No more typing reviews! Try our Samantha, our new voice AI agent.

Splunk SOAR vs Trellix Helix Connect comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
4.9
Torq reduced alert handling time, increased efficiency and ROI, leading to customer satisfaction and renewal interest due to competitive pricing.
Sentiment score
5.6
Organizations using Splunk SOAR see improved ROI, efficiency, and resilience, despite integration challenges and ongoing maintenance costs.
Sentiment score
6.1
Trellix Helix enhanced security, reduced costs, increased efficiency, minimized manual work, decreased downtime, and offered deeper security insights.
Since we started working with Torq, I am handling much fewer alerts. It is becoming really easy for me to handle an alert.
SOC Analyst at AppsFlyer
By the time we officially bought Torq, we already had two workflows that were very helpful to us.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
It pretty much took until we got to our first renewal where we said that this is the value we see, this is the things we want more, but that is the first place where we said we are happy enough that we want to renew.
Information Technology Specialist at a media company with 201-500 employees
Since deploying Splunk SOAR, there has been a notable reduction in time spent on monotonous security tasks, which I estimate to be around 95%, enabling my team to focus on more strategic initiatives.
Identity and Access Management Specialist at a university with 10,001+ employees
We've seen a decrease in false positives and a significant increase in our containment.
Cyber Security Network Security Engineer at Cirrus Logic
Monthly, around 300 hours of effort, it is saving with Splunk SOAR.
Manager cybersecurity at Hexion Inc.
We have seen a return on investment with Trellix Helix Connect, and we can share relevant metrics as we reduce the MTTD and MTTR and have KPIs indicating our ROI.
Presales Lead at a outsourcing company with 11-50 employees
 

Customer Service

Sentiment score
7.0
Torq's customer service is praised for quick, knowledgeable support, resolving issues effectively within 24 hours with minimal formal contact.
Sentiment score
6.6
Splunk SOAR's support is praised for responsiveness and stability, but improvement is needed in niche areas like OT and IoT.
Sentiment score
6.1
Trellix Helix Connect's support is mixed, with praise for proficiency and criticism for delays, impacted by regional strengths.
The speed and quality of their answers have been pretty good, as I usually get a response within 24 hours, and they follow up well.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
We can always get an answer, and the support team are experts in their own system.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
Nine out of ten times, they give me a solution even if it is not the solution I wanted, and I still can get to the result.
Information Technology Specialist at a media company with 201-500 employees
Discovering different troubleshooting methods is harder to do with Splunk SOAR than with Enterprise Security or other Splunk services.
Cyber Security Network Security Engineer at Cirrus Logic
We always have a customer support representative who will come in the picture and help us to direct any ticket or any issue that we are facing to the right team.
Manager cybersecurity at Hexion Inc.
Splunk's technical support is very good and generally not needed often due to the stable environment.
System Engineer - Security Presales at Raya Integration
We experienced some challenges due to the ongoing transformation and fusion of McAfee and FireEye, but we are committed to improving response times.
Senior Value Engineering at a tech vendor with 5,001-10,000 employees
The customer support for Trellix Helix Connect is well in Latin America because there are many people in the region, which enhances the experience.
Presales Lead at a outsourcing company with 11-50 employees
 

Scalability Issues

Sentiment score
7.4
Torq excels in scalability, supporting large teams and adapting efficiently, despite the no-code automation's inherent web interface limitations.
Sentiment score
6.6
Splunk SOAR is praised for its scalability and flexibility, thriving in large environments despite occasional hardware challenges.
Sentiment score
7.2
Trellix Helix Connect is scalable and efficient but may be costly for some, leading to alternatives like CrowdStrike.
Our case management is super scalable.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
In terms of scalability, you can do as long as you can build it, and they can support it.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
Regarding the ability of the solution to grow in your work environment, if it is scalable, if it fits your business requirements, and if there is room to scale up, the answer is yes, for sure.
Global IT Director at OpenWeb
It can be extended and adapted as necessary.
Splunk/SOAR Engineer
Regarding scalability, I find it to be a nine, as we have had no issues with scaling Splunk SOAR.
Advance Data Engineer(Cyber Security) at Novo Nordisk
Everyone is ingesting Copilots or some form of AI in their platforms, and Splunk SOAR doesn't have it yet.
Senior Information Security Engineer at a tech company with 10,001+ employees
We support the largest companies in the world and can cater to large environments.
Senior Value Engineering at a tech vendor with 5,001-10,000 employees
Trellix Helix Connect's scalability is excellent as the solution has a library to make integrations with other brands.
Presales Lead at a outsourcing company with 11-50 employees
 

