

Elastic Security and Splunk SOAR compete in the cybersecurity sector. Elastic Security holds an advantage in cost-effectiveness due to its open-source model, while Splunk SOAR excels in advanced automation and integration functionalities.
Features: Elastic Security offers superior data indexing and visualization through Kibana, comprehensive documentation, and highly effective threat correlation capabilities, leveraging its machine learning features for impressive data analysis. Splunk SOAR is notable for extensive automation, versatile orchestration, and the ability to customize playbooks, facilitating robust integration with numerous third-party solutions.
Room for Improvement: Elastic Security can improve automated log management and user interface design, and users express the desire for more pre-built use cases and advanced analytics. Splunk SOAR could benefit from more affordable pricing, improved workflow customization options, and more extensive customer support and training resources.
Ease of Deployment and Customer Service: Elastic Security supports deployment across on-premises, private, and public cloud environments, with strong community and technical support. Splunk SOAR offers flexible deployment options but lacks the same level of community support as Elastic, with its customer service noted for needing enhanced responsiveness.
Pricing and ROI: Elastic Security's open-source model allows for an affordable entry, providing value with quick return on investment despite premium support limitations. Splunk SOAR, while more costly, delivers value through comprehensive automation and requires full capability utilization to achieve ROI, yet is challenging for smaller enterprises on price considerations.
It does not require hefty security budgets and can be deployed for enterprise security effectively.
We've seen a decrease in false positives and a significant increase in our containment.
Support is prompt and helpful.
Most of the time when my team encounters issues, they receive responses within 24 hours.
I have not faced any difficulties with Elastic Security, as we have a pretty good support service from them.
Discovering different troubleshooting methods is harder to do with Splunk SOAR than with Enterprise Security or other Splunk services.
Splunk's technical support is very good and generally not needed often due to the stable environment.
My experience with the technical support by Splunk has been quite positive
It allows us to think about specific use cases, such as gathering malicious IPs in a single view and analyzing threats based on geolocation.
Elastic Security is quite scalable.
It can be extended and adapted as necessary.
Splunk SOAR has the ability to scale quite significantly.
In terms of stability, I would rate Elastic a solid eight out of ten.
We have not experienced any downtime, crashes, or performance issues.
Splunk SOAR provides a stable environment and technology.
It's been pretty reliable.
CrowdStrike and Defender have more established threat intelligence integration due to having a larger client base.
My security testing team continuously reports vulnerabilities, and we have to fix and update the versions frequently.
Machine learning algorithms become better with time; as they ingest a huge volume of data, they become better.
Although it enhances alert handling, it still has a journey to compete with Palo Alto SOAR and FortiSOAR.
Splunk's Unified Platform does help consolidate networking security and IT observability tools.
I would rate Splunk SOAR support an eight out of ten because escalating a ticket to a higher level can take more time, indicating a need for a larger support team.
The pricing is reasonable, especially for Small Medium Enterprises (SMEs), making it a viable option for businesses building their security infrastructure.
This is beneficial for SMEs as they do not need extensive budgets for security solutions.
Elastic Security is considered cost-effective, especially at lower EPS levels.
Splunk SOAR is moderately priced, neither cheap nor overly expensive.
Splunk SOAR is affordable cost-wise only.
The solution is free for us, which is a beneficial aspect.
Elastic Security offers good insight regarding alerts, reports, and cases.
Elastic Security offers advanced features such as machine learning and integration with ChatGPT.
We require rapid processing speed for alerts and event data, and Elastic Security is very efficient at handling this level of data.
Creating playbooks using the Playbook Editor in Splunk SOAR is easy. The editor is designed to be user-friendly with visual drag and drop features, allowing for easy workflows without writing any code.
Splunk SOAR saves time in threat response, and the time to solve an incident is currently the best in the market.
The customization of the playbook in Splunk SOAR is very beneficial.


| Product | Market Share (%) | 
|---|---|
| Splunk SOAR | 7.7% | 
| Elastic Security | 4.8% | 
| Other | 87.5% | 


| Company Size | Count | 
|---|---|
| Small Business | 40 | 
| Midsize Enterprise | 11 | 
| Large Enterprise | 15 | 
| Company Size | Count | 
|---|---|
| Small Business | 12 | 
| Midsize Enterprise | 7 | 
| Large Enterprise | 30 | 










Elastic Security combines the features of a security information and event management (SIEM) system with endpoint protection, allowing organizations to detect, investigate, and respond to threats in real time. This unified approach helps reduce complexity and improve the efficiency of security operations.
Additional offerings and benefits:
Finally, Elastic Security benefits from a global community of users who contribute to its threat intelligence, helping to enhance its detection capabilities. This collaborative approach ensures that the solution remains on the cutting edge of cybersecurity, with up-to-date information on the latest threats and vulnerabilities.
Splunk SOAR offers features like automation and orchestration of manual tasks, speeding up work, detection and response to advanced and emerging threats.
Automate manual tasks. Address every alert, every day. Establish repeatable procedures that allow security analysts to stop being reactive and focus on mission-critical objectives to protect your business.
Orchestrate and automate repetitive tasks, investigation and response to increase efficiency and productivity, and do more with the people you already have. Make a team of three feel like a team of 10.
Work faster with Splunk SOAR. Respond to threats in seconds. Lower your mean time to respond (MTTR) by automating security tasks and workflows across all of your security tools.
Take advantage of Splunk Enterprise Security and Splunk SOAR joining forces to provide a seamless and intuitive SecOps platform to prevent, detect and respond to advanced and emerging threats.
We monitor all Security Orchestration Automation and Response (SOAR) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.