Try our new research platform with insights from 80,000+ expert users
SAURABHYADAV4 - PeerSpot reviewer
Consultant at a tech vendor with 10,001+ employees
Real User
Top 5
Jun 10, 2024
Enables optimization by reducing manual intervention and increasing automation in the workflow
Pros and Cons
  • "The product provides 100% automation for certain processes."
  • "The solution must provide more AIOps to improve predictability."

What is our primary use case?

I use the solution for incident response and automation.

How has it helped my organization?

The product helps with workflow reduction. The manual efforts required have been reduced. It contributes to optimization. The extent of workflow reduction varies depending on the instance. Manual intervention is required for critical processes. If it is not critical, we can automate it.

What is most valuable?

The product provides 100% automation for certain processes. It needs no manual intervention. We can integrate various tools like VirusTotal and ServiceNow. We can automate all the tasks. It is one of the best things about the tool. It also provides workforce protection.

Whenever we get any alerts or make any configurations, we develop workflow automation using the playbooks. We can fully automate some of the security incident resolutions. We can also do identification and redirection using the product.

I have integrated Splunk Phantom with Splunk Cloud. Previously, I used it with Splunk on-premise to get the logs into Splunk for tracking and audit purposes. Since Splunk is a SaaS-based product, it has certain maintenance windows. Over time, the vendor does some maintenance during off-production hours.

Creating playbooks using the solution’s playbook editor is not tough. For someone who knows the solution, I rate the ease of creating playbooks as four out of five. The solution’s playbook viewer provides full visibility. The product provides different integrations. We can easily integrate the tool with VirusTotal, ServiceNow, and the asset and identity management system.

The product is somewhat easier to use in an investigation. We have been able to identify the false positives using the product. The tool has helped reduce false positives by 30%. Splunk SOAR has helped reduce our mean time to detect by 10% to 15%. Splunk SOAR has a major impact on our meantime to resolve. Our mean time to resolve has been reduced by 35% to 40%.

I have integrated VirusTotal with Splunk SOAR. Instead of doing manual checks, I can easily get the score by integrating the tool with Splunk SOAR. I have also synced Active Directory with the asset and identity management system.

It's been a long time since we have implemented Splunk SOAR. It brings value to our organization. Before Splunk SOAR, everything was done using manual intervention. We had to educate the SOC team on how to do tasks. We also had to create playbooks for them. With Splunk SOAR, we only have to educate the team about how things are done so that they can perform a manual intervention when there is a failure, which is rare.

After deploying the product, we had to provide some training to the SOC team. After getting trained, it was hands-on. Along with other Splunk solutions, Splunk SOAR provides the resilience to face any issues and hardships. We easily cope with downtimes.

Splunk SOAR offers us end-to-end visibility across our environment. It depends on how much we utilize it. Visualizing and troubleshooting our cloud-native environment using Splunk SOAR is somewhat easy. I have to coordinate with the Phantom administrators if there is any issue. I work mostly on playbook development and integrating it with security instances.


What needs improvement?

The solution must provide more AIOps to improve predictability.

Buyer's Guide
Splunk SOAR
December 2025
Learn what your peers think about Splunk SOAR. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,259 professionals have used our research since 2012.

For how long have I used the solution?

I have been using Splunk SOAR for three to four years.

What do I think about the stability of the solution?

The tool is stable because it is completely SaaS-based.

What do I think about the scalability of the solution?

The SOC and engineering teams use the solution. The engineering team uses it to automate tasks. We have around 30 to 40 users. We were not using the tool completely initially. Once we started using it, we scaled it. We have also increased the number of product licenses. Our clients are enterprise-level businesses.

How are customer service and support?

I've been using Splunk products for a long time. Overall, I am pretty satisfied with the quality of service of the support team.

How would you rate customer service and support?

Positive

How was the initial setup?

Splunk SOAR is SaaS-based. The deployment takes a few months to stabilize. We have a Splunk team that manages the deployment. Two to three people are involved in the deployment.

What's my experience with pricing, setup cost, and licensing?

Everything good comes with a price. The tool is not cheap. However, if we use it to its full potential, it will be beneficial.

What other advice do I have?

Overall, I rate the product an eight out of ten.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Jay-Panchal - PeerSpot reviewer
Information Security Analyst at a healthcare company with 1,001-5,000 employees
Real User
Top 10
Sep 11, 2024
It's a powerful tool that can monitor our servers and improve our web business by reducing security threats
Pros and Cons
  • "Splunk has many features that make work easier, and it's simple to implement in a large production environment. Splunk collects a massive amount of data from cloud servers and handles it perfectly."
  • "The dashboard could be improved and some other features. SOAR should integrate network capabilities, allowing us to also monitor the WLAN network. Splunk is also expensive and difficult for beginners to learn. It's hard for a new user to figure out how to visualize old threat data. It took two to three months to learn with hands-on experience how to use the dashboard, visualize events, and analyze threats."

