No more typing reviews! Try our Samantha, our new voice AI agent.
JaiBharath Boithi - PeerSpot reviewer
Data Scientist at a tech vendor with 51-200 employees
Real User
Top 5Leaderboard
Aug 19, 2026
Automation has transformed incident response and has saved many analyst hours each week
Pros and Cons
  • "Splunk SOAR has significantly improved our ability to investigate and remediate threats by centralizing alerts and automating responsive workflows."
  • "I would like to see easier playbook development, better troubleshooting, debugging, and more intuitive improved integrations and documentation, which would also make automation easier to maintain."

What is our primary use case?

I primarily use Splunk SOAR for security incident response automation, alert triage, and orchestrating automation remediation workflows.

For example, I use Splunk SOAR to automatically enrich security alerts, investigate suspicious IPs, and trigger actions such as blocking malicious IPs and requests and isolating affected endpoints based on predefined playbooks and APIs.

I also use Splunk SOAR to reduce manual investigation and testing and to standardize incident response while improving response time through automated playbooks and integrations.

One success story involved automating suspicious IP investigation and blocking through a Splunk SOAR playbook, which reduced the response time from several manual steps to a few minutes. It saved the team significant time and potentially prevented malicious activity before it could impact other systems.

What is most valuable?

The best features of Splunk SOAR, in my opinion, are automated playbooks, integrations with security tools, alert enrichment, and automated response remediations, which help reduce manual effort and speed up incident response.

I rely mostly on automated playbooks because they streamline repetitive investigation and response steps, help ensure consistent handling of incidents, and significantly reduce manual efforts and response time.

Another useful feature is case management and investigation tracking, which helps maintain investigative context, document actions, and coordinate response activities efficiently.

Splunk SOAR has positively impacted my organization by reducing manual effort on incident response time by automating repetitive security tasks, improving response consistency, and enhancing overall SOC efficiency.

What needs improvement?

I would like to see easier playbook development, better troubleshooting, debugging, and more intuitive improved integrations and documentation, which would also make automation easier to maintain. If there is a good idea on it, it will be easy to go through it.

Better playbook debugging and error handling would help, especially for complex workflows. More detailed execution logs and simple integration configuration would also improve day-to-day use cases.

I think Splunk SOAR's AI capabilities have strong governance and security with an emphasis on transparency, privacy, and secure data, but I would still like more granular control over AI from the auditability and automation actions.

The output from Splunk SOAR is generally accurate and reliable, especially for SPL generation and security analysis, but I still validate generated results before using them in production because occasional hallucinations or incorrect queries can occur.

For how long have I used the solution?

I have been using Splunk SOAR for approximately 1.8 to 2 years.

Buyer's Guide
Splunk SOAR
August 2026
Learn what your peers think about Splunk SOAR. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,683 professionals have used our research since 2012.

What do I think about the stability of the solution?

I would consider Splunk SOAR stable and reliable for our production use, as we have found it dependable in running automated playbooks and integrations with good system health monitoring and troubleshooting.

What do I think about the scalability of the solution?

Splunk SOAR's scalability allows it to handle increasing volumes and automation work by scaling through additional resources, distributed deployments, and integrations as the security environment grows.

How are customer service and support?

I rate customer support an 8 out of 10, as the support team is responsive and helpful for technical issues, especially with integrations and troubleshooting, although complex cases can take time to resolve. Splunk also provides a support portal and documentation for troubleshooting.

Which solution did I use previously and why did I switch?

We previously relied more on processes and separate security tools for alert investigation and response. We moved to Splunk SOAR to centralize workflows, automate tasks, and reduce incident response time.

How was the initial setup?

The pricing and license for Splunk SOAR were reasonable for the value provided, although the initial setup and integration required some planning, with the main effort centered around configuring integrations.

What about the implementation team?

We only have a customer relationship with the vendor and are not a partner, reseller, or distributor.

What was our ROI?

We have seen a positive return on investment mainly through time savings rather than reducing headcount, as automation has reduced repetitive security work by roughly 30 to 40%, saving around 10 to 15 hours per week for the team. Incident response time has also improved by approximately 25 to 30% due to automating enrichment, investigation, and response steps. The saved capacity allows analysts to focus on threat hunting, complex investigations, and security projects, offering the biggest financial benefit from getting more done with the same team size and resources.

Which other solutions did I evaluate?

Before moving to Splunk SOAR, we evaluated several tools and applications, such as Palo Alto Cortex, XSOAR, IBM Resilient, and Swimlane before making our choice.

What other advice do I have?

Splunk SOAR integrates well with our existing security tools through its wide range of apps and APIs, making it easy to exchange alerts, enrich data, and connect systems.

Splunk SOAR has saved us roughly 10 to 15 hours per week by automating repetitive investigations and response tasks, thus allowing the team to focus on higher priority security problems.

Splunk SOAR has helped us consolidate several security tools into centralized automation workflows, connecting SIEM and endpoint security, reducing the need to manually switch between multiple console investigations and centralizing alerts to increase investigation and response actions through playbooks. Overall, it has improved operational efficiency and made the security workflow more consistent.

Splunk SOAR has significantly improved our ability to investigate and remediate threats by centralizing alerts and automating responsive workflows. Playbooks provide good end-to-end visibility into the investigation steps and actions taken. For our on-premises environment, troubleshooting is generally straightforward because the execution logs make it easy to identify failed actions, although complex playbooks and integrations can sometimes require additional troubleshooting. Overall, threat investigation and remediation are faster, more consistent, and easier to manage.