Stability Issues

Sentiment score
5.4
Torq generally performs stably with minor bugs and glitches, but overall user satisfaction remains high without significant disruptions.
Sentiment score
7.2
Splunk SOAR is stable with minor multitasking lag and implementation issues; praised for reliability, easy version control, and uptime.
Sentiment score
8.0
Trellix Helix Connect is highly stable and reliable, with minimal issues, often rated nine out of ten by users.
Most of the time, the system is stable as long as the components that they integrate with are stable.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
Regarding stability, I have noticed some lagging, crashing, and downtime, which is one of my largest gripes.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
I would rate Torq's product stability at eight, acknowledging that there are bugs, glitches, and downtimes.
Senior Cyber Architect at a manufacturing company with 10,001+ employees
We have not experienced any downtime, crashes, or performance issues.
Cyber Security Network Security Engineer at Cirrus Logic
We have not seen any impact in the work that we do with Splunk SOAR or the SIEM platform.
Manager cybersecurity at Hexion Inc.
I would rate Splunk SOAR's stability at around eight, indicating that it is quite stable with minimal downtime, bugs, or glitches.
Advance Data Engineer(Cyber Security) at Novo Nordisk
The availability is high, which is critical for our customers who rely on a single panel of glass to operate.
Senior Value Engineering at a tech vendor with 5,001-10,000 employees
Trellix Helix Connect is very stable, and I have experienced almost no downtime or issues.
Presales Lead at a outsourcing company with 11-50 employees
 

Room For Improvement

Torq requires improvements in AI features, error handling, data handling, and workflow navigation for enhanced usability and reliability.
Splunk SOAR struggles with a complex interface, integration issues, high costs, and needs improvements in automation and customization.
Trellix Helix Connect needs improvements in UI design, integration, support, pricing, and features to enhance user experience.
It was able to capture data but was unable to differentiate between the agent hostname we are using and the hostname that resides on the back end of the Internet.
Senior Consultant at a university with 10,001+ employees
From an engineering perspective, I think more error messages and error handling information for our engineering team would be very helpful.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
If a step is failing, the system could try to autocorrect it with AI or open a ticket from the workflow itself.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
If we start ingesting those data to Splunk SOAR or SIEM with some sort of integration with threat intelligence feed, that will also improve our detection and prediction method or help us with the investigation.
Manager cybersecurity at Hexion Inc.
Although it enhances alert handling, it still has a journey to compete with Palo Alto SOAR and FortiSOAR.
System Engineer - Security Presales at Raya Integration
Splunk's Unified Platform does help consolidate networking security and IT observability tools.
Cyber Security Network Security Engineer at Cirrus Logic
We have just released the solutions to the market recently, making it a revolution in the cybersecurity sector.
Senior Value Engineering at a tech vendor with 5,001-10,000 employees
The usability of hyperautomation is something to improve in the solution because it is expensive regarding the needed improvements.
Presales Lead at a outsourcing company with 11-50 employees
 