What is our primary use case?

I use Splunk to detect threats and conduct threat analysis. The solution monitors, models, and analyzes all security events in our cloud environment's production areas and mitigates threats.

How has it helped my organization?

Before we used Splunk SOAR, we didn't know how much traffic was coming in or what security threats were happening on our servers. We could not monitor the entire production environment. Splunk enables us to perform monitoring, threat hunting, threat analysis, and reporting on the risks and impact on our business. 

Splunk improves our business resilience because it's a powerful tool that can monitor our servers and improve our web business by reducing security threats.  Before Splunk, security threats heavily impacted our production environments. 

In the past, we had to monitor all our servers manually, but now that we have implemented SOAR in our production environment, we no longer need to monitor everything 24/7. It sends alerts to our emails, saving us time that we can spend on other tasks. It reduces our monitoring time by about 50 percent. Splunk speeds up our response time by 20 percent. 

Splunk can integrate and manage multiple solutions simultaneously. It has reduced our alert volume and improved our security. We can show our clients that we're monitoring all the production environments and mitigating events as they happen. It has improved our security posture and reduced the risk.

What is most valuable?

Splunk has many features that make work easier, and it's simple to implement in a large production environment. Splunk collects a massive amount of data from cloud servers and handles it perfectly. 

It manages the whole thread of data security logs and visualizes the data, making it easier to view everything. Splunk gives you end-to-end visibility of your on-prem environment, enabling you to troubleshoot issues easily. 

Splunk integrates easily with the AWS cloud and also other clouds like GCP and Azure. It quickly and efficiently captures all the logs from the cloud just like it was capturing logs from your on-premises environment.

What needs improvement?

The dashboard could be improved and some other features. SOAR should integrate network capabilities, allowing us to also monitor the WLAN network. Splunk is also expensive and difficult for beginners to learn. It's hard for a new user to figure out how to visualize old threat data. It took two to three months to learn with hands-on experience how to use the dashboard, visualize events, and analyze threats. 

For how long have I used the solution?

I used Splunk SOAR for about a year at the company I just left. 

What do I think about the stability of the solution?

I rate Splunk SOAR eight out of 10 for stability. 

What do I think about the scalability of the solution?

I rate Splunk SOAR nine out of 10 for scalability.

How are customer service and support?

I rate Splunk support eight out of 10.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I previously worked with Wazoo, and Splunk is a much better SOAR solution. 

How was the initial setup?

Splunk SOAR is deployed on the cloud. The initial deployment wasn't complex, but implementing it on our production servers was a bit difficult because we had to deploy agents to more than 60 servers. It requires a little maintenance, such as upgrades and changing the dashboard. Installing it to a new production server takes a day to reconfigure. 

What was our ROI?

Once Splunk is fully deployed, we can realize the full benefit. Implementing the solution across all our servers took a week.

What's my experience with pricing, setup cost, and licensing?

I rate Splunk SOAR two out of 10 for affordability. Splunk is a fast enterprise tool, but it costs too much. At the same time, it's worth what we pay, in my opinion. We can efficiently perform all the functions and tie together the data. It's the perfect tool for our needs. 

What other advice do I have?

I rate Splunk SOAR eight out of 10. I recommend Splunk if the company can afford it. It's suitable for a large organization that requires security monitoring. It's the best tool for threat hunting and analysis. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Splunk SOAR
December 2025
Learn what your peers think about Splunk SOAR. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,259 professionals have used our research since 2012.
Amit Moralwar - PeerSpot reviewer
Senior Information Security Engineer at a tech company with 10,001+ employees
Real User
Top 20
Jun 2, 2024
Provides a user-friendly GUI, and reduces manual work, but the playbooks have room for improvement
Pros and Cons
  • "Splunk SOAR's extensive library of pre-built integrations allows it to connect with a vast array of popular security and IT applications, streamlining workflows across our existing security stack."
  • "Various aspects of the playbook development process itself can be optimized."

What is our primary use case?

I use Splunk SOAR to create automation for our SOC team. These automations integrate with third-party applications, which is a key requirement for our SOC.

How has it helped my organization?

Splunk makes creating playbooks simple with its GUI. We can build playbooks by dragging and dropping different elements, eliminating the need for complex coding.

The visibility of the playbook viewer is good. We can add custom code while developing the playbook if required.

Splunk SOAR provides end-to-end visibility into our environment.

Troubleshooting our cloud-native environment with Splunk SOAR is a breeze thanks to its intuitive graphical interface. Unlike traditional tools requiring command lines, Splunk SOAR lets us manage integrations and cloud access entirely within the user-friendly GUI, streamlining the process.

