No more typing reviews! Try our Samantha, our new voice AI agent.

McAfee ePolicy Orchestrator vs Splunk SOAR comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 29, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Torq
Sponsored
Ranking in Security Orchestration Automation and Response (SOAR)
4th
Average Rating
8.6
Reviews Sentiment
6.5
Number of Reviews
18
Ranking in other categories
AI-SOC (1st), AI-Powered Security Automation (1st)
McAfee ePolicy Orchestrator
Ranking in Security Orchestration Automation and Response (SOAR)
16th
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
42
Ranking in other categories
No ranking in other categories
Splunk SOAR
Ranking in Security Orchestration Automation and Response (SOAR)
1st
Average Rating
8.2
Reviews Sentiment
6.4
Number of Reviews
76
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of September 2026, in the Security Orchestration Automation and Response (SOAR) category, the mindshare of Torq is 3.5%, down from 5.7% compared to the previous year. The mindshare of McAfee ePolicy Orchestrator is 1.8%, up from 0.7% compared to the previous year. The mindshare of Splunk SOAR is 7.0%, down from 7.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Orchestration Automation and Response (SOAR) Mindshare Distribution
ProductMindshare (%)
Splunk SOAR7.0%
Torq3.5%
McAfee ePolicy Orchestrator1.8%
Other87.7%
Security Orchestration Automation and Response (SOAR)
 