Setup Cost

Enterprise buyers find Torq's pricing high but worthwhile due to its modernization, automation, and strategic investment value.
Splunk SOAR's high pricing is justified for large enterprises, but costly for small to medium-sized businesses.
Trellix Helix Connect is considered reasonable, costly, competitive for enterprises, with bulk discounts and free for FireEye users.
When they bring more and more value into the platform, it makes more sense to pay that price, but still, it is expensive.
Senior Cyber Architect at a manufacturing company with 10,001+ employees
Before deciding to implement Torq, I considered that compared to our old case management platform, Torq was a much better price and had a lot better value for what you get out of the platform, which was a key consideration for the company.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
It is an expensive solution, not an inexpensive solution, but we get through the flexibility.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
It is way below what it costs to hire some professionals to do only that type of work.
Splunk Engineer at Data Elicit Solutions Pvt. Ltd.
Splunk SOAR is moderately priced, neither cheap nor overly expensive.
Splunk/SOAR Engineer
I am familiar with the pricing aspect, setup cost, and licensing cost of Splunk SOAR, and it is pretty much similar to what industries are offering these days.
Manager cybersecurity at Hexion Inc.
It is not the cheapest, but also not the most expensive solution.
Senior Value Engineering at a tech vendor with 5,001-10,000 employees
 

Valuable Features

Torq enhances productivity by streamlining workflows, integrating systems, and utilizing AI for efficient SecOps and API management.
Splunk SOAR enhances efficiency with integration, automation, user-friendly interface, and customization, reducing incident resolution time and improving resilience.
Trellix Helix Connect excels at automating processes, enhancing threat detection, and improving security with strong integration and AI features.
Torq's unified platform approach to AI SOC automation and case management has significantly benefited us by integrating the case management platform with the automation, which saves time compared to managing multiple point solutions across our security stack.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
The fact that I can build whatever I want within my own imagination and skills without relying on code is the best thing about Torq.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
You can copy and paste a cURL command. If you have documentation or APIs, you usually have an example on the side. You basically have all the information on how the API call should be. You can just copy that and paste it into a step, and it will just build the step for you.
Global IT Director at OpenWeb
Creating playbooks using the Playbook Editor in Splunk SOAR is easy. The editor is designed to be user-friendly with visual drag and drop features, allowing for easy workflows without writing any code.
Splunk/SOAR Engineer
Splunk SOAR saves time in threat response, and the time to solve an incident is currently the best in the market.
Strategic Account Executive at a computer software company with 51-200 employees
Splunk SOAR has improved our MTTD and MTTR both with the consolidation with a unified platform with Splunk.
Manager cybersecurity at Hexion Inc.
Trellix Helix, as an AI XDR platform, helps our organization by offering an extensive number of connectors for integration, enabling us to consolidate all information in a single dashboard.
Senior Value Engineering at a tech vendor with 5,001-10,000 employees
 

Categories and Ranking

Torq
Sponsored
Average Rating
8.6
Reviews Sentiment
6.6
Number of Reviews
7
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (5th), AI-SOC (3rd), AI-Powered Security Automation (2nd)
Splunk SOAR
Average Rating
8.0
Reviews Sentiment
6.6
Number of Reviews
57
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (2nd)
Trellix Helix Connect
Average Rating
8.6
Reviews Sentiment
6.7
Number of Reviews
13
Ranking in other categories
Security Information and Event Management (SIEM) (19th), Security Incident Response (3rd)
 

Mindshare comparison

Security Orchestration Automation and Response (SOAR) Mindshare Distribution
ProductMindshare (%)
Splunk SOAR8.0%
Microsoft Sentinel12.2%
Palo Alto Networks Cortex XSOAR8.8%
Other71.0%
Security Orchestration Automation and Response (SOAR)
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
Trellix Helix Connect1.1%
Splunk Enterprise Security7.2%
Wazuh5.8%
Other85.9%
Security Information and Event Management (SIEM)
 