Splunk SOAR has significantly reduced our manual workload by automating many previously time-consuming processes. We only began to see the full benefits after about five months.

Splunk simplifies security investigations by offering pre-built processes and leveraging the rich functionality embedded within Phantom's alerts. This combination provides a powerful toolkit for investigators.

Splunk SOAR has significantly improved our security alert resolution efficiency. While the specific time saved depends on the individual case, we've seen a general reduction in resolution time from around 20 minutes to five minutes thanks to the variety of use cases it supports.

Splunk has reduced our mean time to detection by 15 minutes.

Our mean time to resolution is now down to five minutes.

Splunk SOAR streamlined our security operations by consolidating multiple tools. We've successfully integrated and replaced approximately 15 individual applications into a more unified environment.

What is most valuable?

The most valuable features are the third-party integrations and the playbook development that can be done using Python.

Splunk SOAR's extensive library of pre-built integrations allows it to connect with a vast array of popular security and IT applications, streamlining workflows across our existing security stack. This includes tools like Salesforce, Microsoft Outlook, and abuseIP, empowering our organization's SOC and security teams to leverage these familiar applications within SOAR's automation and orchestration capabilities.

What needs improvement?

Playbooks offer significant room for improvement, as custom code is often required during development. Various aspects of the playbook development process itself can be optimized.

For how long have I used the solution?

I have been using Splunk SOAR for one and a half years.

What do I think about the stability of the solution?

Splunk SOAR is extremely stable.

What do I think about the scalability of the solution?

Splunk SOAR is scalable to our needs.

How are customer service and support?

The technical support is good.

How would you rate customer service and support?

Positive

What other advice do I have?

I would rate Splunk SOAR five out of ten.

Early on, we encountered some issues automating tasks with playbooks. However, a recent Splunk version upgrade resolved those problems.

We have 50 users spread across different regions.

The resilience of Splunk SOAR is great.

A thorough evaluation of the SOAR landscape is recommended to identify the best fit for your needs. If Splunk aligns with your requirements after this assessment, it can be a strong option.

Which deployment model are you using for this solution?

On-premises
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Rodrigo Scorsatto - PeerSpot reviewer
Senior Principal Site Reliability Engineer at a tech vendor with 10,001+ employees
Real User
Top 20
Dec 26, 2025
Data Enrichment and Auto-healing for IT Operarions
Pros and Cons
  • "SOAR allows custom code to be written and integrates with various technologies through pre-built apps like Windows Remote Management or custom apps we can build ourselves like a secret retrieval app from our vault."
  • "While there have been improvements to the investigation process, particularly with the playbook data, the current log review method is cumbersome."

What is our primary use case?

Splunk SOAR, formerly Splunk Phantom, is a powerful automation platform with a high security focus, but it is also usable for any other general tasks such as putting a server off the network, restarting services, performing health checks, performing data enrichment by collecting information from different sources and combining, analyzing, and providing precise information about several topics. It has a variety of options, and what can stop you is just your creativity.

How has it helped my organization?

Splunk SOAR has a user-friendly interface that simplifies playbook creation. While some initial training is helpful, the drag-and-drop functionality and pre-built code generation features make it accessible even for those without extensive coding experience. This ease of use allows teams to quickly automate incident response tasks, reducing the business impact.

Splunk SOAR helps us improve our data collection and automate operational tasks. While it enriches data, some actions require approval or additional information. For application outages, immediate action is crucial to avoid business impact, and time to respond is key to be able to identify the root cause of issues. For example, if a database server goes down, if the analyst doesn't check the issue right after it occurs, they may end up losing precious logs, which would help them identify the issue and avoid reoccurrence. Additionally, manual database tasks like service restarts or log checks are time-consuming. Splunk SOAR automates these tasks, enriching our log collection, running health checks, and generating reports for the database team. This allows for faster issue identification and resolution, ultimately contributing to high system availability and minimal customer impact.

It provides a comprehensive solution for our environment's health. Splunk offers two key products: Splunk as an observability tool that detects critical issues, and Splunk SOAR, an automation platform that enriches data and even automates remediation actions.

SOAR offers easy integration with various tools. We can leverage pre-built apps for common integrations or create custom ones. While Splunk integrations are automatic, SOAR's API allows us to send data from any observability tool using the SOAR API. This API offers different options to manage the platform, and one of the options is to create a container in SOAR, which can trigger the appropriate playbook based on a label name, simplifying integration with new tools and accelerating proof-of-concept deployments.

