunk SOAR has helped to improve my company's business resilience."
"Its ability to integrate with other systems and applications in our environment is pretty easy. Sometimes if we see any complexity we try to involve a consultant to help us. Everything is through the built-in app. Splunk can connect to any assets through the built-in app. It could be in a platform, firewalls, or endpoints. It's easy if it's an app integration."
 

Cons

"The free plan has limitations. For example, I can only set up three rules, and the application firewall is unavailable."
"I would like them to include a VPN feature to provide a secure connection to the data center."
"When there are any dynamic changes in complex applications, the tool takes a lot of time, making its analytics-related area a major matter of concern where improvements are needed."
"Cloudflare One is not very powerful, but for what we require, it is basic and sufficient."
"There are premium tier live service and lower tier live service, so we opted for the lower tier. But there is no medium tier where we pay a little extra and get a bit more service. So if that can be improved."
"Feedback could be enhanced. While I work efficiently with Clover as a partner in Mexico City, sometimes the information and requests are easier to manage with more concrete solutions."
"The software has automated alerts, but the automated alerts are not available in the mobile app."
"Operating and tuning the product is difficult."
"If they continue improving and enhancing this solution, it could be even faster and more accurate."
"The application does not work properly and does not pass the log-based configuration. I feel that some kind of review should happen in the application. This review should validate things so that we can get the right information. Splunk does not tell us where the IP address is associated with."
"Some of the training materials are on a basic level."
"The cost of Splunk SOAR has room for improvement."
"The number of playbooks on offer should be increased."
"We've run into a few minor issues. Some of the playbook writing is a bit complicated. We've had a few hiccups with the source control. We'd really like to use GitHub deployment keys for a dedicated account. We haven't been able to do that. I think those are some of the major ones."
"What we have seen is if the workflow gets halted or if we want to halt a workflow, it cannot be resumed."
"Splunk SOAR can improve IoT/OT security-related case studies or your use cases. Their integration with identity and access management (IAM) solutions is a bit shaky. They don't have good integration with a lot of IAM solutions. They do have good capability in terms of user access management internally, but even with privileged user access, they have a good module. However, if they have to integrate with solutions, such as CyberArk or IBM IAM solutions they are lacking, the visibility of user access is not that much."
"The Splunk SOAR case management feature lacks some of the functionalities like the possibility to fully customize the fields for the tickets/events and create custom statuses."
 

Pricing and Cost Advice

"The price tag is no longer $200,000, but rather $300,000 to $400,000. It's twice."
"The solution's pricing lacks transparency."
"The pricing is somewhere in the middle. I would rate the pricing a seven out of ten."
"My company has to make yearly payments towards the licensing costs attached to the solution. There are no hidden charges apart from the licensing costs of the solution."
"The prices are slightly expensive."
"The solution is not that expensive."
"Cloudflare Zero Trust Platform's pricing is good."
"The pricing of the solution is cheap. The licensing cost is also very low. I rate the cost and pricing a three out of ten."
Information not available
"It's very overpriced because it is based on the number of users. There is no bulk licensing."
"The licensing cost is reasonable."
"When we first purchased our Splunk SOAR license, it was based on an event-count model. It was based on the number of events. I had strong opinions at the time that automation should not be stifled by the amount of automation you can accomplish, so the previous structure was not as beneficial for us. Later that year, we got told or saw at a conference that they announced user-based pricing. We are now in a renewal period, so we migrated to a user-based license model, which is more appropriate for us so that we no longer have to worry about stifling our automation based on the quantity."
"The tool is not cheap."
"We renewed it this year. This year was the first time there was a dramatic increase in the price. It was kind of non-negotiable. It was just a high increase. We had internal communications, and it was definitely a surprise to us. In a short time frame, we renewed it this year. Prices are going up everywhere, but they are not always justifiable, at least not to our eyes. The pricing this year was definitely a big shock."
"Splunk SOAR is moderately priced, neither cheap nor overly expensive."
"The cost is high and the licensing is on an annual basis."
"While I can't confirm the exact pricing, some colleagues have mentioned that Splunk SOAR may be on the costlier side."
report
Use our free recommendation engine to learn which Email Security solutions are best for your needs.
909,679 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
18%
Comms Service Provider
11%
Outsourcing Company
8%
Financial Services Firm
8%
Construction Company
18%
Comms Service Provider
12%
Manufacturing Company
9%
Energy/Utilities Company
7%
Financial Services Firm
12%
Manufacturing Company
9%
Construction Company
9%
Outsourcing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise1
Large Enterprise12
No data available
By reviewers
Company SizeCount
Small Business18
Midsize Enterprise10
Large Enterprise47
 

Questions from the Community

What needs improvement with Cloudflare Zero Trust Platform?
In my opinion, Cloudflare One can be improved mainly through compatibility, as the integration should be much simpler...
What is your primary use case for Cloudflare Zero Trust Platform?
Cloudflare One's primary use case for my organization is to protect servers and to provide remote access with the VPN...
Ask a question
Earn 20 points
What is your experience regarding pricing and costs for Splunk Phantom?
For pricing, I would rate Splunk SOAR a seven where one is high price and ten is low price.
What needs improvement with Splunk Phantom?
When it comes to Splunk SOAR, in terms of improvement, I feel there should be some pre-deployed solutions available. ...
What is your primary use case for Splunk Phantom?
I started working with Splunk SOAR four years ago. I provide Splunk SOAR solutions to our customers as an MSSP. We wo...
 

Also Known As

Cloudflare Area 1 Email Security, Cloudflare Bot Management, Cloudflare Gateway, Cloudflare Zero Trust Platform, Cloudflare DDoS, Cloudflare SASE & SSE Platform
Cofense Intelligence, PhishMe Intelligence, Intelligence ThreatHQ, Cofense Triage, Cofense LMS
Phantom
 

Overview

 

Sample Customers

23andMe
Jackson Health System
Recorded Future, Blackstone
Find out what your peers are saying about Proofpoint, Microsoft, Check Point Software Technologies and others in Email Security. Updated: July 2026.
909,679 professionals have used our research since 2012.