The automation part of the product is great.
Splunk SOAR can easily be connected with a lot of solutions that are available out there. The in-built apps are pretty useful to me.
It's easy to install and offers good documentation.
The automation part of the product is great.
Splunk SOAR can easily be connected with a lot of solutions that are available out there. The in-built apps are pretty useful to me.
It's easy to install and offers good documentation.
I don't have much experience with that. I'm not sure as I don't have much technical knowledge about SOAR in general. I have a little bit of experience with SOAR. I can't speak to any shortcomings right now.
The scalability could be better.
It's an expensive solution.
I've worked with the solution for the last year or so.
The solution is stable. There are no bugs or glitches and it doesn't crash or freeze. It's reliable.
We faced a couple of issues scalability-wise, I would say it is average.
I've never contacted technical support. I wouldn't be able to comment on their level of helpfulness.
The solution's initial setup is easy and straightforward. They do offer great documentation, which helps with the process.
I'm not sure how many people were involved in the deployment or maintenance of the product.
I can't speak to if consultants or integrators were involved. I just have general knowledge of the setup and the solution itself.
I use a trial version, not an actual version. We are partners. We have our work license. My understanding is that the cost is pretty high compared to others, however, I'm not sure of the exact price.
Users just need to pay for their package. There are no add-on costs on top of that.
I'm not able to compare it with other solutions as I don't have experience with other solutions.
We're a Splunk partner.
I'm dealing with the latest version of the solution.
I'd recommend the solution to companies just starting out.
I would rate the solution eight out of ten.
Splunk SOAR can be deployed on-premise and in the cloud.
The most valuable features of Splunk SOAR are the easy integration with other solutions, including other Splunk solutions. The most important playbooks we need on the market come already on the Frontend. However, nowadays, Splunk changed its name, it's not Frontend anymore, it's Splunk Store. This is a very strong point.
I have been using Splunk SOAR for approximately two years.
We have approximately six users from one client and four from another client using Splunk SOAR.
The technical support from Splunk SOAR is good. However, you can always resolve the problem with the community. Splunk has a very good community, and most of the time, we find a solution much better, it is easier and quicker in the community, instead of waiting to open a ticket for Splunk. When you open a ticket, you go into a queue, then the feedback is a little bit slower.
The initial implementation of Splunk SOAR is in the middle range of difficulty. It is not very easy because you need to understand a little bit of the solution to deploy it, but as soon as you learn it, it becomes very easy because most of the integrations are ready. It's very easy to change playbooks, or create a new playbook because you do not need to know how to code. It doesn't matter how the language of the coding it's running in the back end to learn your playbook. It is up to you to create a playbook using the UI interface. If you want, you can code your own if you enjoy coding. You can have the opportunity to change or create some playbooks with Python codes, but you don't need to do that, it is optional. Anyone can develop their own playbooks.
The deployment of Splunk SOAR on premises took approximately 15 days, and deployments in the cloud took approximately two days. You learn how to integrate the solution by doing it. It took about two days because it was my first time, but the next time, when I do it, it will take approximately half a day.
Splunk SOAR has room to improve its offering for small-sized customers. The price is not fair for smaller-sized customers.
The price of Splunk SOAR is based on the number of people using it. Once you increase the users, the prices go goes up. The customer receives a license for the user that is going to operate it in their environment.
I rate Splunk SOAR a ten out of ten.
We're not really creating the use cases. Our internal team is developing the use cases. Right now, we have automated the whole phishing process. After that we are still planning to automate a few more things like malware investigation and then from there other processes.
We're in the POC phase. We need more time to get used to the solution and to understand it better to discover the most useful features.
So far, the interface is very easy to use.
The GUI is great.
The features in the Phantom playbook are all very good.
You can build different playbook and you can play with the playbook. One playbook can give you insights into URL applications, one playbook you can give the reputation about the file access. You can build different playbooks and after integrating all the playbooks you can come up with some organizational directions and decisions. It will give you very good insights into various incidents.
The solution is great for automating redundant work.
It's difficult sometime to manage the amount of reported suspicious emails. Using an intervention like this solution helps make that task easier.
We haven't had too much experience on the solution.
The solution is relatively new in the market.
It would be ideal if we could automate processes even more.
The interface is great, however, they could still keep refining it to make it even more user friendly.
We have used the solution over the past year.
At a previous organization, I did work with another tool in Beta. It was able to provide UVA capacity. I'm not sure if they used a different tool at this current organization.
The Phantom has better GUI, however, I'm not able to clearly see the risk fabric.
I wasn't part of the deployment team. I have no idea if the initial implementation is straightforward or complex.
Technically, we are still in the deployment phase. We haven't finished yet. We are yet to go live. IN the next few weeks we'll go live, however, only on the phishing features.
I'm not aware of the company looking into other options before choosing this solution. All of this was handled by the procurement team, and I am not a party to their decision-making process.
I'm not sure which version of the solution we're currently using.
If a company wants to automate redundant work, this solution is perfect for that. Very specific processes can be easily automated to save time. That way, analysts can invest their time elsewhere. Phantom is one of the great tools for reducing redundancies.
I'd rate the solution eight out of ten.
I'm just a beginner on the solution and it's pretty easy for me to use.
Our team likes it. They've been using it for a while and they really seem to like it. They know more about it than I do at this point, as I'm still new.
It's a default for a lot of things on our system.
We've had trouble implementing the solution with Microsoft products. There seems to be an integration gap.
The pricing of the product could be more reasonable.
While I am a beginner on the Splunk platform, our team has a good amount of experience with it overall. I've personally only been working with it for two or three months or so. It hasn't been that long.
I've never actually opened a ticket with Splunk technical support in the past. I can't speak to how helpful or responsive they are. I don't have any experience with them to discuss how helpful or responsive they are.
The licenses are quite expensive at this time. They need to work on the pricing in order to make the costs much more reasonable.
We are a customer and an end-user. We don't have a business relationship with Splunk.
I can't speak to which version of the solution we're using.
I'd rate the solution at seven out of ten overall.
My primary use case was for the MITRE ATT&CK parameters. I have some experience with MITRE ATT&CK for SIEM and SOAR solutions.
I like the integration capabilities of Phantom. It has a lot of integrations with other products.
Its searching methodologies are also good. It is also easy to understand and easy to create playbooks.
I haven't used it fully, but based on my usage, I could not find simulation tools and features. It currently lacks simulation features, which are important for me for creating a playbook.
It is also very expensive for my region.
I have been using this solution for one year.
I didn't focus on that feature, so I cannot say anything about that.
I don't have any experience with their technical support. My customer was using it in their company, and I had some experience with this solution over there while managing their security solutions, but I didn't get in touch with Splunk specialists.
Its initial setup is straightforward. It is similar to most of the solutions. I didn't have any complexity.
I don't know the exact price, but for my region, it is very expensive.
I would recommend this solution, but it also depends on the price. Splunk is number one for SIEM or SOAR. Another solution that I would recommend is Palo Alto XSOAR.
I would rate Splunk Phantom a nine out of ten.