Implementing a SOAR platform significantly improved our IT operations. Previously, frequent application downtime overwhelmed our busy operations team, forcing them to prioritize and leave some issues unresolved. SOAR automation relieved this pressure by allowing us to create playbooks that automatically detect and fix recurring problems. While the initial setup required developing playbooks and standards, the resulting reduction in alerts and faster issue resolution freed up the operations team's time and had a major positive impact on our overall IT environment.

Our mean time to detect is within seconds. Before SOAR, manually detecting and resolving server issues was slow and unreliable. It could take hours for an overloaded team to identify a problem, and even longer to fix it, potentially impacting customers. SOAR automates this process, triggering immediate responses that take seconds, minimizing downtime, and ensuring a smooth customer experience.

Our mean time to resolution is improved. SOAR helps resolve issues quickly by automating tasks through playbooks. When an issue is detected, SOAR can run a playbook to fix it or provide more information to analysts, expediting resolution.

SOAR has significantly improved our efficiency by automating manual tasks. This frees our IT staff to focus on resolving issues faster and tackling more complex projects.

What is most valuable?

SOAR allows custom code to be written and integrates with various technologies through pre-built apps like Windows Remote Management or custom apps we can build ourselves like a secret retrieval app from our vault. Playbooks, built with drag-and-drop and custom functions, provide further flexibility for developers to tailor the solution to their specific needs.

What needs improvement?

While there have been improvements to the investigation process, particularly with the playbook data, the current log review method is cumbersome. Scrolling through massive, unsearchable logs is inefficient. Ideally, the system would offer search functionality or even AI-powered analysis to pinpoint issues quickly, saving time spent sifting through text.

SOAR's development efficiency can be enhanced by incorporating AI to assist in writing custom code, eliminating the need to start from scratch. This AI-powered approach would significantly reduce the time required to develop playbooks.

For how long have I used the solution?

I have been using Splunk SOAR for over five years.

What do I think about the stability of the solution?

SOAR is stable. In the last three years, we only had it go down twice, which was related to a server issue.  

What do I think about the scalability of the solution?

SOAR is designed to grow with our needs by allowing us to add more hardware to handle increased workloads. This makes it a good fit since scalability was a major factor in our evaluation. On top of that, SOAR's customizable platform ensures it can be tailored to our specific requirements.

How are customer service and support?

During playbook development, we encountered technical issues with the playbook feature itself, requiring vendor assistance. Their expertise was invaluable. Not only did they resolve the immediate problems, but they also proactively suggested improvements to our SOAR platform coding for better speed and overall performance.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Having experience with various automation tools, including Microsoft Orchestrator, Ansible, Rundek, I find SOAR to be the most user-friendly. In fact, after exploring most market offerings, Splunk SOAR stands out for its comprehensive feature set, surpassing any other platforms we've previously used.

How was the initial setup?

The deployment required one member from our team and one from the SOAR team.

What about the implementation team?

Implementing Splunk SOAR was made significantly easier with the support and expertise of the vendor's team. Their deep knowledge of the platform and extensive deployment experience proved invaluable, allowing for a smoother and more efficient implementation process overall.

What's my experience with pricing, setup cost, and licensing?

While the exact pricing for Splunk SOAR is not known to me, I've heard from some colleagues that it may be on the more expensive side compared to other automation tools. However, the general consensus seems to be that the investment in Splunk SOAR pays off once you start utilizing its capabilities and automating your workflows. By automating tasks and freeing up resources, Splunk SOAR can provide a strong return on investment in the long run, despite the potentially higher upfront cost.

Which other solutions did I evaluate?

I have evaluated different automation platforms, such as Microsoft Orchestrator, Ansible and Rundeck.

What other advice do I have?

I would rate Splunk SOAR nine out of ten. I am deducting one point because it is tedious to go through the logs manually.

SOAR allows for cloud and on-premise deployment, and I favor the on-premise option for enhanced security. Since some automation has extensive access to our internal systems, any internet communication during operation raises the potential for breaches.

Which deployment model are you using for this solution?

On-premises
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Last updated: Dec 26, 2025
Flag as inappropriate
PeerSpot user
reviewer2499171 - PeerSpot reviewer
Security Engineer at a retailer with 10,001+ employees
Real User
Top 10
Jun 16, 2024
Saves a lot of time and the mobile app makes it easy for our analysts to get alerted and respond
Pros and Cons
  • "Surprisingly, the mobile app is valuable because it is very convenient for our on-call analysts to respond and get alerted to security alerts and events wherever they are. We are able to harness the power of Splunk SOAR and everything that we are doing, and we are also able to alert our on-call analysts 24/7. From their mobile phone, they can respond to those alerts."
  • "Unfortunately, not all of our analysts are iPhone users or iOS users. The mobile app is only supported on iOS. Our analysts who have Android do not have that benefit. That would be a nice thing to have so that we can have it across the board and not just for iOS."

What is our primary use case?

