No more typing reviews! Try our Samantha, our new voice AI agent.

DFLabs IncMan SOAR vs Splunk SOAR comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Torq
Sponsored
Average Rating
8.8
Reviews Sentiment
6.6
Number of Reviews
20
Ranking in other categories
AI-SOC (1st), AI-Powered Security Automation (1st)
DFLabs IncMan SOAR
Average Rating
0.0
Reviews Sentiment
7.3
Number of Reviews
1
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (29th)
Splunk SOAR
Average Rating
8.2
Reviews Sentiment
6.4
Number of Reviews
76
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (1st)
 

Featured Reviews

AD
Solutions Architect at ProArch
Automation has streamlined multi-tenant SOC workflows and improves alert handling efficiency
Although the reporting within Torq is not that great, we did ask for many features regarding reporting in Torq, but due to some platform constraints, they could not make the whole dataset available for us to be used in reporting. Except for that, we used some basic reporting. When I used Torq, it was indeed in the early stages of AI capabilities. Only a few customers were allowed to use it, and we were among them. It functioned well as long as we summarized the data properly. If you input garbage, you would get garbage out. Thus, we had to do significant fine-tuning regarding what data context we provided to the AI orchestrator to get meaningful results. In terms of Torq's unified platform approach to AI SOC automation and case management compared to managing multiple point solutions across my security stack, I find it case-centric. The unified view in case management is good since it provides clarity, although there are limitations regarding how many items in case management can be modified at once. Bulk operations are very limited, potentially due to their back-end database or data retrieval processes that can be improved. Regarding improvements for Torq, when we were onboarded, there were aspects we were uncertain about, such as the number of cases that could be generated, what data we could bring in, how many clients we could onboard, and similar concerns. Initially, we also lacked clarity about the number of playbooks or workflows we could build. Different triggers like system triggers, case-based triggers, and others can be employed without restrictions, but when it comes to on-demand and scheduled jobs, there is a limitation based on the subscription and pricing tier that notably caps the number of workflows we can create. No bulk editing across cases was one issue, along with limited filtering related to single grouping constraints. Additionally, the out-of-the-box case templates provided require substantial modifications before they become usable. There is also a feature in the cases for notes that cannot be searched. They are only visible through the UI, which is another area for improvement. The workflow and execution-based charges seem misleading as this was not discussed initially. I am not sure if new customers are made aware of this. It seems that workflows revolving around cases hinder functionality outside of case management, as we have many use cases needing on-demand triggers and schedules for functions like reporting or polling devices. Creating additional workflows to achieve basic functionalities raises costs significantly, which disadvantages customers. While they facilitate optimization and scaling, the support received tends to be very basic. Improvements can be made in that area as well.
reviewer1137807 - PeerSpot reviewer
Technical Team Manager at a tech services company with 11-50 employees
Protects an organization from the threat of a data breach or cyberattack
The vendors themselves will actually help with any customizations a client may require. Many vendors don't offer this service or if they do, they charge very high rates. Their vendors are very helpful; they will walk you through the whole Playbook until you have a good grasp of the product. Also, in terms of integration, it is very seamless compared to other cybersecurity products. They also have good features such as multi-tenancy. Every user would like to see these kinds of fanciful features on a robust interface. It actually makes the user feel like they are in a sci-fi movie.
Vikash Kushwaha - PeerSpot reviewer
Full-Stack Software Engineer at mindpathtech
Automated playbooks have transformed incident response and now protect critical services
The biggest advantage I see from my personal experience as an integrator with Splunk SOAR is that it integrates with most of the security features among the Defenders, Microsoft Defender, firewalls, CloudWatch, and AWS security agents, as well as EC2 machines, firewalls, EDR, IAM, email security, and antivirus. It automates the security process over phishing emails and any other brute force attacks. It helps quite a lot because if 100 phishing emails were sent to a domain, a developer can only reach one, two, or five, but for hundreds of others, it actually supports better automated playbooks and provides major security. Splunk SOAR introduced some new and innovative capabilities or approaches that transformed the way my SOC operates. Splunk SOAR provides playbooks for automatic security features, such as for firewalls, phishing mails, and utilizing Defenders or