Splunk SOAR is a stable and reliable security automation platform. Its playbooks and integrations significantly reduce manual work, improve response times, and provide consistent incident handling. I would rate it around 8 out of 10.

I recommend Splunk SOAR for organizations looking to automate security operations and reduce manual efforts. It is best to start with a few high-value use cases, validate integrations, and gradually expand playbooks as the team becomes comfortable with the platform.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Aug 19, 2026
Flag as inappropriate
PeerSpot user
Vsadalaga Sadalga - PeerSpot reviewer
Soc Analyst at a manufacturing company with 10,001+ employees
Real User
Top 5Leaderboard
Aug 10, 2026
Automation has reduced manual soc work and speeds up consistent incident investigations
Pros and Cons
  • "Splunk SOAR has helped me reduce manual work and improve the speed of incident response, and automating alert enrichment and repetitive investigation steps allows analysts to focus more on actual investigation and high-priority incidents."
  • "Splunk SOAR could be improved by making playbook development easier for new users and providing better troubleshooting and debugging options."

What is our primary use case?

My main use case for Splunk SOAR is automating repetitive SOC tasks and speeding up incident response, and I mainly use it for alert enrichment, gathering information from security tools, and performing actions such as blocking IPs or isolating affected endpoints when required. This reduces manual effort and helps analysts respond to incidents faster.

One example of how I have used Splunk SOAR for alert enrichment was a suspicious IP alert where I automated the enrichment process; the playbook checked the IP reputation using my threat intelligence source and gathered additional information before the analyst reviewed the alert. If the IP was confirmed as malicious, the playbook could trigger the blocking action through the relevant security tool, which reduced the manual steps and helped me respond faster.

What is most valuable?

Splunk SOAR mainly helps me automate repetitive tasks and make investigations faster; it fits into my daily workflow by enriching alerts, collecting information from different security tools, and automating response actions where appropriate. This allows analysts to spend more time on investigation rather than manual enrichment tasks.

The best features of Splunk SOAR, in my opinion, are playbook automation, alert enrichment, and integration with different security tools, and the playbooks are especially useful because they automate repetitive investigation and response steps, which saves time for SOC analysts. The wide range of integrations also makes it easier to connect Splunk SOAR with existing security tools.

I find playbooks fairly easy to customize once I understand the workflow and available actions, and I mainly use them for alert enrichment, such as checking IP or domain reputation and collecting information from security tools. Common integrations in my workflow include Splunk, threat intelligence platforms, and endpoint security tools, and the main benefit is that I can automate repetitive investigation steps and customize the playbook based on the alert type.

Another useful feature of Splunk SOAR is the ability to run actions across multiple security tools from a single playbook; overall, it helps reduce manual work, standardize investigation steps, and makes the incident response process faster and more convenient.

What needs improvement?

Splunk SOAR could be improved by making playbook development easier for new users and providing better troubleshooting and debugging options. More out-of-the-box integrations and simpler configuration for integrations would also be helpful, and better reporting on playbook performance and automation results would make it easier to measure the overall value of the automation.

One challenge I face is that some integrations can require additional configurations and troubleshooting before they work smoothly; also, debugging complex playbooks can sometimes take time. Improving documentation, error messages, and troubleshooting guidance would make it easier for SOC analysts to build and maintain playbooks.

For how long have I used the solution?

I have been using Splunk SOAR for 1.5 years.

What was our ROI?

I saw value relatively quickly after implementation; once the main integrations and a few common playbooks were configured, I started seeing benefits within the first few weeks. The biggest early benefit was the reduction in manual enrichment and repetitive response tasks, which helped analysts save time and focus on higher-priority investigations.

What other advice do I have?

Splunk SOAR has helped me reduce manual work and improve the speed of incident response, and automating alert enrichment and repetitive investigation steps allows analysts to focus more on actual investigation and high-priority incidents. It has also made my response process more consistent by using standardized playbooks for common alert types.

I have noticed a clear reduction in manual investigation time for common alerts since using Splunk SOAR; Splunk SOAR playbooks can automate several enrichment steps that previously required analysts to perform them manually. In practice, this can save around 10 to 15 minutes per alert, depending on the use case, and allows analysts to focus more on investigation and response.

Splunk SOAR has helped free up some analysts' time by automating repetitive enrichment and response tasks; on average, it can save around 10 to 15 minutes on common alerts, depending on the playbook. It gives analysts more time to focus on detailed investigations, threat hunting, and other security projects.

Splunk SOAR improves my ability to investigate and respond by bringing enrichment and response action into a single workflow. It provides good visibility into the investigation through the data collected by the playbook, although understanding complex cloud environments can still require additional knowledge and troubleshooting. Overall, it makes routine investigations and remediation steps easier by reducing the number of manual steps.

My experience connecting existing security tools with Splunk SOAR has been good overall; I mainly use integrations with Splunk, endpoint security tools, threat intelligence sources, and network security tools for alert enrichment and response actions. Once the integrations are configured, playbooks can easily pass information between the tools, which helps reduce manual work during investigation.

My advice would be to start with a few common and repetitive SOC use cases rather than trying to automate everything at once; make sure the required integrations are properly configured and test playbooks before using automated response actions in production. Splunk SOAR is most useful when it is used to reduce manual work and standardize common investigation and response processes. I would rate my overall experience with Splunk SOAR as a 9 out of 10.

Which deployment model are you using for this solution?