The primary use case is for our Security Operation Center. We use it for automation and responding to some of our cybersecurity alerts. It is being used for performance enrichment and automation on those events.

We do not use Splunk SOAR to predict things or try to predict things that can happen in the future. We are mainly using it to respond to things. It is more for responding to events that have happened.

How has it helped my organization?

We implemented Splunk SOAR because we had a lot of repetitive tasks that our analysts do. In our area, it was hard, and it still is hard, to find cybersecurity graduates and analysts, so any time that we can save for our analysts can be better spent.

There has been a lot of time-saving which equals to dollars-savings for the company. We have a lot of automation of repetitive tasks and things like that. We do not have to do things manually, so it saves a lot of time for our analysts. It is hard to measure the time savings because we are always developing or trying to develop new things. We are not that far along. We have been using it for three years but we have used it in production for maybe a year and a half. There is a big learning curve, so I am still learning. 

Our cloud endeavors are still in their infancy phase. We have not even started to look at that part yet. For our on-prem environment, there is definitely an advantage. There are a lot of features and capabilities not only from a security perspective. We have real-time alerting based on the system downtime and certain logs that are collected and things like that. I am sure we can apply it to the cloud infrastructure in the future as well.

We have definitely saved a lot of time with the things that we have automated. We have probably saved the amount of one analyst in a year.

In terms of Splunk SOAR's impact on our organization’s business resilience, it is on the way to getting there. This year and next year, we will definitely set that stage. We have some initiatives that are just starting that would definitely put us into that area. We have not crossed that bridge yet.

Splunk's unified platform has helped consolidate networking, security, and IT observability tools. A simple example is the ability to use SOAR integrations and API integrations in all the different tool sets that we have. Our analysts can use those tools from Splunk instead of having to log in to each one of those tool sets to do things. It is saving a lot of time as well for our analysts.

What is most valuable?

Surprisingly, the mobile app is valuable because it is very convenient for our on-call analysts to respond and get alerted to security alerts and events wherever they are. We are able to harness the power of Splunk SOAR and everything that we are doing, and we are also able to alert our on-call analysts 24/7. From their mobile phone, they can respond to those alerts. They do not necessarily have to have a laptop with them. That is one of the most convenient features or parts of Splunk SOAR that we use. This type of integration with the mobile app is not very common.

What needs improvement?

Unfortunately, not all of our analysts are iPhone users or iOS users. The mobile app is only supported on iOS. Our analysts who have Android do not have that benefit. That would be a nice thing to have so that we can have it across the board and not just for iOS.

For how long have I used the solution?

I have been using Splunk SOAR for three years.

What do I think about the stability of the solution?

It is very stable. It is pretty rare that it goes down. It crashed just once last week.

What do I think about the scalability of the solution?

This is an aspect that we have not yet explored. We have a single instance on-prem.

How are customer service and support?

From my experience, Splunk support has always been top-notch. I would rate them a nine out of ten. One point that is missing is because of the bad experience that we had while starting out with Phantom. It was hard for the support to assist us. There were definitely some breakdowns in communication that resulted in delays.

Which solution did I use previously and why did I switch?

Before SOAR, it was called Phantom. It was the same thing, and then they changed the name of it. We did not use any other solution previously.

How was the initial setup?

It was a pretty rocky start. That was when it was Phantom, and there were a lot of problems. I had a lot of problems with Phantom. A lot of that was why we had hesitation with renewing Splunk SOAR. A lot of the problems were related to bad code and poor instructions and guidance. Some of it was things that we may not have done right, but a lot of it was related to code. It definitely got off to a rocky start. It was not as smooth as we anticipated the whole thing to be. 

Our environment is on-prem. We have some things in AWS, but I am not privy to the cloud aspect.

What about the implementation team?

We deployed Phantom ourselves.

What's my experience with pricing, setup cost, and licensing?

We renewed it this year. This year was the first time there was a dramatic increase in the price. It was kind of non-negotiable. It was just a high increase. We had internal communications, and it was definitely a surprise to us. In a short time frame, we renewed it this year. Prices are going up everywhere, but they are not always justifiable, at least not to our eyes. The pricing this year was definitely a big shock.

Instead of a gradual increase from time to time, it was just a big sticker shock increase. The price is never going to decrease again. I am not saying it was justifiable or not, but the message that was relayed to us and the unwillingness to negotiate at least to a more reasonable number were surprising.

Which other solutions did I evaluate?

The only one that we pursued was a product called Siemplify which has been bought out by Google since then. Our primary reason for going with Splunk SOAR was that we were already a Splunk customer. It made sense to wrap Splunk SOAR into that as well. We use Splunk ES. With Siemplify, the integration piece was lacking just because it was not a Splunk product.

What other advice do I have?

