Try our new research platform with insights from 80,000+ expert users

IBM Cloud Pak for Security vs Splunk SOAR comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

IBM Cloud Pak for Security
Average Rating
0.0
Number of Reviews
1
Ranking in other categories
Cloud and Data Center Security (27th)
Splunk SOAR
Average Rating
8.2
Reviews Sentiment
6.7
Number of Reviews
48
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (3rd)
 

Mindshare comparison

IBM Cloud Pak for Security and Splunk SOAR aren’t in the same category and serve different purposes. IBM Cloud Pak for Security is designed for Cloud and Data Center Security and holds a mindshare of 0.1%, down 0.2% compared to last year.
Splunk SOAR, on the other hand, focuses on Security Orchestration Automation and Response (SOAR), holds 7.7% mindshare, down 8.0% since last year.
Cloud and Data Center Security Market Share Distribution
ProductMarket Share (%)
IBM Cloud Pak for Security0.1%
Illumio22.8%
Akamai Guardicore Segmentation21.5%
Other55.599999999999994%
Cloud and Data Center Security
Security Orchestration Automation and Response (SOAR) Market Share Distribution
ProductMarket Share (%)
Splunk SOAR7.7%
Microsoft Sentinel15.9%
Palo Alto Networks Cortex XSOAR9.6%
Other66.8%
Security Orchestration Automation and Response (SOAR)
 

Featured Reviews

reviewer1907040 - PeerSpot reviewer
Great user-friendly interface; provides many functionalities and many free applications
The interface is good and very user-friendly, it's easy for our customers to use. Cloud Pak provides a lot of functionalities and many free applications available from the online shop which can be deployed to your system. It allows for an increase in functionalities even if you've bought the smallest installation.
Mack Scott - PeerSpot reviewer
Improves response time by consolidating tools and automating threat detection
I haven't gone too far into it to see anything that needs improvement yet. We can likely include some features related to the integration with on-premises resources, rather than focusing solely on the existing automation. These are the additional features that could be included in the future. Splunk's Unified Platform does help consolidate networking security and IT observability tools. They should integrate Splunk Enterprise Security better into Splunk Cloud.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The interface is good and very user-friendly."
"Splunk SOAR's extensive library of pre-built integrations allows it to connect with a vast array of popular security and IT applications, streamlining workflows across our existing security stack."
"The features of Splunk SOAR that I appreciate most are the integrations with all the other applications and tools."
"When you design a playbook, you can integrate multiple log sources and define rules... After that, the platform automatically compiles all these activities and, based on the results, the analyst only has to indicate whether the result is a true or false positive. That reduces the time and effort involved."
"We are not a 24/7 SOC, so the most valuable feature of Splunk SOAR is the auto-response to threats when we are not in the office and the notifications that it sends to the on-call engineer."
"It's pretty easy when it comes to setting up assets. If you want to fetch emails or call a REST API, you can set up an asset and grab that information."
"The product’s integration with other Splunk products is valuable."
"Before its use, analyzing each email would take at least 15 to 20 minutes, with some complex cases taking up to 30 minutes...With the automation provided by Splunk Phantom, we could significantly reduce the amount of time and human effort required to complete this task."
"The automation part of the product is great."
 

Cons

"Lacks sufficient technical support."
"The pricing could be a bit more reasonable. It would be great if it were feasible for smaller organizations."
"The dashboard could be improved and some other features. SOAR should integrate network capabilities, allowing us to also monitor the WLAN network. Splunk is also expensive and difficult for beginners to learn. It's hard for a new user to figure out how to visualize old threat data. It took two to three months to learn with hands-on experience how to use the dashboard, visualize events, and analyze threats."
"The font used in the interface could be changed and made easier to read."
"While support is available, the resources around Splunk SOAR are more homegrown by other users, and discovering different troubleshooting methods is harder to do with Splunk SOAR than with Enterprise Security or other Splunk services."
"Various aspects of the playbook development process itself can be optimized."
"The solution must provide more AIOps to improve predictability."
"We've had trouble implementing the solution with Microsoft products. There seems to be an integration gap."
"The number of playbooks on offer should be increased."
 

Pricing and Cost Advice

Information not available
"The cost is high and the licensing is on an annual basis."
"I found the price of Splunk SOAR to be good."
"Splunk SOAR is moderately priced, neither cheap nor overly expensive."
"Splunk is a fast enterprise tool, but it costs too much. At the same time, it's worth what we pay, in my opinion. We can efficiently perform all the functions and tie together the data. It's the perfect tool for our needs."
"The licensing cost is reasonable."
"Splunk SOAR is an expensive solution for an organization of our size."
"We renewed it this year. This year was the first time there was a dramatic increase in the price. It was kind of non-negotiable. It was just a high increase. We had internal communications, and it was definitely a surprise to us. In a short time frame, we renewed it this year. Prices are going up everywhere, but they are not always justifiable, at least not to our eyes. The pricing this year was definitely a big shock."
"In my opinion, the price is high, but if you want good products, you have to be willing to pay for them."
report
Use our free recommendation engine to learn which Cloud and Data Center Security solutions are best for your needs.
871,469 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
No data available
Financial Services Firm
12%
Computer Software Company
11%
Manufacturing Company
9%
University
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business11
Midsize Enterprise7
Large Enterprise29
 

Questions from the Community

Ask a question
Earn 20 points
What do you like most about Splunk Phantom?
Splunk SOAR's quick response to incidents is the most valuable part.
What is your experience regarding pricing and costs for Splunk Phantom?
I don't have experience with costs; management handles that aspect.
What needs improvement with Splunk Phantom?
I haven't gone too far into it to see anything that needs improvement yet. We can likely include some features related to the integration with on-premises resources, rather than focusing solely on ...
 

Also Known As

No data available
Phantom
 

Overview

 

Sample Customers

Information Not Available
Recorded Future, Blackstone
Find out what your peers are saying about Akamai, SentinelOne, Broadcom and others in Cloud and Data Center Security. Updated: October 2025.
871,469 professionals have used our research since 2012.