virtual tools. A playbook maintains its algorithms or processes, so if any kind of security issue arises, the playbook automatically runs and handles actions such as IP blocking or resolving brute force attacks, notifying the admin about suspicious users. After implementing Splunk SOAR, the training process for my SOC team to use playbooks takes a long time during the whole integration part, as it retrieves all credentials from us, whether for an EC2 machine or any antivirus. It takes about one to two months for the team to fully sustain and know the processes of the playbooks and security, particularly for three or four individuals in the cyber security or DevOps team. Splunk SOAR significantly reduces the time spent on monotonous security tasks. In banking, insurance, or healthcare, automated services for addressing phishing emails and security threats are common. Having a manual workforce of two or three individuals can only handle five or ten security threats while Splunk SOAR automates the entire process across apps and machines, making it easier and notifying the admin about the threats. If someone tries to breach, Splunk SOAR immediately processes incoming requests, validating them and blocking any unsecured requests, which reduces a lot of time and effort. With the help of the playbook viewer, I assess the visibility provided by Splunk SOAR as very positive, especially for security purposes. If someone is attacked by 100 users, it blocks all the users, while individual developers such as myself can only handle two or three at a time. The automated process of Splunk SOAR handles all the processes concurrently, making it a game-changing solution. It helps reduce mean time to resolve (MTTR). It takes around 10 to 20 minutes to resolve one incident through the whole process and notify the admin of the issue. If there are multiple incidents, calculating the time taken for each, it generally requires around 40 to 50 minutes to resolve five incidents.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Almost four or five hours of work is now completed in four or five minutes."
"Torq's unified platform approach to AI, SOAR, automation, and case management is superior compared to my experience managing multiple point solutions."
"Any request that comes in, regardless of how complex it is, I can accomplish it with Torq."
"Under one SOC tool in Torq, analysts get to know everything within the context of an alert or incident they are working on, and this ability to view the whole picture within Torq is one of the major breakthroughs and best offerings of Torq."
"With Torq, I automate actions while achieving SLA compliance and streamline alert investigation processes much better."
"According to positive outcomes, Torq reduced manual work and made incident response more efficient."
"Since we started working with Torq, I am handling much fewer alerts, it is becoming really easy for me to handle an alert, I have all the information that I need, I do not need to connect to different vendors to receive this information, and the main thing I got from Torq is time, which now helps me to build another automated system and learn."
"Once I started to use the system and I saw the potential, it changed all of our work in IT."
"The vendors themselves will actually help with any customizations a client may require, and their vendors are very helpful; they will walk you through the whole Playbook until you have a good grasp of the product."
"Its ability to integrate with other systems and applications in our environment is pretty easy. Sometimes if we see any complexity we try to involve a consultant to help us. Everything is through the built-in app. Splunk can connect to any assets through the built-in app. It could be in a platform, firewalls, or endpoints. It's easy if it's an app integration."
"Splunk SOAR is more user-friendly than those tools and provides more precise and advanced information that we require to analyze whether a case is a true positive or false positive."
"Splunk has many features that make work easier, and it's simple to implement in a large production environment. Splunk collects a massive amount of data from cloud servers and handles it perfectly."
"Splunk SOAR has made a huge impact across security operations and the business overall."
"The main benefit of using Splunk SOAR is the automation, as a job that would have been very tedious for an analyst to do in terms of removing all the dashboards that haven't been used is now saving space and saving money."
"One particular example I can recall is that in enterprise, we get around 100 to 200 notables daily, which consumes approximately 16 to 40 hours per day for an analyst, but since we have Splunk SOAR, it is now just about five to seven minutes or five to 10 minutes per alert."
"The solution allows us to customize playbooks and incorporate custom code, allowing us to drag and drop elements while still writing code to build the integrations we need."
"When you design a playbook, you can integrate multiple log sources and define rules... After that, the platform automatically compiles all these activities and, based on the results, the analyst only has to indicate whether the result is a true or false positive. That reduces the time and effort involved."
 

