Try our new research platform with insights from 80,000+ expert users

D3 Security vs Splunk SOAR comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 5, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

D3 Security
Ranking in Security Orchestration Automation and Response (SOAR)
18th
Average Rating
9.0
Reviews Sentiment
7.5
Number of Reviews
2
Ranking in other categories
Security Incident Response (8th), AI-Powered Security Automation (4th)
Splunk SOAR
Ranking in Security Orchestration Automation and Response (SOAR)
3rd
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
50
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of November 2025, in the Security Orchestration Automation and Response (SOAR) category, the mindshare of D3 Security is 0.8%, up from 0.4% compared to the previous year. The mindshare of Splunk SOAR is 7.6%, down from 7.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Orchestration Automation and Response (SOAR) Market Share Distribution
ProductMarket Share (%)
Splunk SOAR7.6%
D3 Security0.8%
Other91.6%
Security Orchestration Automation and Response (SOAR)
 

Featured Reviews

Muhammad Aamir Riaz - PeerSpot reviewer
Offers open API for integrating any available tools without any recurring costs
Before committing, I recommend a Proof of Concept (POC) or demo first. This way, you can see if the product aligns with your specific use cases and security needs. Knowledge transfer is key, and D3 Security's team excels in this area. During the POC, your analysts gain valuable product knowledge, putting them ahead of the curve for deployment. In our case, the learning curve was steep initially, but by the end of the POC, my team was already building playbooks independently. D3 Security also schedules dedicated knowledge transfer sessions during the POC, making it a win-win for both parties. Since technology transfer is crucial for government entities like ours, this approach eliminates the need for additional learning after deployment, unlike with certain competitors like the Fortinet FortiSOAR case. While Fortinet FortiSOAR achieved the desired tasks, its knowledge transfer process was lacking, leaving us with a shaky foundation. D3 Security's approach solidifies the learning and empowers our team. Overall, I would rate the solution an eight out of ten.
Hamada Elewa - PeerSpot reviewer
Creating automation workflows has reduced detection time but integration and visibility challenges remain
The visibility of Splunk SOAR's playbook viewer is rather unclear to me; I wonder what the visibility is for. There are indeed some problems with integrating Splunk SOAR with other Splunk products or other vendors in my system, and it took a while after implementing Splunk SOAR to train my SOC team on how to use the playbooks. Splunk SOAR does not help me reduce my security event volume; in fact, it makes them massive. Splunk SOAR does not help me free up resources to work on other projects; they are not good in this regard. I have not seen time to value with Splunk SOAR; I am curious about what time to value means. I believe Splunk SOAR can be improved by adding more integrations and out-of-the-box integrations, and by increasing the number of admins that can access the solution simultaneously. I see the need to inject more AI in creating the playbooks. I think they can inject more threat intelligence into the solution.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It is an out-of-the-box automated integration with our 20 departments. We perform L1 LiveOps automatically through the portal."
"The solution's valuable feature is its GUI. It has more than 450 connectors, which are excellent for connecting devices and automating integration. The solution has all the features we need. We deployed it in our environment, and it's fully integrated. Thanks to their open APIs, the seamless integration makes everything work well together."
"Splunk has many features that make work easier, and it's simple to implement in a large production environment. Splunk collects a massive amount of data from cloud servers and handles it perfectly."
"The best feature is the integration and the custom Python code that we can write. Splunk SOAR provides us with both of these capabilities, allowing us to integrate different security solutions with Splunk SOAR and take remediation actions directly on those security tools."
"The customization of the playbook in Splunk SOAR is very beneficial."
"When you design a playbook, you can integrate multiple log sources and define rules... After that, the platform automatically compiles all these activities and, based on the results, the analyst only has to indicate whether the result is a true or false positive. That reduces the time and effort involved."
"Surprisingly, the mobile app is valuable because it is very convenient for our on-call analysts to respond and get alerted to security alerts and events wherever they are. We are able to harness the power of Splunk SOAR and everything that we are doing, and we are also able to alert our on-call analysts 24/7. From their mobile phone, they can respond to those alerts."
"Workflow management is most valuable. It is easily customizable"
"The most valuable features are the Splunk SOAR apps and playbooks."
"The product’s integration with other Splunk products is valuable."
 

