


Exabeam and Splunk SOAR are competitors in the security software category, specifically in security analytics and automation. Although both provide strong features, Splunk SOAR may have an edge due to its integration and automation prowess.
Features: Exabeam is noted for its user-friendly interface, automation, and user and entity behavior analytics (UEBA). Its timeline-based analysis provides insights into user behavior, making it valuable for security investigations. Splunk SOAR excels in integration capabilities, playbook automation, and customization, allowing streamlined workflows across various security tools.
Room for Improvement: Exabeam could improve by expanding integration capabilities, enhancing flow analysis, and improving reporting dashboards. It also faces challenges with API interactions and technical documentation. Splunk SOAR's challenges include its complex playbook creation process and high pricing for small organizations. Users also request better debugging tools and more comprehensive training materials.
Ease of Deployment and Customer Service: Exabeam offers on-premises and cloud deployment options, with feedback on customer support being generally positive despite some slow response reports. Splunk SOAR provides cloud and hybrid environments and is praised for efficient support with dedicated engineers, although deployment complexity and need for comprehensive support are noted concerns.
Pricing and ROI: Exabeam's pricing is generally seen as reasonable with flexible models, although considered costly by some. It often reports positive ROI due to cost reductions from tool consolidation. Splunk SOAR, however, is viewed as expensive, especially for smaller organizations, with a user-based pricing model impacting affordability. Despite its costs, the investment is justified by its automation and integration capabilities, contributing to strong ROI.
Since we started working with Torq, I am handling much fewer alerts. It is becoming really easy for me to handle an alert.
We have seen a return on investment, targeting a $600,000 ROI for the year.
By the time we officially bought Torq, we already had two workflows that were very helpful to us.
Exabeam offers more machine learning models that detect anomalies.
I have seen a return on investment with Exabeam Fusion SIEM, and it is worth the money.
Since deploying Splunk SOAR, there has been a notable reduction in time spent on monotonous security tasks, which I estimate to be around 95%, enabling my team to focus on more strategic initiatives.
We've seen a decrease in false positives and a significant increase in our containment.
Monthly, around 300 hours of effort, it is saving with Splunk SOAR.
My impression of their technical support during the initial setup was that they were helpful, responded within a reasonable timeframe, and provided exactly what we needed.
The speed and quality of their answers have been pretty good, as I usually get a response within 24 hours, and they follow up well.
We can always get an answer, and the support team are experts in their own system.
Even with TAM support from Exabeam, many issues go unresolved.
I would rate Exabeam Fusion SIEM support team a nine out of ten; I do not give anyone a perfect score.
I also had the chance to look at the documentation, and the documentation is good.
Discovering different troubleshooting methods is harder to do with Splunk SOAR than with Enterprise Security or other Splunk services.
We always have a customer support representative who will come in the picture and help us to direct any ticket or any issue that we are facing to the right team.
I have worked with Splunk SOAR's technical support or customer service, which I find to be as perfect as Splunk SIEM
Our case management is super scalable.
In terms of scalability, you can do as long as you can build it, and they can support it.
Regarding the ability of the solution to grow in your work environment, if it is scalable, if it fits your business requirements, and if there is room to scale up, the answer is yes, for sure.
I believe Exabeam Fusion SIEM is excellent regarding scalability, and I would rate it at approximately an eight out of ten.
Regarding Exabeam's scalability and how well it adapts to its customers' needs, I would rate it an eight.
This solution is very much scalable, so I would rate it a ten.
It can be extended and adapted as necessary.
Regarding scalability, I find it to be a nine, as we have had no issues with scaling Splunk SOAR.
We have been using Torq for one and a half years, but we have experienced no downtime.
Most of the time, the system is stable as long as the components that they integrate with are stable.
I have never faced any downtime or issues.
These problems were not frequent, and the last six to eight months have been stable.
Regarding stability, I would rate Exabeam Fusion SIEM at approximately eight to eight and a half out of ten because it is very stable.
Overall, I think Exabeam's stability level is good.
We have not experienced any downtime, crashes, or performance issues.
We have not seen any impact in the work that we do with Splunk SOAR or the SIEM platform.
I have not encountered any outages or glitches within my experience with Splunk SOAR.
Torq should offer default templates that can directly scan firewall data and automate actions.
The AI value depends on maturity. Real value depends heavily on telemetry, integration depth, and workflow design, all of which rely on how mature customers are in their SOC department.
It was able to capture data but was unable to differentiate between the agent hostname we are using and the hostname that resides on the back end of the Internet.
Exabeam needs to improve its documentation and provide more customization for dashboards and case management.
I have explored the SaaS version; it offers many new features.
Exabeam's integration capabilities are not good, as Exabeam has a very limited number of integrations and no out-of-box integration.
If we start ingesting those data to Splunk SOAR or SIEM with some sort of integration with threat intelligence feed, that will also improve our detection and prediction method or help us with the investigation.
Torq is better than Splunk SOAR because Torq has a no-code UI where we can accomplish anything through drag and drop.
Visibility into automated response actions and investigation workflows that help analysts to quickly identify threats and understand attack patterns.