Cons

"However, we did encounter some problems with custom steps, which definitely affected our progress, and the speed of bug fixes is also a bit slower than expected."
"If Torq could enhance its AI features, it would benefit customers significantly by making the platform even more user-friendly."
"We have MCP that we are working with our cloud security platform, and we wanted to connect this MCP to the case management."
"Regarding stability, I have noticed some lagging, crashing, and downtime, which is one of my largest gripes."
"It was able to capture data but was unable to differentiate between the agent hostname we are using and the hostname that resides on the back end of the Internet."
"There are some issues and bugs that I think need to be fixed, but they are currently not focused on it."
"Torq can probably use more ML and look at what can be closed and what cannot be closed in terms of data classification."
"Torq can be improved by adding some more features, such as adding more automation and providing a no-code option so I don't have to code for everything."
"The support is not 24/7."
"Because we are located in Singapore, there is a time-zone difference with customer support. The support is not 24/7 so we have to work with them on their schedule for deployment and customization, which is usually in the afternoon, Singapore time."
"Improving the integration ecosystem can raise the quality of the bottom tier of the integrations so that they can work better out of the box."
"A pain point is that you cannot debug from the console or widget within the playbook itself."
"The font used in the interface could be changed and made easier to read."
"The cost of Splunk SOAR has room for improvement."
"The solution is a bit more expensive than other offerings."
"The algorithm and machine learning have room for improvement and can be more user-friendly."
"It would be nice if we could put it on other search heads, not just Enterprise Security."
"When it comes to Splunk SOAR, in terms of improvement, I feel there should be some pre-deployed solutions available."
 

Pricing and Cost Advice

Information not available
Information not available
"Splunk is a fast enterprise tool, but it costs too much. At the same time, it's worth what we pay, in my opinion. We can efficiently perform all the functions and tie together the data. It's the perfect tool for our needs."
"The licensing cost is reasonable."
"The cost is high and the licensing is on an annual basis."
"The tool is not cheap."
"Splunk SOAR is more expensive compared to other options for SOAR."
"I found the price of Splunk SOAR to be good."
"While I can't confirm the exact pricing, some colleagues have mentioned that Splunk SOAR may be on the costlier side."
"Splunk SOAR is an expensive solution for an organization of our size."
report
Use our free recommendation engine to learn which Security Orchestration Automation and Response (SOAR) solutions are best for your needs.
916,197 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Financial Services Firm
12%
Comms Service Provider
11%
Manufacturing Company
10%
No data available
Financial Services Firm
12%
Manufacturing Company
10%
Outsourcing Company
9%
Construction Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise5
Large Enterprise13
No data available
By reviewers
Company SizeCount
Small Business23
Midsize Enterprise10
Large Enterprise53
 

Questions from the Community

What needs improvement with Torq?
There are some bugs in Torq, of course. They can be present in data transformation, some UI debugging, and other area...
What is your primary use case for Torq?
My main use case for Torq is the automation of cyber security processes through a SOAR platform and APIs. A main exam...
What advice do you have for others considering Torq?
Regarding someone thinking about using Torq, I recommend looking into their provided academy to start working with th...
Ask a question
Earn 20 points
What is your experience regarding pricing and costs for Splunk Phantom?
I was not involved with the pricing, setup cost, and licensing.
What needs improvement with Splunk Phantom?
To improve Splunk SOAR, I would suggest making it easier for integration with third-party applications without having...
What is your primary use case for Splunk Phantom?
My main use case for Splunk SOAR is integration with third-party apps. A quick specific example of how I use Splunk S...
 

Also Known As

No data available
DFLabs IncMan Incident Response
Phantom
 

Overview

 

Sample Customers

Information Not Available
University of Advancing Technology, Cybersecurity Ventures
Recorded Future, Blackstone
Find out what your peers are saying about Splunk, Palo Alto Networks, Microsoft and others in Security Orchestration Automation and Response (SOAR). Updated: October 2026.
916,197 professionals have used our research since 2012.