Private Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Aug 10, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Splunk SOAR
August 2026
Learn what your peers think about Splunk SOAR. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,683 professionals have used our research since 2012.
reviewer2898987 - PeerSpot reviewer
Technical Architect at a healthcare company with 10,001+ employees
Real User
Top 20
Sep 15, 2026
Automation playbooks have reduced response times and now streamline alert investigations
Pros and Cons
  • "Splunk SOAR helps my team prioritize and respond to security alerts and incidents very effectively because it automates many of the manual tasks for us."
  • "I have not seen a return on investment. We have not realized any measurable business outcomes, such as cost savings or risk reduction, from using Splunk SOAR."

What is our primary use case?

My main use case for Splunk SOAR is integration with third-party apps.

A quick specific example of how I use Splunk SOAR for integrating with third-party apps is collecting context data to help with investigations.

We use Splunk SOAR for remediation as well, such as quarantining machines.

What is most valuable?

One of the best features Splunk SOAR offers is the ease of creating playbooks.

The aspect of creating playbooks in Splunk SOAR that makes it easy for me is its very flexible nature in terms of what we can do, and it is very capable because of that.

Splunk SOAR has impacted my organization positively by lowering the time to respond. We probably save about one-third of the time in our response time, roughly.

The accuracy and reliability of output in Splunk SOAR, especially when it comes to automation or any AI-driven features I have used, is very spot on, but those are manually defined parameters.

What needs improvement?

To improve Splunk SOAR, I would suggest making it easier for integration with third-party applications without having to learn custom API commands. If something is not supported out of the box, it would be nice to have something easier to build out the integration.

I would change Splunk SOAR by using more AI to help us create playbooks without having to know how to create a playbook.

I would assess Splunk SOAR's ability to integrate with other systems and applications in my environment as having some lagging. Since not everything is supported, anything missing is possible to integrate, but it does require manual setup to make it work, and that can be a challenge.

For how long have I used the solution?

I have been using Splunk SOAR for five years.

What do I think about the stability of the solution?

Splunk SOAR is stable, except for during upgrades which still require downtime, so that is something to work around.

What do I think about the scalability of the solution?

Splunk SOAR's scalability seems to just work without any issues.

How are customer service and support?

The customer support for Splunk SOAR is very good. I would rate the customer support a 10 on a scale of 1 to 10.

Which solution did I use previously and why did I switch?

I did not previously use a different solution before Splunk SOAR.

How was the initial setup?

I did not purchase Splunk SOAR through the AWS Marketplace. I purchased it from Splunk.

What was our ROI?

I have not seen a return on investment. We have not realized any measurable business outcomes, such as cost savings or risk reduction, from using Splunk SOAR.

What's my experience with pricing, setup cost, and licensing?

I was not involved with the pricing, setup cost, and licensing.

Which other solutions did I evaluate?

Before choosing Splunk SOAR, we did not evaluate other options.

What other advice do I have?

Splunk SOAR helps my team prioritize and respond to security alerts and incidents very effectively because it automates many of the manual tasks for us.

The use of Splunk SOAR's automation playbooks has allowed our analysts to spend less time trying to get context, therefore enabling us to spend more time figuring out and assessing the threat.

I am satisfied with the customization and management of Splunk SOAR playbooks in my environment.

Splunk SOAR has not impacted my ability to scale security operations and onboard junior analysts because it does require some getting used to for a junior analyst to start developing and using Splunk SOAR.

My advice for others looking into using Splunk SOAR is to start small and build that out. Do not try to do something major on day one. I would rate this review an overall 8 out of 10.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 15, 2026
Flag as inappropriate
PeerSpot user
R Nandasana - PeerSpot reviewer
Senior Information Technology Security Consultant at Mideast Data Systems
Real User
Top 5Leaderboard
May 20, 2026
Security automation has reduced manual investigation and now streamlines phishing incident handling
Pros and Cons
  • "Analysts save a lot of time with Splunk SOAR because all relevant details from phishing emails, including the email ID, IP address, sender information, and email content such as links or attachments, are automatically integrated into an incident and sent to ServiceNow, making troubleshooting easier and enabling them to start investigating directly or know what to do next."
  • "To make Splunk SOAR more usable, the tool needs to be simplified."

What is our primary use case?

I mainly using Splunk SOAR for security automation. We want to create security incidents based on monitoring data and logs in Splunk. For example, if we identify firewall issues such as unauthenticated firewall login attempts, we analyze these logs and create security incidents. Our SOC team then works on these incidents to find the resolution and take necessary actions.

We use many playbooks and customize them extensively. We have built most of our playbooks based on learnings from our experience.

What is most valuable?

Splunk SOAR is very flexible. We can use Python, which is one of the best aspects because we can write many Python-based playbooks that significantly reduce manual SOC work. Additionally, it supports all environments including on-premises, cloud, and hybrid deployments.

There are many workflows available to investigate issues, which is very valuable. Splunk SOAR provides alerts immediately whenever something wrong happens, unlike our previous Splunk alerts which we could only schedule for specific times. This immediacy is very useful.

It is also helpful for threat intelligence enrichment. When we identify threats in our logs, Splunk SOAR assists us. We frequently receive phishing IPs and phishing emails, and Splunk SOAR immediately identifies all of these and informs our full team via email.

