No more typing reviews! Try our Samantha, our new voice AI agent.

ServiceNow Security Operations vs Splunk SOAR comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 29, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Torq
Sponsored
Ranking in Security Orchestration Automation and Response (SOAR)
4th
Average Rating
8.6
Reviews Sentiment
6.7
Number of Reviews
12
Ranking in other categories
AI-SOC (1st), AI-Powered Security Automation (1st)
ServiceNow Security Operations
Ranking in Security Orchestration Automation and Response (SOAR)
9th
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
24
Ranking in other categories
Security Incident Response (1st), Risk-Based Vulnerability Management (12th)
Splunk SOAR
Ranking in Security Orchestration Automation and Response (SOAR)
1st
Average Rating
8.2
Reviews Sentiment
6.5
Number of Reviews
62
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of June 2026, in the Security Orchestration Automation and Response (SOAR) category, the mindshare of Torq is 3.8%, down from 5.5% compared to the previous year. The mindshare of ServiceNow Security Operations is 3.5%, down from 3.7% compared to the previous year. The mindshare of Splunk SOAR is 7.1%, down from 7.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Orchestration Automation and Response (SOAR) Mindshare Distribution
ProductMindshare (%)
Splunk SOAR7.1%
Torq3.8%
ServiceNow Security Operations3.5%
Other85.6%
Security Orchestration Automation and Response (SOAR)
 

