What is our primary use case?
I primarily use Splunk SOAR for security incident response automation, alert triage, and orchestrating automation remediation workflows.
For example, I use Splunk SOAR to automatically enrich security alerts, investigate suspicious IPs, and trigger actions such as blocking malicious IPs and requests and isolating affected endpoints based on predefined playbooks and APIs.
I also use Splunk SOAR to reduce manual investigation and testing and to standardize incident response while improving response time through automated playbooks and integrations.
One success story involved automating suspicious IP investigation and blocking through a Splunk SOAR playbook, which reduced the response time from several manual steps to a few minutes. It saved the team significant time and potentially prevented malicious activity before it could impact other systems.
What is most valuable?
The best features of Splunk SOAR, in my opinion, are automated playbooks, integrations with security tools, alert enrichment, and automated response remediations, which help reduce manual effort and speed up incident response.
I rely mostly on automated playbooks because they streamline repetitive investigation and response steps, help ensure consistent handling of incidents, and significantly reduce manual efforts and response time.
Another useful feature is case management and investigation tracking, which helps maintain investigative context, document actions, and coordinate response activities efficiently.
Splunk SOAR has positively impacted my organization by reducing manual effort on incident response time by automating repetitive security tasks, improving response consistency, and enhancing overall SOC efficiency.
What needs improvement?
I would like to see easier playbook development, better troubleshooting, debugging, and more intuitive improved integrations and documentation, which would also make automation easier to maintain. If there is a good idea on it, it will be easy to go through it.
Better playbook debugging and error handling would help, especially for complex workflows. More detailed execution logs and simple integration configuration would also improve day-to-day use cases.
I think Splunk SOAR's AI capabilities have strong governance and security with an emphasis on transparency, privacy, and secure data, but I would still like more granular control over AI from the auditability and automation actions.
The output from Splunk SOAR is generally accurate and reliable, especially for SPL generation and security analysis, but I still validate generated results before using them in production because occasional hallucinations or incorrect queries can occur.
For how long have I used the solution?
I have been using Splunk SOAR for approximately 1.8 to 2 years.
Buyer's Guide
Splunk SOAR
August 2026
Learn what your peers think about Splunk SOAR. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,683 professionals have used our research since 2012.
What do I think about the stability of the solution?
I would consider Splunk SOAR stable and reliable for our production use, as we have found it dependable in running automated playbooks and integrations with good system health monitoring and troubleshooting.
What do I think about the scalability of the solution?
Splunk SOAR's scalability allows it to handle increasing volumes and automation work by scaling through additional resources, distributed deployments, and integrations as the security environment grows.
How are customer service and support?
I rate customer support an 8 out of 10, as the support team is responsive and helpful for technical issues, especially with integrations and troubleshooting, although complex cases can take time to resolve. Splunk also provides a support portal and documentation for troubleshooting.
Which solution did I use previously and why did I switch?
We previously relied more on processes and separate security tools for alert investigation and response. We moved to Splunk SOAR to centralize workflows, automate tasks, and reduce incident response time.
How was the initial setup?
The pricing and license for Splunk SOAR were reasonable for the value provided, although the initial setup and integration required some planning, with the main effort centered around configuring integrations.
What about the implementation team?
We only have a customer relationship with the vendor and are not a partner, reseller, or distributor.
What was our ROI?
We have seen a positive return on investment mainly through time savings rather than reducing headcount, as automation has reduced repetitive security work by roughly 30 to 40%, saving around 10 to 15 hours per week for the team. Incident response time has also improved by approximately 25 to 30% due to automating enrichment, investigation, and response steps. The saved capacity allows analysts to focus on threat hunting, complex investigations, and security projects, offering the biggest financial benefit from getting more done with the same team size and resources.
Which other solutions did I evaluate?
Before moving to Splunk SOAR, we evaluated several tools and applications, such as Palo Alto Cortex, XSOAR, IBM Resilient, and Swimlane before making our choice.
What other advice do I have?
Splunk SOAR integrates well with our existing security tools through its wide range of apps and APIs, making it easy to exchange alerts, enrich data, and connect systems.
Splunk SOAR has saved us roughly 10 to 15 hours per week by automating repetitive investigations and response tasks, thus allowing the team to focus on higher priority security problems.
Splunk SOAR has helped us consolidate several security tools into centralized automation workflows, connecting SIEM and endpoint security, reducing the need to manually switch between multiple console investigations and centralizing alerts to increase investigation and response actions through playbooks. Overall, it has improved operational efficiency and made the security workflow more consistent.
Splunk SOAR has significantly improved our ability to investigate and remediate threats by centralizing alerts and automating responsive workflows. Playbooks provide good end-to-end visibility into the investigation steps and actions taken. For our on-premises environment, troubleshooting is generally straightforward because the execution logs make it easy to identify failed actions, although complex playbooks and integrations can sometimes require additional troubleshooting. Overall, threat investigation and remediation are faster, more consistent, and easier to manage.
Splunk SOAR is a stable and reliable security automation platform. Its playbooks and integrations significantly reduce manual work, improve response times, and provide consistent incident handling. I would rate it around 8 out of 10.
I recommend Splunk SOAR for organizations looking to automate security operations and reduce manual efforts. It is best to start with a few high-value use cases, validate integrations, and gradually expand playbooks as the team becomes comfortable with the platform.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.