Analysts save a lot of time with Splunk SOAR. For example, with phishing emails, we can find the email in our email logs and identify it as phishing from a specific sender. We can integrate many things with the playbook including the email ID, IP address, sender information, and email content such as links or attachments. All of these details are included in the incident and sent to ServiceNow to create an incident containing everything needed. This makes troubleshooting easier because analysts can read all information and understand the full issue, allowing them to start investigating directly or know what to do next. We can also include next steps in the playbook such as blocking the sender.

What needs improvement?

Licensing becomes expensive for large-scale automation. We currently have fewer than 50 playbooks, but if we were to go over 100 or 500 playbooks, licensing would become significantly more expensive because of the large amount of data ingestion.

To make Splunk SOAR more usable, the tool needs to be simplified. There are many other tools in the market that are very good. For instance, Torq is better than Splunk SOAR because Torq has a no-code UI where we can accomplish anything through drag and drop. In Splunk SOAR, we need to write playbooks, so the tool could be improved with drag and drop functionality or default predefined playbooks.

Another limitation of Splunk SOAR is that initial learning is required. Additionally, when a playbook fails partway through, it is difficult to identify and troubleshoot the issue.

For how long have I used the solution?

I have been using Splunk SOAR for one year.

What do I think about the stability of the solution?

Splunk SOAR is a stable product. We have not experienced any downtime or issues.

What do I think about the scalability of the solution?

Scalability will increase cost somewhat because of more data ingestion. However, there are many benefits that come with the increased cost, and the return on investment is very good compared to the cost. For example, we are paying a certain amount but receiving value equal to that investment.

How are customer service and support?

Technical support was very good and very helpful. Whenever we have a problem, we raise a case and the support team comes and fixes the issue. They are very responsive.

Which solution did I use previously and why did I switch?

We have never used another SOAR solution before. I am aware that Palo Alto SOAR exists, but I do not know details about it.

We did not switch from another SOAR at our current company. However, at my previous company, we were using Torq, and at my current company, we are using Splunk SOAR. This is why I am familiar with both. By comparing both products, I prefer Torq.

How was the initial setup?

Deployment was very easy. We received help from Splunk support, and they provided excellent assistance, making the deployment straightforward. We experienced no challenges.

Which other solutions did I evaluate?

I can provide one piece of advice. Before purchasing Splunk SOAR, explore many other SOARs as well. Palo Alto SOAR is available, and I have heard of Tines, which is also a product worth considering. Based on your use cases, you can make a decision. If you are completely dependent on security automation and an incident response platform, then Splunk SOAR may be suitable. If your use case does not match this area, you should choose another SOAR or consider Torq.

What other advice do I have?

Onboarding a junior analyst is somewhat complex because they need to become familiar with the UI, which is complex for new junior analysts. However, if someone has experience with Splunk SOAR and other similar tools, they can onboard easily and work on the platform effectively. I would rate this product overall as a five-star solution based on the overall experience.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Last updated: May 20, 2026
Flag as inappropriate
PeerSpot user
Mohsin Mehdi - PeerSpot reviewer
Cybersecurity Integrater at a government with 10,001+ employees
Real User
Top 20
Sep 16, 2026
Automation has streamlined investigations and onboarding but still needs smoother administration
Pros and Cons
  • "Splunk SOAR helps in automating a lot of tasks, reduces man-hours, reduces response time since everything is automated, and it requires less human interaction."
  • "Because Splunk SOAR was initially based off the Phantom application, there is still some leftover legacy code from Phantom that should be upgraded and made its own."

What is our primary use case?

Splunk SOAR's main use case in our organization is automating tasks. We use Splunk SOAR to automate the creation and deployment of the endpoint binary from the Velociraptor server to the endpoint.

We decided to automate that specific process with Splunk SOAR because we had been doing it manually, and it seemed like the next logical step to automate the process to make it easier for the admins.

Splunk SOAR helps in automating a lot of tasks, reduces man-hours, reduces response time since everything is automated, and it requires less human interaction.

What is most valuable?

The best features Splunk SOAR offers are the fact that it can remotely apply things, and once it's set up and the network allows it, it's very easy to integrate into everything.

Integration has helped our workflow significantly. Once firewall connectivity has been opened and network connectivity has been established, it is really easy that when a new use case comes up, we can just start working on it and reduce deployment time since it's already integrated into the network.

Splunk SOAR has positively impacted our organization as it is a great remote management tool. We have an on-premises deployment, so it is easy to manage, simple to upgrade, and just a very helpful and simple tool for automation.

Splunk SOAR does reduce errors since it is automated, and because scripting and automation are involved, it does reduce a lot of time, including the onboarding time for new administrators and new employees since everything is automated. Once you teach them how to do it, it doesn't require much scripting after it has been initially completed.

What needs improvement?

Because Splunk SOAR was initially based off the Phantom application, there is still some leftover legacy code from Phantom that should be upgraded and made its own. For example, it is cumbersome how you have to manage the system on a Linux box where we have it installed, as every time the server reboots, it doesn't always start up on its own, and there isn't a systemd file for it that you can enable and run as a daemon. A lot of the old legacy Phantom code needs to be upgraded to make Splunk SOAR a truly enterprise application.

I haven't really used Splunk SOAR's AI capabilities yet, but I believe that is the next step. The next updates should make creating apps and integrations even simpler, though I do not have much experience with it. I believe security is the biggest concern going forward, to ensure erroneous prompts don't cause downtime or create applications and integrations that are too open. I believe its accuracy and reliability of output still require improvement, though I don't have much experience with it.

