No more typing reviews! Try our Samantha, our new voice AI agent.

Pros & Cons summary

Buyer's Guide

Get pricing advice, tips, use cases and valuable features from real users of this product.
Get the report

Prominent pros & cons

PROS

Splunk SOAR significantly improves efficiency and productivity through extensive integration capabilities with popular security and IT applications.
The platform automates processes, reducing the mean time to detect by approximately 70% and enabling more strategic focus.
Splunk SOAR offers valuable integration features, allowing connection with multiple platforms, enhancing workflow management and security processes.
Customizable playbooks and automated workflows are key features, drastically saving time and effort for security analysts.
Splunk SOAR leverages advanced automation and orchestration, providing a mature suite of tools for user entity and behavioral analytics.

CONS

Splunk SOAR lacks integration with Teams and has gaps in integrating with IAM solutions like CyberArk.
There is a need for more playbooks and improved template playbooks in Splunk SOAR's repository.
The integration and scalability of Splunk SOAR for small-sized customers could be better, and the price is not considered fair for these customers.
The process to create playbooks is complex, and better built-in debugging tools and smarter playbook suggestions could enhance Splunk SOAR.
Splunk SOAR has integration gaps with Microsoft products and must enhance the integration ecosystem for improved bottom-tier integrations.
 

Splunk SOAR Pros review quotes

SS
Manager cybersecurity at Hexion Inc.
Nov 11, 2025
Splunk SOAR has saved us a lot; monthly, around 300 hours of effort, it is saving with Splunk SOAR, and it has helped us where we were able to run the SOC operation with the less number of headcount versus what we used to do earlier.
Sydney D'Souza - PeerSpot reviewer
Security Consultant at SoftwareONE
Jul 17, 2026
One particular example I can recall is that in enterprise, we get around 100 to 200 notables daily, which consumes approximately 16 to 40 hours per day for an analyst, but since we have Splunk SOAR, it is now just about five to seven minutes or five to 10 minutes per alert.
Abhishek Nayak - PeerSpot reviewer
Soc L1 Engineer at Softcell Technologies Limited
Jun 23, 2026
We decided to use Splunk SOAR because it's a powerful, reliable engine that has significantly improved our SOC operations, especially in terms of incident response time and scaling features.
Learn what your peers think about Splunk SOAR. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,800 professionals have used our research since 2012.
Vaibhav Mahendra Kolhe - PeerSpot reviewer
Soc Analyst at Softcell Technologies Limited
Jun 2, 2026
Splunk SOAR helps a lot with consolidating our networking, security, and observability tools, and we are saving almost 200 hours compared to not using Splunk SOAR.
Jabez Daniel - PeerSpot reviewer
Advance Data Engineer(Cyber Security) at Novo Nordisk
Jan 19, 2026
In terms of time savings in threat responses, as a team, we save more than 30%, estimated around 30-40%.
SN
Identity and Access Management Specialist at a university with 10,001+ employees
Feb 22, 2026
Since deploying Splunk SOAR, there has been a notable reduction in time spent on monotonous security tasks, which I estimate to be around 95%, enabling my team to focus on more strategic initiatives.
Mack Scott - PeerSpot reviewer
Cyber Security Network Security Engineer at Cirrus Logic
Sep 9, 2025
In terms of deployment, there were no issues. It was pretty seamless.
R Nandasana - PeerSpot reviewer
Senior Information Technology Security Consultant at Mideast Data Systems
May 19, 2026
Analysts save a lot of time with Splunk SOAR because all relevant details from phishing emails, including the email ID, IP address, sender information, and email content such as links or attachments, are automatically integrated into an incident and sent to ServiceNow, making troubleshooting easier and enabling them to start investigating directly or know what to do next.
Vikas Pandita - PeerSpot reviewer
Global Head Of Security Architecture Digital & Technology at Aramex
Apr 16, 2026
I have saved much time thanks to Splunk SOAR's impact, where earlier, without autonomous monitoring, users took almost one day or two days; now, a twenty-four hour job is done in almost thirty minutes.
Hamada Elewa - PeerSpot reviewer
System Engineer - Security Presales at Raya Integration
Oct 28, 2025
Splunk SOAR helps reduce my mean time to detect significantly and enhances it very well; it reduces the mean time to detect by approximately 70%.
 

Splunk SOAR Cons review quotes

SS
Manager cybersecurity at Hexion Inc.
Nov 11, 2025
One thing that we would like to see with Splunk SOAR is the expandability to the threat intelligence feed.
Sydney D'Souza - PeerSpot reviewer
Security Consultant at SoftwareONE
Jul 17, 2026
When it comes to Splunk SOAR, in terms of improvement, I feel there should be some pre-deployed solutions available.
Abhishek Nayak - PeerSpot reviewer
Soc L1 Engineer at Softcell Technologies Limited
Jun 23, 2026
I have found a challenge in my three months with Splunk SOAR in that it is quite a heavy tool to maintain.
Learn what your peers think about Splunk SOAR. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,800 professionals have used our research since 2012.
Vaibhav Mahendra Kolhe - PeerSpot reviewer
Soc Analyst at Softcell Technologies Limited
Jun 2, 2026
The price of Splunk SOAR is high. From a price perspective, the cost for an organization is very high.
Jabez Daniel - PeerSpot reviewer
Advance Data Engineer(Cyber Security) at Novo Nordisk
Jan 19, 2026
I'd rate Splunk's technical support around five because compared to IBM QRadar, their support is much better. I feel Splunk should enhance their support, as it appears lacking, especially considering the costs associated with higher licenses.
SN
Identity and Access Management Specialist at a university with 10,001+ employees
Feb 22, 2026
While I appreciate Splunk SOAR, there are areas for improvement, notably regarding the CI/CD pipeline for playbook lifecycle management, as transitioning playbooks from development to production currently feels cumbersome and requires more manual effort than I would prefer.
Mack Scott - PeerSpot reviewer
Cyber Security Network Security Engineer at Cirrus Logic
Sep 9, 2025
They should integrate Splunk Enterprise Security better into Splunk Cloud.
R Nandasana - PeerSpot reviewer
Senior Information Technology Security Consultant at Mideast Data Systems
May 19, 2026
To make Splunk SOAR more usable, the tool needs to be simplified.
Vikas Pandita - PeerSpot reviewer
Global Head Of Security Architecture Digital & Technology at Aramex
Apr 16, 2026
From the improvement point of view regarding Splunk SOAR, I suggest including more types of LLM models such as autonomous AI models including Anthropic and Opus 4.6, as well as creating a playground for new users to work on these, which will significantly help solve complex problems and assist new companies in understanding how Splunk works easily.
Hamada Elewa - PeerSpot reviewer
System Engineer - Security Presales at Raya Integration
Oct 28, 2025
Splunk SOAR does not help me reduce my security event volume; in fact, it makes them massive.