Featured Reviews

AD
Solutions Architect at Swimlane
Automation has streamlined multi-tenant SOC workflows and improves alert handling efficiency
Although the reporting within Torq is not that great, we did ask for many features regarding reporting in Torq, but due to some platform constraints, they could not make the whole dataset available for us to be used in reporting. Except for that, we used some basic reporting. When I used Torq, it was indeed in the early stages of AI capabilities. Only a few customers were allowed to use it, and we were among them. It functioned well as long as we summarized the data properly. If you input garbage, you would get garbage out. Thus, we had to do significant fine-tuning regarding what data context we provided to the AI orchestrator to get meaningful results. In terms of Torq's unified platform approach to AI SOC automation and case management compared to managing multiple point solutions across my security stack, I find it case-centric. The unified view in case management is good since it provides clarity, although there are limitations regarding how many items in case management can be modified at once. Bulk operations are very limited, potentially due to their back-end database or data retrieval processes that can be improved. Regarding improvements for Torq, when we were onboarded, there were aspects we were uncertain about, such as the number of cases that could be generated, what data we could bring in, how many clients we could onboard, and similar concerns. Initially, we also lacked clarity about the number of playbooks or workflows we could build. Different triggers like system triggers, case-based triggers, and others can be employed without restrictions, but when it comes to on-demand and scheduled jobs, there is a limitation based on the subscription and pricing tier that notably caps the number of workflows we can create. No bulk editing across cases was one issue, along with limited filtering related to single grouping constraints. Additionally, the out-of-the-box case templates provided require substantial modifications before they become usable. There is also a feature in the cases for notes that cannot be searched. They are only visible through the UI, which is another area for improvement. The workflow and execution-based charges seem misleading as this was not discussed initially. I am not sure if new customers are made aware of this. It seems that workflows revolving around cases hinder functionality outside of case management, as we have many use cases needing on-demand triggers and schedules for functions like reporting or polling devices. Creating additional workflows to achieve basic functionalities raises costs significantly, which disadvantages customers. While they facilitate optimization and scaling, the support received tends to be very basic. Improvements can be made in that area as well.
SH
Freelancer at a media company with 1,001-5,000 employees
Gaining unified control over vulnerabilities has improved governance but pricing and support need work
The market price is slightly high. The pricing should be a little lower because this is a SaaS-based product. Everyone using ServiceNow might be getting many modules, but the overall module cost becomes high with license consumption one by one. I personally see that if ServiceNow is to grow over the next decade, they need to work on the pricing part. Cheap providers are emerging, and in the age of AI, it is evident that the chatbot and the virtual agent features, which are prominent features of ServiceNow, could be completely compromised and replaced by people choosing other tools. If ServiceNow develops a strategy to lower the price and increase the customer base, it could help ServiceNow to grow for another decade. I encountered one issue in ServiceNow Security Operations. The different tools, for example, Tenable and TVM, discovered vulnerabilities that had very limited information when imported. However, the same vulnerabilities from different sources, the TVM and Tenable, had shorter descriptions than what was present in the common vulnerabilities or CVE. If this depends on the implementer, such as Tenable or how other security operations implement them, the text was very limited. Customers were asking questions about why this was happening and if ServiceNow was working properly. The vulnerability information should be updated and the common text should be displayed every time, regardless of how many different tools are used for integration. The vulnerability database should be consistent when it comes to the description to avoid confusion for customers implementing it for the first time. This is an improvement that ServiceNow can make.
SS
Manager cybersecurity at Hexion Inc.
Automates threat response and reduces investigation time but needs better threat intelligence integration
One thing that we would like to see with Splunk SOAR is the expandability to the threat intelligence feed. Currently, we have limited ingestion to the threat intelligence feed for the correlation purpose. We would like to see it being integrated, with license cost or without license cost, to leading threat intelligence sources such as Recorded Future, Feedly, or Flare. That is something we would appreciate having integrated. The second thing on the improvement side is about exposed credential-related information. If we start ingesting those data to Splunk SOAR or SIEM with some sort of integration with threat intelligence feed, that will also improve our detection and prediction method or help us with the investigation.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Using that one piece of AI, we auto-closed 511 cases in quarter four alone."
"If I review about 100 vendors that I might work with, Torq is definitely in the top five that gave me personally investment back, just because every bit of effort I put into Torq eventually became a workflow that gave it back to me."
"As an analyst, it has demonstrated potential to reduce workforce requirements and time needed for related activities."
"What I appreciate most about Torq is that it is an essential part of our system."
"Torq's unified platform approach to AI, SOAR, automation, and case management is superior compared to my experience managing multiple point solutions."
"Torq has exceeded expectations by delivering workflows in a timely and lower effort manner than XSOAR, and it meets all my needs while saving a ton of time and targeting $600,000 saved this year, which is a substantial amount of money."
"Torq has helped a lot regarding SOC analyst efficiency."
"Any request that comes in, regardless of how complex it is, I can accomplish it with Torq."
"ServiceNow Security Operations has helped me in getting more precise results."
"The solution is available over the cloud and is easy to manage."
"It has helped optimize security costs by consolidating multiple tools into one platform."
"I will recommend it to others as it is an enterprise application used by large companies for ticketing purposes."
"The most valuable aspect of working with ServiceNow is its meaningful and feature-rich product."
"The product has a very simple UI, I like the look and feel, and I find it very easy to navigate."
"It streamlines processes; it collects data, takes that data and turns it into information, and allows you to manage through dashboards and work lists, improving every facet of the overall process."
"The product's most valuable features include the no-code capability for workflows and flow design, which makes it user-friendly, and the ability to perform advanced configurations."
"Our customers find it easy to conduct searches and consider it an excellent content management system."
"When you design a playbook, you can integrate multiple log sources and define rules... After that, the platform automatically compiles all these activities and, based on the results, the analyst only has to indicate whether the result is a true or false positive. That reduces the time and effort involved."
"It helps increase efficiency and productivity."
"I'm just a beginner on the solution and it's pretty easy for me to use."
"The solution’s dashboard is really good and customizable. It also has a good UI."
"Very flexible integration with other tools"
"I like the way Splunk interacts with various systems via the API. The ability to integrate Splunk with our ticketing system has been an immense help because we can maintain our workflow while blending Splunk with our support desk and other ways that we track work."
"We are not a 24/7 SOC, so the most valuable feature of Splunk SOAR is the auto-response to threats when we are not in the office and the notifications that it sends to the on-call engineer."
 

Cons

"Additionally, the documentation for Torq is not very clear. Most of the information is presented in videos, which are not ideal for reading; there are mostly paragraphs and other text-based content."
"I wish Torq's AI assistant for building templated workflows from scratch worked better; when you start with a blank slate, asking AI to help you build or template the workflow out does not go well."
"The initial deployment of Torq was not easy."
"It was able to capture data but was unable to differentiate between the agent hostname we are using and the hostname that resides on the back end of the Internet."
"The workflow and execution-based charges seem misleading as this was not discussed initially, and creating additional workflows to achieve basic functionalities raises costs significantly, which disadvantages customers."
"Torq does extensive marketing saying that SOAR is dead and markets itself as an all-in-one solution, but this is not actually true."
"Even now, we have workflows that are in production that use AI steps and I get different results, making it unusable to some degree."
"We have MCP that we are working with our cloud security platform, and we wanted to connect this MCP to the case management."
"Report generation within ServiceNow can take some time."
"In future releases, I would like to add a follow-up and reminder feature. For the tickets in our queue, we could set reminders. This would help us prioritize older tickets before moving on to new ones."
"There is room for improvement in terms of developer support and documentation."
"There are limitations for the third-parties that are providing the inputs. They should increase the robustness of the solution."
"We'd like customization to be easier in terms of the UI and using the dashboards."
"Customer awareness and understanding of ServiceNow's SecOps capabilities could be improved."
"I would rate technical support for ServiceNow Security Operations as a six out of ten in terms of faster resolution."
"It's very slow. When you click a button or update a field, it takes forever to actually react."
"The Splunk SOAR platform was not designed specifically for case management which is why this area needs improvement."
"From the improvement point of view regarding Splunk SOAR, I suggest including more types of LLM models such as autonomous AI models including Anthropic and Opus 4.6, as well as creating a playground for new users to work on these, which will significantly help solve complex problems and assist new companies in understanding how Splunk works easily."
"I'd rate Splunk's technical support around five because compared to IBM QRadar, their support is much better. I feel Splunk should enhance their support, as it appears lacking, especially considering the costs associated with higher licenses."
"There are areas where Splunk SOAR can continue to improve, particularly regarding the synchronization of information, as sometimes it takes longer than other tools."
"The solution must provide more AIOps to improve predictability."
"The tool's response is slower because it has to search through a huge dataset, which can be improved for latency."
"I haven't had any issues with the solution so far."
"The solution is a bit more expensive than other offerings."
 