As far as additions, I would say a systemd file would help for Linux deployments, along with better monitoring of the process from the operating system side, which we've noticed. The fact that it also requires a Linux user and a Phantom user to function, if you can reduce the need for a service account, that would also help.

For how long have I used the solution?

I have been using Splunk SOAR for about a year and a half.

What do I think about the stability of the solution?

Splunk SOAR is very stable in our environment.

What do I think about the scalability of the solution?

Splunk SOAR's scalability is good. We have an organization with thousands of servers and endpoints, and it has been working really well for us.

How are customer service and support?

Customer support for Splunk SOAR has been good. We have run into incidents or issues during upgrades which support has been helpful with.

Which solution did I use previously and why did I switch?

We have other automation tools like Ansible or Microsoft TFSA, but I'm not sure if we specifically used a different solution for SOAR.

What was our ROI?

I don't have a metric, but I do believe Splunk SOAR is helping us since we have been renewing it ever since it was onboarded.

What other advice do I have?

Splunk SOAR's automation playbooks have greatly affected how my analysts allocate their time during a typical security investigation. It lets them focus on the investigation instead of the initial setup and scripts or tools they need to deploy, so it is amazing for that. It reduces their overhead time on non-incident tasks and lets them focus on the incident tasks.

Splunk SOAR helps our team prioritize and respond to security alerts and incidents very effectively. Anytime a new need arises or the security analyst gets stuck, they reach out to the admins to create new playbooks or new automation that they might need, and once it has been set up and tested, it reduces their blockers on any investigations.

Splunk SOAR has really helped with onboarding junior analysts. Whatever skill sets they come in with, they can apply it to incident response and security incidents, and since Splunk SOAR automates all the tool deployments, it reduces their onboarding time with that.

The advice I would give to others looking into using Splunk SOAR is that there is a learning curve with creating playbooks, but once you get the hang of it, it is a really useful tool that makes your day-to-day job a lot easier. The transition from Phantom to Splunk SOAR is not complete, and completing that transition would be very helpful. I would rate my overall experience with Splunk SOAR as a seven out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 16, 2026
Flag as inappropriate
PeerSpot user
reviewer2875785 - PeerSpot reviewer
Soc Analyst at a manufacturing company with 10,001+ employees
Real User
Top 5Leaderboard
Aug 12, 2026
Automation has reduced manual effort and improves incident response with integrated playbooks
Pros and Cons
  • "Splunk SOAR has freed up our resources by automating tasks like IOC enrichment, reputation checks, ticket creation, and incident updates, reducing our manual efforts by approximately 20 to 30 percent and giving our analysts more time to focus on complex tasks and complex investigations."
  • "Splunk SOAR could be improved with a more intuitive user interface, better playbooks, and more detailed documentation."

What is our primary use case?

We use Splunk SOAR to automate tasks by creating playbooks. For example, if we want to enrich data related to an IP address, we can create a playbook for that. We get information from the threat intelligence platform, or we have another use case where instead of creating manual tickets in ServiceNow, we use Splunk SOAR to create the tickets and populate all the tickets in ServiceNow.

For example, if there is an incident alert in Splunk SIEM which looks malicious, we create a ticket in ServiceNow. We run the playbook in Splunk SIEM and provide the relevant information or the required information. After that, the Splunk SOAR ServiceNow ticket will be created automatically. Analysts do not have to create that ticket manually; it will be created automatically.

We also have other use cases such as IOC enrichment, IP and domain reputation checks, and certain threat intelligence lookups, as well as some containment actions like blocking IPs or domains.

What is most valuable?

The best features of Splunk SOAR are the playbook automation, integration, and IOC enrichment, as well as incident orchestration. I especially find the ability to automate repetitive tasks and connect tools like SIEM, EDR, firewall, or threat intelligence very useful for improving response time and reducing manual efforts.

It has significantly reduced manual effort and improved our incident response time. It automates repetitive tasks like IOC enrichment, threat intelligence checks, and ServiceNow ticket creation. This allows analysts to focus more on complex investigation and helps us respond to threats more consistently.

The integration capabilities are very strong. Splunk SOAR integrates well with SIEM, EDR, firewall, and threat intelligence platforms through apps and APIs. This allows us to automate tasks like enrichment, creating tickets, and response actions across multiple security tools.

Splunk SOAR has freed up our resources by automating tasks like IOC enrichment, reputation checks, ticket creation, and incident updates. As I mentioned, it has reduced our manual efforts by approximately 20 to 30 percent. This gives our analysts more time to focus on complex tasks and complex investigations.

What needs improvement?

Splunk SOAR could be improved with a more intuitive user interface, better playbooks, and more detailed documentation. Additionally, more out-of-the-box integrations would make deployment easier and reduce the efforts we need to do with custom API integrations.

The UI and documentation could be improved, and playbook troubleshooting could be more user-friendly. Apart from that, its automation integrations are very effective for SOC operations.

For how long have I used the solution?

I have been using Splunk SOAR for one and a half years.

What do I think about the stability of the solution?

Splunk SOAR is stable and scalable as the number of alerts, users, integrations, and playbooks increases. With proper infrastructure sizing and configuration, we can handle higher workloads without significant impact on performance.

How are customer service and support?

Overall customer support is quite good.

Which solution did I use previously and why did I switch?

We have not used any previous solutions.

How was the initial setup?

The setup is quite easy. Once the team understands the workflow, we usually start with existing playbook templates and customize them according to our SOC requirements. The main challenge is the API permissions and authentication and differences between the tool integrations. Playbook troubleshooting can also take time when an integration fails, but overall, the customization is manageable.