I would rate Splunk SOAR a ten out of ten, especially as compared to other options out there, such as XSOAR and Siemplify. A lot of my decision is based on the fact that we were already a Splunk customer, so the integration was beneficial.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
SOC analyst at a outsourcing company with 5,001-10,000 employees
Real User
Top 20
Jul 29, 2024
Enabled us to reduce the use of other tools
Pros and Cons
  • "Splunk integrates with so many products. It provides us with good information for us to be able to do our jobs."
  • "I haven't had any issues with the solution so far."

What is our primary use case?

I primarily use the solution for incident investigations. 

What is most valuable?

We can make custom playbooks and use the Playbook Editor to do so. The Playbook is my favorite feature, it's quite useful. There are a lot of automation capabilities.

Its visibility is good. It's end-to-end. We can see incidents across our environment. We've been satisfied with the level of visibility so far. 

The automation helps save us time. We've saved a lot of time researching incidents. If we do resolutions manually, it can take up to 15 minutes. With Splunk's automation and Playbook, we can resolve issues within two to three minutes. 

We have Splunk integrated with other tools and systems. Some are using, for example, Carbon Black EDR. It's very flexible. It works with various third-party tools. Which we use depends on the customer. 

The solution provides good business resilience. It helps with real-time detection and resolutions. With automation, our real-time alerting is quite good. 

Splunk integrates with many products. It provides us with good information for us to be able to do our jobs.

We have been able to reduce the use of other tools. When we use Splunk, we tend to just focus on Splunk's findings, only. We do a lot of investigations using Splunk. It makes the process easier. 

We've noticed a reduction in security event volume. It's helped us to reduce a lot. We've been able to reduce the mean time to detect by 30% to 40%. It's also helped us reduce the mean time to resolve by almost 50% to 60%. We have a lot of customers and a lot of alerts typically, so we've always had a lot to deal with. 

What needs improvement?

I haven't had any issues with the solution so far. 

For how long have I used the solution?

I've used the solution for three months.

What do I think about the scalability of the solution?

The solution is really scalable. We are using it across multiple customers and handle multiple alerts. 

How are customer service and support?

We are able to connect with support if we have issues. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Right now, we also have IBM. However, mostly, we use Splunk. Our customers prefer Splunk over IBM thanks to the playbooks on offer. The appearance of Splunk is also better. Splunk has a strong reputation in the space. It makes investigations easier.

How was the initial setup?

The deployment process is straightforward. Our deployment team will deploy it for customers. It will take two to three days, depending on our customer's servers. 

We can train employees on how to use Playbooks within two months. 

What about the implementation team?

We help our clients deploy Splunk. 

What's my experience with pricing, setup cost, and licensing?

The cost is as expected. It can be a bit high, however, we get a better rate between us and our third party. We provide services to clients if they purchase Splunk SOAR which gives them good value. 

What other advice do I have?

I'd rate the solution nine out of ten. 

Disclosure: My company has a business relationship with this vendor other than being a customer. partner
PeerSpot user
Ryan Plas - PeerSpot reviewer
SOAR Engineer at a consultancy with 10,001+ employees
Real User
Top 10
Jul 3, 2024
Offers playbook automation that helps reduce the manual and tedious work for users
Pros and Cons
  • "The most valuable feature of the solution is the playbook automation just because it allows us to reduce the manual actions that SOC has to handle."
  • "Improving the integration ecosystem can raise the quality of the bottom tier of the integrations so that they can work better out of the box."

What is our primary use case?

My company operates as an MSSP that takes care of the detection and response for our customers. Splunk SOAR is where our company does the alert processing, and it is also where our SOC does its work. I work on developing the playbooks and apps that we use.

How has it helped my organization?

The product has improved the working of our company since it has removed a lot of the tedious work that we had to do previously. Even some of the easy stuff gets automated. Our company's analysts can really focus their hours on work that requires critical thinking, creative skills, and other similar areas.

What is most valuable?

The most valuable feature of the solution is the playbook automation just because it allows us to reduce the manual actions that SOC has to handle. When it comes to some of the workbook functionality where the analyst has to take some manual action, we can guide that process through templates and other things.

What needs improvement?

I think some of the case management functionality could be improved. Improving the integration ecosystem can raise the quality of the bottom tier of the integrations so that they can work better out of the box. In general, our company is pretty happy with the tool.

For how long have I used the solution?

I have been using Splunk SOAR for four years.

What do I think about the stability of the solution?

The tool's stability is fairly good.

What do I think about the scalability of the solution?

When it comes to the scalability, I think we have seen some issues there, such as running into some hardware bottlenecks sometimes, but I am detached from that part of the deployment, so I can't go into details on the things I have seen, but I know there are some pain points for our company. As we scale up the tool in our company, we are not really sure how to scale up in a better manner.