Featured Reviews

AD
Solutions Architect at ProArch
Automation has streamlined multi-tenant SOC workflows and improves alert handling efficiency
Although the reporting within Torq is not that great, we did ask for many features regarding reporting in Torq, but due to some platform constraints, they could not make the whole dataset available for us to be used in reporting. Except for that, we used some basic reporting. When I used Torq, it was indeed in the early stages of AI capabilities. Only a few customers were allowed to use it, and we were among them. It functioned well as long as we summarized the data properly. If you input garbage, you would get garbage out. Thus, we had to do significant fine-tuning regarding what data context we provided to the AI orchestrator to get meaningful results. In terms of Torq's unified platform approach to AI SOC automation and case management compared to managing multiple point solutions across my security stack, I find it case-centric. The unified view in case management is good since it provides clarity, although there are limitations regarding how many items in case management can be modified at once. Bulk operations are very limited, potentially due to their back-end database or data retrieval processes that can be improved. Regarding improvements for Torq, when we were onboarded, there were aspects we were uncertain about, such as the number of cases that could be generated, what data we could bring in, how many clients we could onboard, and similar concerns. Initially, we also lacked clarity about the number of playbooks or workflows we could build. Different triggers like system triggers, case-based triggers, and others can be employed without restrictions, but when it comes to on-demand and scheduled jobs, there is a limitation based on the subscription and pricing tier that notably caps the number of workflows we can create. No bulk editing across cases was one issue, along with limited filtering related to single grouping constraints. Additionally, the out-of-the-box case templates provided require substantial modifications before they become usable. There is also a feature in the cases for notes that cannot be searched. They are only visible through the UI, which is another area for improvement. The workflow and execution-based charges seem misleading as this was not discussed initially. I am not sure if new customers are made aware of this. It seems that workflows revolving around cases hinder functionality outside of case management, as we have many use cases needing on-demand triggers and schedules for functions like reporting or polling devices. Creating additional workflows to achieve basic functionalities raises costs significantly, which disadvantages customers. While they facilitate optimization and scaling, the support received tends to be very basic. Improvements can be made in that area as well.
Binu Haneef - PeerSpot reviewer
System Administrator at Sky News Arabia
Comprehensive security management enabled through efficient integration and automation
McAfee ePolicy Orchestrator helps automate routine security tasks. We created customized automation. For example, when we did not have an EDR or XDR solution, we created tasks exclusively for detection and response automation and automatic segregation of infected PCs. The ability to customize the dashboard in McAfee ePolicy Orchestrator helps us significantly. The main feature is automation for auto-segmentation and segregation. As we are in an AI era, McAfee can focus on AI tools. Instead of putting manual effort into each security-related task, it can implement more advanced automation using AI. This enhancement could improve cybersecurity significantly. Regarding the reporting area in McAfee ePolicy Orchestrator, we are satisfied with what we currently have. Our cybersecurity team needs customized reports beyond the default ones. We have more than 20 separate reports for identifying threats, managing, and understanding the security posture of our company and assets.
Vikash Kushwaha - PeerSpot reviewer
Full-Stack Software Engineer at mindpathtech
Automated playbooks have transformed incident response and now protect critical services
The biggest advantage I see from my personal experience as an integrator with Splunk SOAR is that it integrates with most of the security features among the Defenders, Microsoft Defender, firewalls, CloudWatch, and AWS security agents, as well as EC2 machines, firewalls, EDR, IAM, email security, and antivirus. It automates the security process over phishing emails and any other brute force attacks. It helps quite a lot because if 100 phishing emails were sent to a domain, a developer can only reach one, two, or five, but for hundreds of others, it actually supports better automated playbooks and provides major security. Splunk SOAR introduced some new and innovative capabilities or approaches that transformed the way my SOC operates. Splunk SOAR provides playbooks for automatic security features, such as for firewalls, phishing mails, and utilizing Defenders or virtual tools. A playbook maintains its algorithms or processes, so if any kind of security issue arises, the playbook automatically runs and handles actions such as IP blocking or resolving brute force attacks, notifying the admin about suspicious users. After implementing Splunk SOAR, the training process for my SOC team to use playbooks takes a long time during the whole integration part, as it retrieves all credentials from us, whether for an EC2 machine or any antivirus. It takes about one to two months for the team to fully sustain and know the processes of the playbooks and security, particularly for three or four individuals in the cyber security or DevOps team. Splunk SOAR significantly reduces the time spent on monotonous security tasks. In banking, insurance, or healthcare, automated services for addressing phishing emails and security threats are common. Having a manual workforce of two or three individuals can only handle five or ten security threats while Splunk SOAR automates the entire process across apps and machines, making it easier and notifying the admin about the threats. If someone tries to breach, Splunk SOAR immediately processes incoming requests, validating them and blocking any unsecured requests, which reduces a lot of time and effort. With the help of the playbook viewer, I assess the visibility provided by Splunk SOAR as very positive, especially for security purposes. If someone is attacked by 100 users, it blocks all the users, while individual developers such as myself can only handle two or three at a time. The automated process of Splunk SOAR handles all the processes concurrently, making it a game-changing solution. It helps reduce mean time to resolve (MTTR). It takes around 10 to 20 minutes to resolve one incident through the whole process and notify the admin of the issue. If there are multiple incidents, calculating the time taken for each, it generally requires around 40 to 50 minutes to resolve five incidents.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"What I appreciate most about Torq is that it is an essential part of our system."
"As an analyst, it has demonstrated potential to reduce workforce requirements and time needed for related activities."
"Torq has helped a lot regarding SOC analyst efficiency."
"Any request that comes in, regardless of how complex it is, I can accomplish it with Torq."
"According to positive outcomes, Torq reduced manual work and made incident response more efficient."
"We have seen fewer failures of automations from the time Torq came into the picture, we've had a more streamlined process of handling incidents, and at the same time, we've learned to embed the AI into our incident types, and that is how it has helped us in the automation."
"Under one SOC tool in Torq, analysts get to know everything within the context of an alert or incident they are working on, and this ability to view the whole picture within Torq is one of the major breakthroughs and best offerings of Torq."
"Torq has exceeded expectations by delivering workflows in a timely and lower effort manner than XSOAR, and it meets all my needs while saving a ton of time and targeting $600,000 saved this year, which is a substantial amount of money."
"I like the solution's feasibility. McAfee ePolicy Orchestrator is also better and easier to use than other ePOs."
"McAfee ePolicy Orchestrator's performance is good."
"The most valuable feature of the solution is the central management console, which is used for DLP, endpoint security, drive encryption, and application control."
"Many organizations will find the solution has many features that would suit their needs and reduce the number of issues they face."
"The most valuable feature of the McAfee ePolicy Orchestrator is agent communication."
"The general endpoint protection is valuable, and it is easy to manage."
"Application control and traffic encryption are the most valuable features."
"The solution's best part is that it is very easy to manage McAfee Agent."
"The most valuable feature is the API connector, depending on how it's formatted and who made the actual app offering for it. The REST API is my favorite component. It's very easy to use. The filters are also really valuable. Those are the two primary features but I enjoy using the rest of it."
"Splunk integrates with so many products. It provides us with good information for us to be able to do our jobs."
"The customization continues to be excellent."
"Integration has made our operations significantly easier, and for phishing investigations, IP checks, and endpoint isolations, our response time to incidents has reduced substantially, and false positives are identified much quicker because of Splunk SOAR."
"The tool's most valuable feature is its searchability and ease of action on the logs. I can easily search within the logs and take action on them, and I can trace them back to my environment because the way the logs are written is very helpful for us."
"Splunk SOAR saves time in threat response, and the time to solve an incident is currently the best in the market."
"The most valuable feature of the solution is the playbook automation just because it allows us to reduce the manual actions that SOC has to handle."
"The ability to automate Splunk SOAR and customize the playbook use cases is the most valuable feature and is very exciting for me."
 