What was our ROI?

We have seen a return on investment as many tasks were automated and this has reduced our time significantly. It has reduced our manual efforts by approximately 20 to 30 percent.

Which other solutions did I evaluate?

I am not familiar with this area as it comes under management. The team might have, or might not have thought about other products as we were already using Splunk as SIEM. Splunk SOAR was the only product that we evaluated, or might have evaluated.

What other advice do I have?

Splunk SOAR's AI governance and security are overall good. From the SOC's perspective, access control, data protection, audit logging, and human validations are important. I would use AI to assist investigations, but I keep analyst approval for critical response actions.

The accuracy and reliability are quite good, as it is reliable in assisting with alert analysis, summarization, and alert investigation. However, I do not depend on it alone for critical decisions. I validate the output against the logs, threat intelligence, and other security evidence before taking any actions.

In this project, whenever we create new playbooks, we directly involve our analysts in that. We tell them what the playbook is and how it works, and after that, they start using it. We had only one session, but before joining the projects, analysts have to complete courses on Splunk SOAR so they will understand it later. We continuously train the analysts as soon as we create a new playbook.

Splunk SOAR has definitely improved our team's ability to investigate and respond. Splunk SOAR provides the centralized incident view and enrichment results and actions from different tools. For cloud-native environments, visualization is fairly easy once the integrations are configured. The main challenge is troubleshooting API or integration failures. Overall, it has improved visibility and helped us remediate threats faster.

Before starting, begin with repetitive high-volume tasks such as IOC enrichment and tickets. Look at what the use cases are and what things you can automate. Start with simple playbooks, validate the integration and permissions, and then gradually automate more complex response actions. Keep human approval for critical containment actions.

I would rate this product a 9 out of 10.

Which deployment model are you using for this solution?

Private Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Aug 12, 2026
Flag as inappropriate
PeerSpot user
Vikas Pandita - PeerSpot reviewer
Global Head Of Security Architecture Digital & Technology at Aramex
Real User
Top 5
Apr 16, 2026
Automation has transformed phishing, brute force, and malware response while cutting hours to minutes
Pros and Cons
  • "I have saved much time thanks to Splunk SOAR's impact, where earlier, without autonomous monitoring, users took almost one day or two days; now, a twenty-four hour job is done in almost thirty minutes."
  • "From the improvement point of view regarding Splunk SOAR, I suggest including more types of LLM models such as autonomous AI models including Anthropic and Opus 4.6, as well as creating a playground for new users to work on these, which will significantly help solve complex problems and assist new companies in understanding how Splunk works easily."

What is our primary use case?

The use cases that I work with mostly in Splunk SOAR include phishing email responses automation, where Splunk detects suspicious indicators such as the URL, IP, and geolocation from reputed VirusTotal or Hybrid Analysis, blocks the email directly on the gateway, quarantines it, and creates an incident if integrated with ServiceNow or other SIEM tools.

A second use case is brute force attack detection, where Splunk SOAR detects multiple login failure attempts, checks the intel to auto block the IP on the firewall, and locks the user, asking them to change their credentials.

A third use case involves malware endpoint detection, where an alert detected in an endpoint leads Splunk SOAR to isolate the endpoint, kill the malicious process, collect forensics, and notify the SOC team.

What is most valuable?

I value the Threat Intelligence Enrichment feature most in Splunk SOAR, where Splunk detects suspicious IPs and domains, scoring those IPs, geolocation, history, and activity, as well as vulnerability management that finds many critical vulnerabilities and maps them, making the job very easy; earlier, it took me two days to do this job, and now it takes only about one hour or fifty minutes.

Splunk SOAR has indeed helped improve my organization's business resilience through centralized log management, providing pre-built dashboards, threats, trends, and alerts on time; the strong saved queries in SPL allow us to automate monitoring, incident response, and create a backup plan, significantly reducing manual effort and improving the response time, thereby ensuring our business continues running without interruption.

What needs improvement?

From the improvement point of view regarding Splunk SOAR, I suggest including more types of LLM models such as autonomous AI models including Anthropic and Opus 4.6, as well as creating a playground for new users to work on these, which will significantly help solve complex problems and assist new companies in understanding how Splunk works easily.

I think the pricing and licensing of Splunk SOAR are good, but from the price point of view, it is necessary to ensure that deduplication of alerts does not exist, and that recommendations are provided to further reduce cost optimization.

Regarding the scalability of Splunk SOAR, I think you can utilize greater LLM models coming to the market to make it more scalable, faster, and optimized.

For how long have I used the solution?

I have been working with Splunk SOAR for almost the past six or seven plus years as I have been a Splunk user from the very beginning, creating playbooks of Splunk and utilizing that, and now the Splunk SOAR orchestration part has become very clean.

What do I think about the stability of the solution?

I find Splunk SOAR very stable and reliable, utilizing playbook patterns and a maturity model, along with threat intelligence integration with other tools, as it has a good marketplace capable of fetching data and more.

I have not encountered any outages or glitches within my experience with Splunk SOAR.

What do I think about the scalability of the solution?

Regarding the scalability of Splunk SOAR, I think you can utilize greater LLM models coming to the market to make it more scalable, faster, and optimized.

How are customer service and support?

I have worked with Splunk SOAR's technical support or customer service, which I find to be as perfect as Splunk SIEM; I would rate them an eight out of ten.

Which solution did I use previously and why did I switch?