How are customer service and support?

The customer service and technical support have been great. We had some professional support come out when we set it up, and they were super helpful in helping us with the use cases and getting us stood up quickly. When our company reached out to the support team with some technical issues, I didn't hear any complaints about the responses from their end, so I think it was good.

Which solution did I use previously and why did I switch?

I have not used any other solutions in the past.

How was the initial setup?

I have done the deployment personally in my lab but not in a production environment.

Which other solutions did I evaluate?

My company evaluated Siemplify, which is known as Chronicle SOAR. My company has also evaluated Demisto and Cortex XSOAR. Our company is heavily invested in Splunk's ecosystem, and I think that was the biggest draw, especially since we use Splunk Enterprise Security and similar tools, so adding another Splunk tool made sense for our company. I think the product felt mature, and the plug-in ecosystem was where we needed it to be, along with the ability for the community to submit and create their own integrations and apps, which was interesting for us.

What other advice do I have?

When it comes to Splunk SOAR's ability to provide end-to-end visibility into our company's cloud-native environment, I would say that we are not using the cloud portions of it. I don't know if that's super relevant to what we are doing in our organization.

I am 100 percent sure that Splunk SOAR helped reduce your mean time to resolve, but I don't have any metrics on hand but I know it has dramatically decreased.

The tool has helped with the business resilience part. I think having it as a platform has been a solid portion of the product that we offer to people.

Spunk SOAR has definitely saved my time in alert triage. When some of the tedious enrichment and lookup stuff happens, the analyst doesn't have to deal with such areas, and they can just jump in and see relevant data all in one pane of glass, which has been super helpful for speeding things up.

The unified platform helps consolidate networking, security, and IT observability tools. The consolidation of tools impacts our organization as it just helps focus the SOC analyst on a single unified place to find information. It helps keep things streamlined and regular so they know where to look for certain stuff they want. It really helps people with training. It is a really easy tool to onboard people into because everything is right there in the product itself.

The product is really great. I would love to see more SOAR innovation going into the tool, especially the on-premises version since it is what we use in our company. I feel the tool needs to encourage continuous improvements, but as a product itself, my company is really happy with the solution.

I rate the tool an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Shubham Sinha. - PeerSpot reviewer
Senior Principal Information Security Analyst at a tech vendor with 5,001-10,000 employees
Real User
Top 20
Jun 22, 2023
Helped eliminate repetitive and redundant tasks, but custom functions and reporting need a lot of work
Pros and Cons
  • "When you design a playbook, you can integrate multiple log sources and define rules... After that, the platform automatically compiles all these activities and, based on the results, the analyst only has to indicate whether the result is a true or false positive. That reduces the time and effort involved."
  • "Suppose I am initially granted user rights or analyst rights, but later on, I also get admin rights. SOAR is unable to amend the limitations of my role. I raised a support ticket with Splunk about this. They said it's a bug in their 5.3.5 version. To fix this, I had to reinstall the entire platform from scratch.."

What is our primary use case?

I'm using it mainly for SOC automation and reporting. It's for incident and threat modeling, incident reporting, and triage.

I come from a cybersecurity background and I used to work on the tickets for the security alerts we received from various sources, including Splunk and other SIEM tools. The major challenge was that we were occupied with a lot of noise and activities like validation of IP reports, DNS checks, and traffic monitoring. These were redundant activities that every analyst had to do. We wanted to stop these kinds of activities. 

How has it helped my organization?

Splunk SOAR has multiple integrations with various tools, such as VirusTotal. Once we purchased those tools from the respective owners and automated them, the kinds of redundant activities we were having to do were almost immediately stopped.

Also, the ingestion of multiple log sources together helped us eliminate false positives. Using the SOAR platform, our monthly alert count was reduced from 1,100 to 200 or 250. That was the best impact we have seen from implementing SOAR in our environment.

It has reduced our mean time to detect and mean time to respond, from 20 to 30 minutes to just 5 to 10 minutes. In cybersecurity, every moment can be a ticking time bomb for us. We need to get to a solution immediately, whenever any incident is triggered in our environment. SOAR has helped us a lot.

Using this platform has resulted in a better work-life balance for my team.

What is most valuable?

One of the features I like most is playbook creation, and custom functions are another. 

When you design a playbook, you can integrate multiple log sources and define rules. That used to be done by the analysts by going to the respective tools and doing tasks manually. Now, with playbook design, writing down those rules is a one-time activity that a SOAR admin has to do. After that, the platform automatically compiles all these activities and, based on the results, the analyst only has to indicate whether the result is a true or false positive. That reduces the time and effort involved. Our KPIs have greatly improved. An incident that used to take 15 to 20 minutes, was reduced to five minutes. This helped us speed up our response to any alert, whether it was a true positive or false positive.