Cons

"Regarding stability, I have noticed some lagging, crashing, and downtime, which is one of my largest gripes."
"Torq can be improved by adding some more features, such as adding more automation and providing a no-code option so I don't have to code for everything."
"Even now, we have workflows that are in production that use AI steps and I get different results, making it unusable to some degree."
"The workflow and execution-based charges seem misleading as this was not discussed initially, and creating additional workflows to achieve basic functionalities raises costs significantly, which disadvantages customers."
"Torq can probably use more ML and look at what can be closed and what cannot be closed in terms of data classification."
"Torq does extensive marketing saying that SOAR is dead and markets itself as an all-in-one solution, but this is not actually true."
"If Torq could enhance its AI features, it would benefit customers significantly by making the platform even more user-friendly."
"I wish Torq's AI assistant for building templated workflows from scratch worked better; when you start with a blank slate, asking AI to help you build or template the workflow out does not go well."
"It would be highly beneficial if the metrics or dashboards could be customized"
"McAfee ePolicy Orchestrator support has been helpful. However, sometimes when I raise the case they take a while to answer. For example, the last time I used them it took them two weeks to reply back by email. No one has contacted me back since. They should improve their service."
"The areas of concern where improvements are needed are related to the product's assignment policy and tag assignment, where users can assign the policies with the help of tags and sort out the systems."
"The Virtual Patching feature needs to be improved."
"As for improvements, I think that putting everything on a cloud and one console would be a great idea and would be useful for customers."
"The fact that it uses MSSQL, and cannot be deployed on anything other than Windows, can be a problem."
"I am not familiar with the newer versions, but the biggest issues we had with our version were false positives and performance degradation."
"McAfee ePolicy Orchestrator should improve its integration with other tools."
"The algorithm and machine learning have room for improvement and can be more user-friendly."
"Various aspects of the playbook development process itself can be optimized."
"have put a number of ideas on the ideas.splunk.com site for feature requests for the Splunk SOAR product. I posted one of them about three years ago, which finally got implemented in the latest release that just got announced, so the time to implement new features and things like that is a little bit concerning."
"Overall, this product is fairly good but it's not quite mature yet. It needs some enhancement and some stabilization in some areas."
"While there have been improvements to the investigation process, particularly with the playbook data, the current log review method is cumbersome."
"One thing that we would like to see with Splunk SOAR is the expandability to the threat intelligence feed."
"The solution is a bit more expensive than other offerings."
"There is a lot of room for improvement with the UI."
 