Cons

"The reporting, especially custom reporting, needs to be improved. Additionally, it would be better if it could be hosted on Linux."
"Reporting needs improvement. MTTR and MTTD metrics aren't directly available in playbooks and require manual effort to achieve."
"I'm not an expert on Splunk SOAR, but I'm sure our team members know what areas could be improved."
"We have playbooks written to extract these events and put them into the workflow since it wasn't structured as expected. It was a miss for us. We couldn't figure out why it broke or what actually happened there. It was something in this feed with legitimate and security events, so we tried to understand the names and what we would call them."
"Various aspects of the playbook development process itself can be optimized."
"Splunk SOAR should improve its ease of upgrade, which is a pain point for us right now."
"Portability is one thing that is currently lacking. The open-source product that I evaluated had portability. It would require a lot of development effort, but it will save the cost of rewriting all the playbooks."
"Splunk SOAR can improve IoT/OT security-related case studies or your use cases. Their integration with identity and access management (IAM) solutions is a bit shaky. They don't have good integration with a lot of IAM solutions. They do have good capability in terms of user access management internally, but even with privileged user access, they have a good module. However, if they have to integrate with solutions, such as CyberArk or IBM IAM solutions they are lacking, the visibility of user access is not that much."
"It would be ideal for us if Splunk SOAR could integrate with Teams."
"In my opinion, the focus should be on improving its simplicity, specifically the interface, and configuration."
 

Pricing and Cost Advice

Information not available
"The licensing cost is reasonable."
"I found the price of Splunk SOAR to be good."
"The tool is not cheap."
"I don't know the exact price, but for my region, it is very expensive."
"Splunk SOAR is more expensive compared to other options for SOAR."
"Splunk is a fast enterprise tool, but it costs too much. At the same time, it's worth what we pay, in my opinion. We can efficiently perform all the functions and tie together the data. It's the perfect tool for our needs."
"In my opinion, the price is high, but if you want good products, you have to be willing to pay for them."
"Splunk SOAR is moderately priced, neither cheap nor overly expensive."
report
Use our free recommendation engine to learn which Security Orchestration Automation and Response (SOAR) solutions are best for your needs.
873,085 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
23%
Computer Software Company
21%
University
9%
Outsourcing Company
9%
Financial Services Firm
12%
Computer Software Company
11%
Manufacturing Company
9%
University
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business12
Midsize Enterprise7
Large Enterprise30
 

Questions from the Community

What do you like most about D3 Security?
It is an out-of-the-box automated integration with our 20 departments. We perform L1 LiveOps automatically through the portal.
What is your experience regarding pricing and costs for D3 Security?
We follow a different procurement process. For example, Fortinet qualified technically but lost out in the financial stage due to a two-stage bidding process. So, pricing can be subjective and depe...
What needs improvement with D3 Security?
The reporting, especially custom reporting, needs to be improved. Additionally, it would be better if it could be hosted on Linux.
What do you like most about Splunk Phantom?
Splunk SOAR's quick response to incidents is the most valuable part.
What is your experience regarding pricing and costs for Splunk Phantom?
I don't have experience with costs; management handles that aspect.
What needs improvement with Splunk Phantom?
I'm not an expert on Splunk SOAR, but I'm sure our team members know what areas could be improved. I haven't spoken to them specifically about what could be improved or what they would want Splunk ...
 

Also Known As

No data available
Phantom
 

Interactive Demo

Demo not available
 

Overview

 

Sample Customers

S&P Global, Scotiabank, Cybereason, Cummins
Recorded Future, Blackstone
Find out what your peers are saying about D3 Security vs. Splunk SOAR and other solutions. Updated: September 2025.
873,085 professionals have used our research since 2012.