No more typing reviews! Try our Samantha, our new voice AI agent.

IBM Resilient vs SECDO Platform vs Splunk SOAR comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

Security Incident Response Mindshare Distribution
ProductMindshare (%)
IBM Resilient7.3%
Proofpoint Threat Response8.7%
ServiceNow Security Operations8.0%
Other76.0%
Security Incident Response
Security Incident Response Mindshare Distribution
ProductMindshare (%)
SECDO Platform5.2%
Proofpoint Threat Response8.7%
ServiceNow Security Operations8.0%
Other78.1%
Security Incident Response
Security Orchestration Automation and Response (SOAR) Mindshare Distribution
ProductMindshare (%)
Splunk SOAR8.0%
Microsoft Sentinel12.2%
Palo Alto Networks Cortex XSOAR8.8%
Other71.0%
Security Orchestration Automation and Response (SOAR)
 

Featured Reviews

ZaidHaddad - PeerSpot reviewer
Technical Seller at Alawtad group
Suitable for different industries and ensures effective incident response
IBM Resilient is great in many aspects like its wide range of integrations and customizable playbooks. However, one thing to improve is how it handles data formats, which currently might require scripting for conversion to CSV before uploading. Despite this, it stands out for incident response, case management, task organization, and team collaboration, making it a strong choice for organizations compared to competitors like Demisto Palo Alto. When it comes to additional features, I think IBM Resilient is on the right track with its AI capabilities, like linking related incidents and providing recommended actions. It would be nice to see more enhancements in this area, but overall, it looks good.
it_user1643085 - PeerSpot reviewer
Founder/ CEO
Great documentation, good technical support, and very in-depth
The initial setup can be complex. I would advise users to leverage all of the access with Palo Alto, in terms of setting up with the technical account management teams. They need to ensure that what they have in mind for the product is actually going to be what happens. I have not run into any problems with deploying the product. Any of their security products are well-documented, either with open source intelligence or the documentation from Palo Alto. We had a client with less than a thousand users that received a dedicated engineer and a technical account manager that was able to walk them through the first 90 days of ownership. The support is certainly there.
SS
Manager cybersecurity at Hexion Inc.
Automates threat response and reduces investigation time but needs better threat intelligence integration
One thing that we would like to see with Splunk SOAR is the expandability to the threat intelligence feed. Currently, we have limited ingestion to the threat intelligence feed for the correlation purpose. We would like to see it being integrated, with license cost or without license cost, to leading threat intelligence sources such as Recorded Future, Feedly, or Flare. That is something we would appreciate having integrated. The second thing on the improvement side is about exposed credential-related information. If we start ingesting those data to Splunk SOAR or SIEM with some sort of integration with threat intelligence feed, that will also improve our detection and prediction method or help us with the investigation.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Stability-wise, I rate the solution a ten out of ten...Scalability-wise, I rate the solution a ten out of ten."
"The initial setup of IBM Resilient is not that complex since my company already has a support license that we use internally. In general, the product's deployment phase is not that complex."
"It is a stable solution...It is a scalable solution."
"The solution is simple to use and to integrate with IBM QRadar."
"What I like most about IBM Resilient is that it has a complete stack, which means you don't need to use different OEM products because you have all you need under the IBM Resilient umbrella. You don't need to worry much about integrations and components because you're working with tested and proven architecture."
"The solution is reliable in our usage."
"The product is very good at incident response."
"This is a good solution that we recommend for customers."
"This is a mature product in terms of threat detection."
"The ease of deployment is a valuable feature."
"Palo Alto is extremely helpful and responsive and there is a lot of training documentation provided, making it a good, in-depth solution for enterprise clients that typically works a lot better than SIEM tools out of the box."
"Technical support is great. Palo Alto is extremely helpful and responsive."
"It basically automates the entire alert investigation process."
"It basically automates the entire alert investigation process."
"The best feature in Splunk SOAR is the visual Playbook Editor. The drag-and-drop interfaces make visualizations and understanding workflows easy."
"Splunk SOAR is really saving my time."
"I'm just a beginner on the solution and it's pretty easy for me to use."
"The most valuable feature of Splunk SOAR that stands out is it has a great SOAR, the automation and orchestration module is highly mature, and a lot of use cases are on user entity and behavioral analytics (UEBA), which is artificial intelligence and machine learning-based (AIML)."
"Splunk SOAR allows us to connect to multiple platforms, whether they are networks, security, or observability."
"If a company wants to automate redundant work, this solution is perfect for that."
"The most valuable features of Splunk SOAR are the easy integration with other solutions, including other Splunk solutions, and the most important playbooks we need on the market come already on the Splunk Store, which is a very strong point."
"The solution allows us to customize playbooks and incorporate custom code, allowing us to drag and drop elements while still writing code to build the integrations we need."
 