Another of the best parts of the SOAR platform is its ability to integrate with other systems and applications. It provides API integrations and, through them, I can limit the rights for the tool, which is good. If I want to integrate any of the applications with CrowdStrike, but only for incident-review policies or just to review the work automation, I can grant rights only for those purposes. That is one of the best features available in SOAR. It is very easy to implement and very user-friendly.

What needs improvement?

The visibility of the solution’s playbook viewer depends on the right you assign to the analyst. SOAR has the flexibility to distinguish between the roles of analyst and owner. If the analyst's role is to just work on a ticket, they cannot view the playbook design platform. That is limited to the owner. That can be both a good and bad thing.

A major problem I have faced in SOAR's rights distribution is roles and responsibilities. Suppose I am initially granted user rights or analyst rights, but later on, I also get admin rights. SOAR is unable to amend the limitations of my role. I raised a support ticket with Splunk about this. They said it's a bug in their 5.3.5 version. To fix this, I had to reinstall the entire platform from scratch, just to amend the rights and responsibilities of one role. This bug was not fixed.

Also, the latest GUI is terrible. The previous one was better.

Another point is that while using Splunk SOAR in an investigation is not difficult, there are some complex parameters. We have SOAR case management, but the licensing is going to put a big hole in your pocket. Also, there is an issue with investigation node addition. When you are doing node additions you cannot grant the entire environment to have SOAR visibility into the incident. So when you integrate it with an ITSM tool, like ServiceNow or Jira for ticketing purposes, there is a challenge. When you do nodes for investigation on a regular basis, sometimes it does not update our ServiceNow platform, which is terrible. It is a redundant activity for an analyst to update that in the case management as well as in the ITSM tool. Although SOAR provides integration, the functionality of investigation and nodes is terrible when it comes to integration.

An additional area for improvement is custom function creation. It's terrible. A newbie cannot create custom functions right away. They would require a solid understanding first.

Also, the reporting is really awful. If I want to do a report for a customized time period, such as the last three days or the last four days, or from the 10th to the 12th of June, that is not available in SOAR at all. That kind of feature is available in Cortex XSOAR. Reporting is a real challenge.

For how long have I used the solution?

I have been using Splunk SOAR for four years.

What do I think about the stability of the solution?

It's a stable environment. I don't have any complaints about it in terms of its stability.

What do I think about the scalability of the solution?

Aside from the issue I described where I started with an analyst's role in the solution and then was granted an admin role but the privileges remained those of an analyst, and I had to reinstall the entire platform, overall, the scalability is good.

How are customer service and support?

We have contacted their tech support many times. They are readily available if I raise a P-1 ticket, because SOAR is not something we can work without. Their support is good and more capable than the SME we hired.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

Before SOAR was purchased by Splunk, it was named Phantom and that is what I have worked with most of the time. I have also worked on Demisto, which is now Palo Alto Cortex XSOAR. That was a bit more user-friendly compared to Splunk SOAR.

How was the initial setup?

The initial deployment of SOAR is very complex. In my previous company, the deployment took me almost 10 days, and that was with a Splunk SME sitting with us. We paid them money to have the SME, but even he was unable to do what we needed to be done. Later on, we raised a support ticket with them and there were multiple escalations from our upper management to the Splunk management team. They then sent a good technical guy and he fixed the issue within five minutes. Before that, we were unable to do the DR instance. It took around 10 to 15 days just to fix that.

It's very difficult to install. No newbie could install SOAR on his own. He will require support. Here, I'm specifically talking about the later versions, not Phantom, rather once it became Splunk SOAR v5.3.5.

We had three people involved.

There is some maintenance. For example, it was using Python 2.7 and then there was the decommissioning of that version and the move to Python 3.x. That meant upgrading all the playbooks.

What's my experience with pricing, setup cost, and licensing?

It's very overpriced because it is based on the number of users. There is no bulk licensing.

What other advice do I have?

My advice would be to negotiate the cost. And if your organization is on the smaller side, with between 200 to 500 employees, you should not purchase it because it will blow up your finances. A bigger environment, with 2,000-plus employees, can go with the Splunk SOAR solution.

And if you are going with this solution, you should confirm what support they are going to provide, such as whether they are going to provide training credits or not. Sometimes they don't provide Splunk credits for training. Any newbie who is going to work on this will find it terrible to work in this environment. He will not be able to work without guidance. Other SOAR solutions, like Demisto (Cortex SOAR) are very user-friendly.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
Download our free Splunk SOAR Report and get advice and tips from experienced pros sharing their opinions.
Updated: December 2025
Buyer's Guide
Download our free Splunk SOAR Report and get advice and tips from experienced pros sharing their opinions.