Featured Reviews

Nimrod Vardi - PeerSpot reviewer
Global IT Director at OpenWeb
Automation workflows have transformed our IT, enabling secure just-in-time access control
We work with them quite often, so we have a direct line regarding areas in Torq that have room for improvement. If we have a feature request, we can request it. I do not have anything in mind at the moment. We were a design partner for a short while, so we feel that they listen and that users of the system have an impact on the way the system is designed for the better. They have a new community, which is something that I personally suggested years ago. There are many people like me in different places and they might have already built the workflow that I need. Having the option to share workflows or to jump on a thread and say I have this need, did anyone ever build a workflow for it, is amazing. Someone would jump in and say yes, sure, here, take this workflow. I think this is an amazing thing and I really hope that the community will come alive because I think this is really powerful. This is something that I already suggested and it did happen eventually, and I am quite happy with it. I do not have any specific feature in mind that I have a need for at the moment.
SS
Manager cybersecurity at Hexion Inc.
Automates threat response and reduces investigation time but needs better threat intelligence integration
One thing that we would like to see with Splunk SOAR is the expandability to the threat intelligence feed. Currently, we have limited ingestion to the threat intelligence feed for the correlation purpose. We would like to see it being integrated, with license cost or without license cost, to leading threat intelligence sources such as Recorded Future, Feedly, or Flare. That is something we would appreciate having integrated. The second thing on the improvement side is about exposed credential-related information. If we start ingesting those data to Splunk SOAR or SIEM with some sort of integration with threat intelligence feed, that will also improve our detection and prediction method or help us with the investigation.
reviewer2646834 - PeerSpot reviewer
Presales Lead at a outsourcing company with 11-50 employees
Reduces detection and response times through automation and alert correlation
The best features that Trellix Helix Connect offers are SOAR, automation, hyperautomation, and the correlation of alerts and threat intelligence, for example, when the alerts cross through MITRE ATT&CK, which stand out most to me. Out of those features, automation, alert correlation, and threat intelligence have made my work easier and more effective as we integrate many cybersecurity solutions into the XDR and set up the use cases to reduce MTTD and MTTR from days to minutes. I would add that the level of integration with other brands is something that surprises me about the features of Trellix Helix Connect. Trellix Helix Connect has positively impacted my organization as it is the most important tool to provide MDR service to our clients, which has resulted in specific outcomes and improvements.
report
Use our free recommendation engine to learn which Security Orchestration Automation and Response (SOAR) solutions are best for your needs.
885,789 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Construction Company
11%
Comms Service Provider
8%
Manufacturing Company
8%
Financial Services Firm
12%
Manufacturing Company
10%
Computer Software Company
8%
University
6%
Comms Service Provider
16%
Computer Software Company
9%
Financial Services Firm
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Midsize Enterprise3
Large Enterprise4
By reviewers
Company SizeCount
Small Business16
Midsize Enterprise8
Large Enterprise36
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise1
Large Enterprise7
 

Questions from the Community

What needs improvement with Torq?
This is exactly what we discussed two days ago with the Torq team. We told them where we want to see improvements. Fo...
What is your primary use case for Torq?
I use Torq as my case management and alert system. Working as a SOC analyst, the first thing I do every morning is ge...
What advice do you have for others considering Torq?
I would definitely recommend Torq. I have no doubt, really. When we looked for another vendor, Torq really answered a...
What is your experience regarding pricing and costs for Splunk Phantom?
I am familiar with the pricing aspect, setup cost, and licensing cost of Splunk SOAR, and it is pretty much similar t...
What needs improvement with Splunk Phantom?
Sometimes it lags when I am working on multiple things. Apart from that, every feature is useful. Integration is an a...
What is your primary use case for Splunk Phantom?
We have been using Splunk SOAR for analyzing threats and mitigating issues in cybersecurity. We provide input and SQL...
What is your experience regarding pricing and costs for FireEye Helix?
The price of Trellix Helix is competitive in the market. It is not the cheapest but also not the most expensive. As f...
What needs improvement with FireEye Helix?
To improve Trellix Helix Connect, I think it is possible to enhance the dashboard to share more information about the...
What is your primary use case for FireEye Helix?
My main use case for Trellix Helix Connect is to provide an MDR service to our clients. We use Trellix Helix Connect ...
 

Also Known As

No data available
Phantom
FireEye Helix, FireEye Threat Analytics
 

Overview

 

Sample Customers

Information Not Available
Recorded Future, Blackstone
Police Bank, Verisk Analytics, Teck Resources
Find out what your peers are saying about Microsoft, Splunk, Palo Alto Networks and others in Security Orchestration Automation and Response (SOAR). Updated: March 2026.
885,789 professionals have used our research since 2012.