Pricing and Cost Advice

Information not available
"It is attractively priced. It is a fraction of what we're going to pay for CrowdStrike or SentinelOne, but it only has a fraction of the capabilities as well."
"McAfee tries to package different things into different products, then sell them as different products with different licenses. They just split everything up into multiple things. That's just their sales pitch and how they do it."
"McAfee ePolicy Orchestrator is a cheaply priced product, meaning it is not expensive since McAfee provides a free version of ePO, which includes phone support as well."
"There is a license required to use this solution. If we use the additional components, such as DLP encryption, there is an additional cost. However, it is similar to a separate product altogether. If you want to use that or not, it is optional, but when you use it, it will cost you additional pricing."
"It's an expensive solution"
"For large enterprise companies, the price should be alright, but for small businesses, the uptake might be slow because, for these clients, the price doesn't look very attractive."
"$The price of McAfee ePolicy Orchestrator is expensive, it is approximately $6,000 to $9,000 per license annually."
"On a scale from one to ten, where one is cheap, and ten is expensive, I rate the solution's pricing a three out of ten."
"I found the price of Splunk SOAR to be good."
"I don't know the exact price, but for my region, it is very expensive."
"The tool is not cheap."
"While I can't confirm the exact pricing, some colleagues have mentioned that Splunk SOAR may be on the costlier side."
"Splunk SOAR is moderately priced, neither cheap nor overly expensive."
"The licensing cost is reasonable."
"The cost is high and the licensing is on an annual basis."
"When we first purchased our Splunk SOAR license, it was based on an event-count model. It was based on the number of events. I had strong opinions at the time that automation should not be stifled by the amount of automation you can accomplish, so the previous structure was not as beneficial for us. Later that year, we got told or saw at a conference that they announced user-based pricing. We are now in a renewal period, so we migrated to a user-based license model, which is more appropriate for us so that we no longer have to worry about stifling our automation based on the quantity."
report
Use our free recommendation engine to learn which Security Orchestration Automation and Response (SOAR) solutions are best for your needs.
914,262 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Financial Services Firm
12%
Comms Service Provider
10%
Manufacturing Company
8%
Outsourcing Company
16%
Construction Company
11%
Manufacturing Company
9%
Financial Services Firm
9%
Financial Services Firm
11%
Manufacturing Company
10%
Outsourcing Company
9%
Construction Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise5
Large Enterprise11
By reviewers
Company SizeCount
Small Business13
Midsize Enterprise11
Large Enterprise19
By reviewers
Company SizeCount
Small Business23
Midsize Enterprise10
Large Enterprise53
 

Questions from the Community

What needs improvement with Torq?
There are some bugs in Torq, of course. They can be present in data transformation, some UI debugging, and other area...
What is your primary use case for Torq?
My main use case for Torq is the automation of cyber security processes through a SOAR platform and APIs. A main exam...
What advice do you have for others considering Torq?
Regarding someone thinking about using Torq, I recommend looking into their provided academy to start working with th...
Which is better - Mcafee's MVision ePO or ePolicy Orchestrator?
Our organization ran comparison tests to determine whether Mcafee's MVision ePO or ePolicy Orchestrator network secur...
What needs improvement with McAfee MVISION ePO?
There is a question regarding suggestions for additional tools or functions for McAfee ePolicy Orchestrator, and whet...
What is your primary use case for McAfee MVISION ePO?
The question pertains to describing the use case and process for which people utilize McAfee ePolicy Orchestrator.
What is your experience regarding pricing and costs for Splunk Phantom?
For pricing, I would rate Splunk SOAR a seven where one is high price and ten is low price.
What needs improvement with Splunk Phantom?
Splunk SOAR could be improved by making playbook development easier for new users and providing better troubleshootin...
What is your primary use case for Splunk Phantom?
My main use case for Splunk SOAR is automating repetitive SOC tasks and speeding up incident response, and I mainly u...
 

Also Known As

No data available
McAfee ePO, ePolicy Orchestrator, Intel Security ePolicy Orchestrator, McAfee MVISION ePO
Phantom
 

Overview

 

Sample Customers

Information Not Available
Brelje & Race, Cognizant, Sutherland Global Services, Eagle Rock Energy, Arab National Bank, Bank Central Asia, Kleberg Bank, Leading Mexican Bank, SF Police Credit Union, Macquarie Telecom, Seagate Technology, Blackburn & Darwen Council, California Department of Corrections & Rehabilitation, IRCEP, Major U.S. State Government, State of Alaska, State of Colorado, Cemex, Deutsche Edelstahlwerke
Recorded Future, Blackstone
Find out what your peers are saying about McAfee ePolicy Orchestrator vs. Splunk SOAR and other solutions. Updated: September 2026.
914,262 professionals have used our research since 2012.