What is our primary use case?
Splunk SOAR automatically generates alerts, and there are many use cases, including phishing email investigations, automating IP domain reputation checks, and malware analysis, along with ticket creation.
How has it helped my organization?
The improvements I see in Splunk SOAR include faster incident detection and response, automation of repetitive SOC tasks, better alert prioritization and enrichment, reduced analyst workload, alert fatigue, and faster containment of threats such as malicious IPs, malware, and compromised accounts, along with better visibility across the security environment.
Splunk SOAR provides centralized visibility across the organization's security environment by connecting multiple security tools and collecting incident-related information in one platform, giving the SOC team visibility into security alerts and incidents, user login activities, endpoint and device status, and also including firewall and network events.
What is most valuable?
Splunk SOAR helps me prioritize and respond to security alerts and incidents effectively. I am satisfied with the customization and management of the playbooks in my environment. Splunk SOAR's automation playbooks have significantly affected the way my analysts allocate their time during a typical security investigation.
Manually, investigation may take thirty minutes to several hours, but with the Splunk SOAR playbook, the same process can often be completed in a few seconds to a few minutes, up to five to ten minutes, leading to a reduction of fifty to ninety percent in response time.
Splunk SOAR provides centralized visibility across the organization's security environment by connecting multiple security tools and collecting incident-related information in one platform, giving the SOC team visibility into security alerts and incidents, user login activities, endpoint and device status, and also including firewall and network events.
What needs improvement?
Real-time monitoring of alerts and incidents, centralized dashboards, case management, and correlation of data from SIEM, firewalls, EDR, and cloud tools could be improved. Better tracking of phishing attacks and suspicious login activities could also be enhanced, along with visibility into automated response actions and investigation workflows that help analysts to quickly identify threats and understand attack patterns.
For how long have I used the solution?
I have been using it in my environment for the last six months.
What do I think about the stability of the solution?
Splunk SOAR is considered a stable platform for security operations. It handles automated workflows, alert management, and integrations reliably with minimal downtime. The platform performs consistently in high-alert environments and supports continuous SOC operations. Regular updates, strong integration support, and centralized automation help improve operational reliability, reduce manual errors, and maintain smooth incident response processes across teams.
What do I think about the scalability of the solution?
Splunk SOAR is highly scalable and works well for both small and large enterprises. It can handle increasing security alerts, integrations, and automated workflows without major performance issues. As organizations grow, new playbooks, users, and tools can be added easily. Its distributed architecture supports high-volume environments and helps reduce analyst workload by automating repetitive tasks, improving overall SOC efficiency and response speed.
How are customer service and support?
Customer service and technical support for Splunk SOAR have been good overall. The support team is knowledgeable, responsive, and helpful during troubleshooting and deployment issues. Critical cases usually receive faster attention, and documentation is also useful for resolving common problems. Technical support helped us with integrations, playbook issues, and performance-related queries, which improved the overall experience and reduced downtime.
Which solution did I use previously and why did I switch?
Yes, we previously used a combination of traditional SIEM tools and manual monitoring processes. While they handled basic log collection and alerting, they lacked advanced analytics, scalability, and centralized visibility. We switched to Splunk because it provided faster threat detection, better correlation of security events, improved dashboards, easier integration with multiple data sources, and more efficient incident investigation for our SOC operations.
How was the initial setup?
The deployment period takes approximately three hours to two to three days, and in a medium enterprise setup with integration, I would estimate one to three weeks. However, in a large enterprise SOC implementation, it can take several weeks or a few months. In basic deployment, I expect it to take a few hours or two to three days.
What about the implementation team?
Yes, we worked with Splunk’s implementation team along with internal security engineers during the deployment of Splunk SOAR. The experience was smooth overall. They helped with initial setup, integrations, playbook configuration, and best practices. Their support team was responsive, knowledgeable, and helped resolve deployment and integration issues efficiently.
What was our ROI?
Yes, we saw measurable ROI with Splunk SOAR by automating repetitive SOC activities. Tasks like alert enrichment, phishing analysis, and ticketing that earlier took 15–20 minutes were reduced to a few minutes through playbooks. This improved analyst productivity, reduced response time, and allowed the SOC team to manage a higher alert volume without adding extra resources. It also minimized manual errors and improved overall operational efficiency.
What's my experience with pricing, setup cost, and licensing?
It is not too expensive; I rate it an eight out of ten.
Which other solutions did I evaluate?
When comparing Splunk SOAR with other solutions or vendors, I find that Splunk SOAR provides strong playbook automation, a large number of third-party integrations, and good integration with Splunk Enterprise. Compared to some other SOAR tools, it offers better ecosystem integration for organizations already using Splunk. However, some organizations may find the initial setup and integration complex, and the licensing cost could be higher than smaller vendors. Overall, Splunk SOAR is considered a strong enterprise-grade SOAR solution for improving automation, visibility, and incident response efficiency in modern SOC environments.
What other advice do I have?
I use Splunk SOAR, and it has the best features. The playbooks are easy to use, and they are effective for phishing and login investigations. I have connected my existing security tools with Splunk SOAR, and the experience has been smooth. I have also used other Splunk solutions and the Cisco ecosystem.
My team consists of approximately twenty people using Splunk SOAR. The mean time to detect, for example, if five incidents took a total of one hundred minutes to detect, would be twenty minutes. Overall, Splunk SOAR is a very good tool, and my team uses it effectively. I gave this review an overall rating of eight out of ten.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?