Pricing and Cost Advice

Information not available
"Compared to competitor tools, ServiceNow Security Operations is more affordable"
"If you're going to implement it on your own, there would be internal costs. If you're going to implement it through a contractor or consultant, you have to pay for that."
"It is an expensive product."
"The solution is more expensive than BMC Remedy, the other ITSM tool available in the market."
"This product is a good value for the money."
"The product is more expensive than other solutions."
"I don't know the exact price, but for my region, it is very expensive."
"In my opinion, the price is high, but if you want good products, you have to be willing to pay for them."
"Splunk SOAR is more expensive compared to other options for SOAR."
"The cost is high and the licensing is on an annual basis."
"Splunk SOAR is an expensive solution for an organization of our size."
"The tool is not cheap."
"Splunk is a fast enterprise tool, but it costs too much. At the same time, it's worth what we pay, in my opinion. We can efficiently perform all the functions and tie together the data. It's the perfect tool for our needs."
"We renewed it this year. This year was the first time there was a dramatic increase in the price. It was kind of non-negotiable. It was just a high increase. We had internal communications, and it was definitely a surprise to us. In a short time frame, we renewed it this year. Prices are going up everywhere, but they are not always justifiable, at least not to our eyes. The pricing this year was definitely a big shock."
report
Use our free recommendation engine to learn which Security Orchestration Automation and Response (SOAR) solutions are best for your needs.
902,270 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Construction Company
11%
Manufacturing Company
10%
Comms Service Provider
10%
Financial Services Firm
17%
Manufacturing Company
13%
Government
5%
Computer Software Company
5%
Financial Services Firm
12%
Manufacturing Company
9%
Construction Company
8%
Media Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise5
Large Enterprise5
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise2
Large Enterprise17
By reviewers
Company SizeCount
Small Business17
Midsize Enterprise10
Large Enterprise40
 

Questions from the Community

What needs improvement with Torq?
I do not dislike anything about Torq because it has satisfied all of our use cases and requirements. We contacted sup...
What is your primary use case for Torq?
Initially, we were using Slack for small automations, such as creating pipelines or shutting down servers. For exampl...
What advice do you have for others considering Torq?
I have been working for five years with experience in the IT field. Torq is very good. It manages everything. I would...
What is your experience regarding pricing and costs for ServiceNow Security Operations?
In my opinion, the pricing is quite affordable considering the features, and I do not find it expensive. I would not ...
What needs improvement with ServiceNow Security Operations?
I would like to see new features added, particularly regarding the incident upgrading part. For instance, if you have...
What advice do you have for others considering ServiceNow Security Operations?
For someone looking to use ServiceNow Security Operations, I recommend that they read about the documentation and spe...
What is your experience regarding pricing and costs for Splunk Phantom?
The pricing is quite high. Splunk SOAR is high priced, but their product is also a market leader, so that way it is g...
What needs improvement with Splunk Phantom?
Splunk SOAR can use generative AI more extensively in terms of creating the reports which can be presented to the top...
What is your primary use case for Splunk Phantom?
Splunk SOAR has been in use for almost seven or eight years.
 

Also Known As

No data available
No data available
Phantom
 

Overview

 

Sample Customers

Information Not Available
DXC Technology, Freedom Security Alliance, Prime Therapeutics, Seton Hall University, York Risk Services
Recorded Future, Blackstone
Find out what your peers are saying about ServiceNow Security Operations vs. Splunk SOAR and other solutions. Updated: June 2026.
902,270 professionals have used our research since 2012.