Before Splunk SOAR, I did not use SentinelOne much, but there were some use cases in Sentinel for anomaly detection that I utilized; however, Splunk performs better in terms of phishing analysis and other related areas.

How was the initial setup?

Splunk SOAR was already implemented when I started working at my current company.

What other advice do I have?

Splunk's unified platform absolutely helps me consolidate networking, security, and IT observability tools, enabling collaboration in a single dashboard from the NOC and SOC perspectives to mitigate metrics related to application and data utilization and kill unknown processes from the CPU to keep the server and production running smoothly.

I have saved much time thanks to Splunk SOAR's impact, where earlier, without autonomous monitoring, users took almost one day or two days; now, a twenty-four hour job is done in almost thirty minutes.

An example where automation saved my team and helped prevent a critical security incident involves phishing email analysis; before automation, analysts manually reviewed emails, checking URLs and IP addresses, which took almost one hour, but after executing a playbook in Splunk, it automatically detects indicators such as URLs and malicious IPs, blocking them from the firewall and quarantining emails in less than a minute, reducing what took two to three hours for L1 analysts to less than a minute.

Splunk SOAR is deployed on the cloud as well as Splunk Enterprise. I rate this product a nine out of ten overall.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Apr 16, 2026
Flag as inappropriate
PeerSpot user
Anisha Rice - PeerSpot reviewer
Data Analyst at BAE Systems
Real User
Top 20
Sep 16, 2026
Automation has reduced unused dashboards and reports and now creates detailed incident tickets
Pros and Cons
  • "The main benefit of using Splunk SOAR is the automation, as a job that would have been very tedious for an analyst to do in terms of removing all the dashboards that haven't been used is now saving space and saving money."
  • "The connections have been challenging. I feel that with Splunk SOAR, you need understanding and access to multiple roles."

What is our primary use case?

In my role as a data analyst, I use Splunk SOAR primarily to clean up dashboards. We had over 8,000 dashboards, and I created a playbook that deletes dashboards that haven't been used in the last six months. I also use it to delete reports that haven't been used in the last six months. Additionally, I use Splunk SOAR to kill searches that are hurting the system.

When a certain event happens and we need a Jira ticket created for it, Splunk SOAR can automatically create those tickets without a person sitting there creating the ticket manually. It can pull all the information and populate it in Jira.

What is most valuable?

The connection to other apps and the automation are important, allowing me to respond to events automatically when our analysts are present.

The main benefit of using Splunk SOAR is the automation. A job that would have been very tedious for an analyst to do in terms of removing all the dashboards that haven't been used is now saving space and saving money. We went from having over 8,000 dashboards to now 4,000 dashboards. It is constantly deleting, and we fixed that threshold, so that is a significant savings. Additionally, time is saved because before, we had to sort through many dashboards looking for the one we actually needed, but now it is easier to find the ones that we want.

Creating the Jira ticket alone is beneficial because when an analyst comes in and there was an incident overnight, the Jira is already populated, and they can immediately get to work instead of trying to figure out what happened and doing the digging themselves. The information is already there, and they can begin troubleshooting.

What needs improvement?

The connections have been challenging. I feel that with Splunk SOAR, you need understanding and access to multiple roles. As an analyst, I do not have the administrator access that I may need to get these connections set up, or even the knowledge to have it set up. There is a learning curve there, but I work with other teams to get it done.

The custom functions help with the limitations. I do not think there are any major limitations.

Connecting the apps is challenging. That is the only issue; I feel that you need knowledge of multiple roles to really set it up and use it effectively.

For how long have I used the solution?

I have two years of experience.

Which solution did I use previously and why did I switch?

We did not have another solution. We were previously doing things manually.

What other advice do I have?

I use all of its features. I find it challenging. I work with AWS. I continue to work with other teams to get it done. I cannot think of any limitations. I did not deploy it. I would rate this product an 8 out of 10.

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Sep 16, 2026
Flag as inappropriate
PeerSpot user
Hamada Elewa - PeerSpot reviewer
System Engineer - Security Presales at Raya Integration
Real User
Top 5
Oct 29, 2025
Creating automation workflows has reduced detection time but integration and visibility challenges remain
Pros and Cons
  • "Splunk SOAR helps reduce my mean time to detect significantly and enhances it very well; it reduces the mean time to detect by approximately 70%."
  • "Splunk SOAR does not help me reduce my security event volume; in fact, it makes them massive."

What is most valuable?

The most valuable feature I find in Splunk SOAR is the ease of creating playbooks.

Splunk SOAR helps reduce my mean time to detect significantly and enhances it very well. It reduces the mean time to detect by approximately 70%. It has also helped me reduce my mean time to resolve by the same value.

What needs improvement?

The visibility of Splunk SOAR's playbook viewer is rather unclear to me; I wonder what the visibility is for.

There are indeed some problems with integrating Splunk SOAR with other Splunk products or other vendors in my system, and it took a while after implementing Splunk SOAR to train my SOC team on how to use the playbooks.

Splunk SOAR does not help me reduce my security event volume; in fact, it makes them massive.

Splunk SOAR does not help me free up resources to work on other projects; they are not good in this regard.

I have not seen time to value with Splunk SOAR; I am curious about what time to value means.

I believe Splunk SOAR can be improved by adding more integrations and out-of-the-box integrations, and by increasing the number of admins that can access the solution simultaneously. I see the need to inject more AI in creating the playbooks.

I think they can inject more threat intelligence into the solution.

For how long have I used the solution?

I have been dealing with Splunk SOAR for around two years.