Cons

"The integration could be improved so that it is easy to integrate with other solutions."
"The product needs a bit more development."
"The integration could be improved so that it is easy to integrate with other solutions."
"One thing to improve is how it handles data formats, which currently might require scripting for conversion to CSV before uploading."
"Its price and technical support need improvement."
"This product could be improved with better customization. However, some competitors' solutions contain more integration, support, automation, or flexibility."
"The product must provide more integration with other tools."
"The initial setup is not straightforward or simple. It's quite complex."
"Many will try to use this as an out-of-the-box solution, however, it needs to be configured to fit what a company would like to do with it."
"Maybe the notifications setting could use a simpler setting."
"The price of this solution is higher than the competitors."
"Many will try to use this as an out-of-the-box solution, however, it needs to be configured to fit what a company would like to do with it."
"The price should be reduced in order to be more competitive in the market."
"Maybe the notifications setting could use a simpler setting."
"Splunk SOAR does not help me reduce my security event volume; in fact, it makes them massive."
"The creation of playbooks is complex in Splunk SOAR, and the number of integrations needs enhancement. Although it enhances alert handling, it still has a journey to compete with Palo Alto SOAR and FortiSOAR."
"It would be nice if we could put it on other search heads, not just Enterprise Security."
"To make Splunk SOAR a better solution, there could be better built-in debugging tools, smarter playbook suggestions, and enhanced lifecycle management."
"There is some homework to be done before you can really properly use Splunk SOAR. Resolution times could be faster in terms of support."
"The number of playbooks on offer should be increased."
"There is a lot of room for improvement with the UI."
"We want to see improvements made to the APIs such that we can connect to many different systems and data sources."
 

Pricing and Cost Advice

"I would rate the tool’s pricing a three out of ten. The tool’s pricing is on a yearly basis."
"The cost of the product is quite high."
"We could create unlimited users using the license we had purchased."
"The licensing cost for IBM Resilient is not too expensive, but it's not affordable, so it's moderately expensive. Regarding price, I'm rating the solution seven out of ten. The company pays for the license yearly, based on the number of users. Apart from the cost of the license you need to pay for each user, you also need to spend an initial investment for the base platform. You also have to pay for IBM Resilient support."
"There is a license you need to pay for in order to use this product."
"There are no costs except for the support services that our company pays in addition to the licensing charges attached to the solution."
"Pricing for the solution is good, in my opinion."
"I feel it is an expensive product when my company pays annually for renewal, support, and follow-up."
"The price of this solution is the highest in the market, although there are no costs in addition to the standard licensing fees."
"Be sure of the actual number of endpoints in your company."
"In my opinion, the price is high, but if you want good products, you have to be willing to pay for them."
"When we first purchased our Splunk SOAR license, it was based on an event-count model. It was based on the number of events. I had strong opinions at the time that automation should not be stifled by the amount of automation you can accomplish, so the previous structure was not as beneficial for us. Later that year, we got told or saw at a conference that they announced user-based pricing. We are now in a renewal period, so we migrated to a user-based license model, which is more appropriate for us so that we no longer have to worry about stifling our automation based on the quantity."
"I don't know the exact price, but for my region, it is very expensive."
"Splunk is a fast enterprise tool, but it costs too much. At the same time, it's worth what we pay, in my opinion. We can efficiently perform all the functions and tie together the data. It's the perfect tool for our needs."
"While I can't confirm the exact pricing, some colleagues have mentioned that Splunk SOAR may be on the costlier side."
"Splunk SOAR is more expensive compared to other options for SOAR."
"I found the price of Splunk SOAR to be good."
"The cost is high and the licensing is on an annual basis."
report
Use our free recommendation engine to learn which Security Incident Response solutions are best for your needs.
885,444 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
30%
Government
8%
Construction Company
8%
Computer Software Company
7%
Performing Arts
22%
Manufacturing Company
8%
Construction Company
6%
Comms Service Provider
6%
Financial Services Firm
11%
Manufacturing Company
10%
Computer Software Company
8%
University
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise2
Large Enterprise7
No data available
By reviewers
Company SizeCount
Small Business16
Midsize Enterprise8
Large Enterprise36
 

Questions from the Community

What is your experience regarding pricing and costs for IBM Resilient?
I am not the one in charge of pricing, so I am not sure about the costs.
What needs improvement with IBM Resilient?
Integration with some devices, including Cisco PowerPower and certain antivirus products, has limitations.
Ask a question
Earn 20 points
What is your experience regarding pricing and costs for Splunk Phantom?
I am familiar with the pricing aspect, setup cost, and licensing cost of Splunk SOAR, and it is pretty much similar t...
What needs improvement with Splunk Phantom?
Sometimes it lags when I am working on multiple things. Apart from that, every feature is useful. Integration is an a...
What is your primary use case for Splunk Phantom?
We have been using Splunk SOAR for analyzing threats and mitigating issues in cybersecurity. We provide input and SQL...
 

Also Known As

No data available
No data available
Phantom
 

Overview

 

Sample Customers

Golden Living, Health Equity, USA Funds
Valley National Bank, IDT Corporation
Recorded Future, Blackstone
Find out what your peers are saying about ServiceNow, Proofpoint, Trellix and others in Security Incident Response. Updated: March 2026.
885,444 professionals have used our research since 2012.