When they bring more and more value into the platform, it makes more sense to pay that price, but still, it is expensive.
Before deciding to implement Torq, I considered that compared to our old case management platform, Torq was a much better price and had a lot better value for what you get out of the platform, which was a key consideration for the company.
It is an expensive solution, not an inexpensive solution, but we get through the flexibility.
The pricing for Exabeam Fusion SIEM is not cost prohibitive, but it was a little more than I initially thought.
It is way below what it costs to hire some professionals to do only that type of work.
Splunk SOAR is moderately priced, neither cheap nor overly expensive.
I am familiar with the pricing aspect, setup cost, and licensing cost of Splunk SOAR, and it is pretty much similar to what industries are offering these days.
Torq's unified platform approach to AI SOC automation and case management has significantly benefited us by integrating the case management platform with the automation, which saves time compared to managing multiple point solutions across our security stack.
The fact that I can build whatever I want within my own imagination and skills without relying on code is the best thing about Torq.
You can copy and paste a cURL command. If you have documentation or APIs, you usually have an example on the side. You basically have all the information on how the API call should be. You can just copy that and paste it into a step, and it will just build the step for you.
Exabeam's AI capabilities, like the natural language mode, convert natural language into Exabeam queries, enhancing ease of use.
The product offers useful features like the dashboard, timeline, and session views, which enhance our security tools.
Exabeam's UEBA is the most valuable feature that I have found so far.
Creating playbooks using the Playbook Editor in Splunk SOAR is easy. The editor is designed to be user-friendly with visual drag and drop features, allowing for easy workflows without writing any code.
Splunk SOAR saves time in threat response, and the time to solve an incident is currently the best in the market.
Splunk SOAR has improved our MTTD and MTTR both with the consolidation with a unified platform with Splunk.
| Product | Mindshare (%) |
|---|---|
| Splunk SOAR | 7.1% |
| Torq | 3.8% |
| Exabeam | 3.1% |
| Other | 86.0% |
| Company Size | Count |
|---|---|
| Small Business | 2 |
| Midsize Enterprise | 5 |
| Large Enterprise | 5 |
| Company Size | Count |
|---|---|
| Small Business | 12 |
| Midsize Enterprise | 5 |
| Large Enterprise | 7 |
| Company Size | Count |
|---|---|
| Small Business | 17 |
| Midsize Enterprise | 10 |
| Large Enterprise | 40 |
Torq is the enterprise AI SOC solution that effectively combines adaptive insights and automation to handle critical threats efficiently. It manages threat lifecycles, swiftly moving from triage to response, ensuring effective risk management.
Torq is designed to streamline security operations by aggregating telemetry across your security stack. It investigates significant risks and manages threats from triage to containment and remediation. This AI-driven tool enhances the capabilities of your SecOps team, allowing them to achieve more impactful results without introducing complicated processes.
What are the key features of Torq?In industries like finance and healthcare, Torq shows effectiveness by adapting to specific risk scenarios often encountered in these fields. Its integration with existing infrastructures makes it a valuable asset for maintaining stringent security standards, essential for protecting critical data and operations in diverse high-stakes environments.
Exabeam offers intuitive interfaces, detailed dashboards, and powerful analytics to enhance security investigations. Its machine learning detects complex threats with automation streamlining tasks for efficiency and integration with AWS.
Exabeam stands out with its robust cybersecurity management capabilities, offering advanced user behavior analytics and incident detection tools. Security teams can use its systems to monitor events, create investigative timelines, and analyze log data. While praised for easy use, it benefits from initial training for optimal utilization. Challenges include the need for better flexibility, cost-management, and enhanced AI integration. However, it facilitates seamless AWS integration, real-time updates, and vulnerability prioritization within business contexts. Improvements in dashboard customization and overall performance, especially in UI and log ingestion, could enhance usability.
What are Exabeam's key features?Exabeam is widely used across industries such as finance and government for cybersecurity management. Organizations leverage its capabilities for integrating logs, protecting sensitive environments, and supporting compliance efforts. Its tools aid in detecting anomalies and managing security operations within infrastructures effectively.
Splunk SOAR focuses on automating security operations with seamless third-party integrations and customizable workflows, enhancing incident response and threat management.
Splunk SOAR offers robust playbook automation and powerful API connectivity, allowing organizations to streamline workflows and integrate extensively with tools like Salesforce and ServiceNow. With its capabilities in real-time data visualization and automated threat responses, it significantly enhances security and reduces manual efforts. Users appreciate the ease of creating playbooks, which reduces mean time to detect and resolve. However, attention to its integration challenges with Microsoft products, the need for more playbooks, and improved customization tools is necessary. Enhancements in the development process, visibility, scalability, and case management options are also beneficial. Improving documentation and training resources would add more depth and accessibility.
What are the top features of Splunk SOAR?Organizations implement Splunk SOAR in industries to automate tasks in Security Operation Centers, addressing incidents such as phishing, brute force, and ransomware. It integrates with third-party applications for threat intelligence enrichment, commonly deployed both on-premise and cloud, enhancing cybersecurity efforts.
We monitor all Security Orchestration Automation and Response (SOAR) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.