How are customer service and support?

My experience with the technical support by Splunk has been quite positive; I would rate them at 80%.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Before implementing Splunk SOAR, my team did not use a commercial or open-source solution to help guide our SecOps teams; they were using XSOAR from Palo Alto and FortiSOAR from Fortinet.

I did not switch to Splunk SOAR; I am still using both solutions.

How was the initial setup?

My experience with the implementation and configuration of Splunk SOAR is that it is seamless and not complex. I can find complexity in something such as XSOAR from Palo Alto.

If you are talking about the implementation duration for Splunk SOAR with about six playbooks, it can take around 30 man-days.

What other advice do I have?

I would assess Splunk SOAR's ability to integrate with other systems and applications as very relevant in my environment.

I view Splunk as a platform; I can definitely consider Splunk as a platform. It is not only a SIEM or a SOAR; it is a complete platform. They are increasing the modules integrated with it, so I can give them a rating between 80 to 90%.

My experience with the pricing of Splunk has been that in the past, they were very expensive, but now they can compete with even FortiSOAR or FortiSIEM. The difference in pricing is very good right now.

I would usually recommend Splunk SOAR for customers who do not have the knowledge or the maturity level required for acquiring a native SOAR.

If companies are new to SOAR technology, they can use Splunk SOAR, but if they are at a very good maturity level, they can use something such as Palo Alto. I would rate this review at 7 out of 10.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Vikas_Tiwari - PeerSpot reviewer
Citius Tech at a outsourcing company with 5,001-10,000 employees
Real User
Top 5
May 26, 2026
Security workflows have been automated and incident triage is now streamlined through dashboards
Pros and Cons
  • "Splunk SOAR is very good and very efficient; the UI is very good, and that way we don't have to struggle with a lot of pages because everything is on the dashboard and every detail is just a click away, which saves a lot of time compared to other SOAR solutions whose UIs are quite complex."
  • "Technical support can be improvised more. That is one area where I feel the team is sometimes struggling."

What is our primary use case?

Splunk SOAR has been in use for almost seven or eight years.

What is most valuable?

Splunk SOAR is very good at doing correlation. They handle the triage and correlation aspects very efficiently compared to other SOAR solutions in the market. Because the base of Splunk is data-driven, Splunk SOAR is the first solution which created the foundation based on the database and data-driven triage and identification. That is something we liked a lot.

Splunk SOAR definitely helps because there are many connectors available which we can integrate with different devices, whether it's network devices, firewalls, servers, or access points. All of those we can integrate and we can give a single pane of glass view of the health check on all the security devices running in the environment.

Splunk SOAR is very good and very efficient. The UI is very good, and that way we don't have to struggle with a lot of pages. Everything is on the dashboard and every detail is just a click away. That way it saves a lot of time. If you look at other SOAR solutions, their UI is quite complex, and you have to navigate a couple of pages to get into the bottom of the problem or the issues. That way I think it's very handy and convenient in Splunk SOAR.

It saves time in many aspects and is very efficient in many aspects. Because you get to know the issues very quickly via a dashboard, then you will have a quick option to allocate this to the engineering team or the concerned department to work on that issue and resolve it. Then you also have an option to collaborate on the same SOAR platform with a cross-functional team to understand the issue in detail. After that, there is an option for the root cause analysis and creating the report and sharing it with management. All of these things are available on Splunk SOAR which makes it very user-friendly.

What needs improvement?

Splunk SOAR can use generative AI more extensively in terms of creating the reports which can be presented to the top leadership. There are other couple of items they can do. I don't have an immediate suggestion. I think a brainstorming session on each of the aspects of the product would be beneficial. There is an additional possibility to infuse generative AI in terms of creating reports and improvising some of the more functionalities.

Technical support can be improvised more. That is one area where I feel the team is sometimes struggling. Response time is also good, but the quality I would say can be improvised.

What do I think about the stability of the solution?

The initial setup is not very simple. This is one aspect which is not very simple initially. It requires a lot of work in the beginning but it's still not so bad. It's very competitive compared to other SOAR solutions.

What do I think about the scalability of the solution?

This solution is very much scalable, so I would rate it a ten.

Which solution did I use previously and why did I switch?

Microsoft Sentinel is the competitor I would say. If you see in a lot of cases where Microsoft is the cloud, they are able to succeed with their Sentinel. However, if I have to make a personal choice, I would go with Splunk SOAR because the expertise is quite good.

How was the initial setup?

We have done the automation, and many security incident tickets that get created can automatically route to the available engineer and the entire process is automated. That's one area which we see. Then there are certain thresholds that we have set up. We can set up the policy that if there is a certain threshold for a particular element to escalate the thing, that can be created in a time-bound manner. If you want to revise your policy and revisit at a certain point of time, you can do that also. You can automate that piece of work as well.

What's my experience with pricing, setup cost, and licensing?

The pricing is quite high. Splunk SOAR is high priced, but their product is also a market leader, so that way it is good.

What other advice do I have?

In most of the cases, we do it via the expert consult agency. We outsource it most of the time. There are a few elements where we own the responsibility, but the majority of the elements will be taken care of by the expert outside resources. I would rate the overall experience somewhere between eight to nine.

Everything is cloud-based now. I have been using Splunk SOAR for 16 years. My overall rating for this product is nine.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: May 26, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Download our free Splunk SOAR Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2026
Buyer's Guide
Download our free Splunk SOAR Report and get advice and tips from experienced pros sharing their opinions.