No more typing reviews! Try our Samantha, our new voice AI agent.

Pros & Cons summary

Buyer's Guide

Get pricing advice, tips, use cases and valuable features from real users of this product.
Get the report

Prominent pros & cons

PROS

Splunk SOAR offers powerful integration capabilities, allowing seamless interaction with various security solutions and IT applications.
The automation and orchestration features, including no-code/low-code playbooks, significantly reduce manual tasks, save time, and enhance incident response efficiency.
Custom Python code and customizable playbooks provide flexibility and adaptability, enabling organizations to address unique security needs and workflows.
The extensive library of pre-built integrations allows Splunk SOAR to connect with a vast array of popular security and IT applications, improving workflow management.
Splunk SOAR enhances security operations by consolidating tools, automating responsive workflows, and reducing mean time to detect and respond to incidents.

CONS

Splunk SOAR has a steep learning curve and complex installation process, requiring prior technical knowledge and integration with multiple tools.
The playbook creation and editing process in Splunk SOAR is cumbersome and lacks efficiency, often requiring manual coding and better debugging tools.
The integration ecosystem in Splunk SOAR needs improvement, with challenges in connecting to various IAM solutions and Microsoft products.
Splunk SOAR's technical support is lacking, requiring improvement in response times and availability of detailed documentation for troubleshooting.
Pricing for Splunk SOAR is high compared to competitors, posing challenges for smaller organizations seeking a cost-effective option.
 

Splunk SOAR Pros review quotes

Vikash Kushwaha - PeerSpot reviewer
Full-Stack Software Engineer at mindpathtech
Aug 10, 2026
Splunk SOAR consolidates tools in my environment significantly, notifying users about ongoing malicious activities based on integrated security features in my banking app.
SS
Manager cybersecurity at Hexion Inc.
Nov 11, 2025
Splunk SOAR has saved us a lot; monthly, around 300 hours of effort, it is saving with Splunk SOAR, and it has helped us where we were able to run the SOC operation with the less number of headcount versus what we used to do earlier.
Sydney D'Souza - PeerSpot reviewer
Security Consultant at SoftwareONE
Jul 17, 2026
One particular example I can recall is that in enterprise, we get around 100 to 200 notables daily, which consumes approximately 16 to 40 hours per day for an analyst, but since we have Splunk SOAR, it is now just about five to seven minutes or five to 10 minutes per alert.
Learn what your peers think about Splunk SOAR. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,806 professionals have used our research since 2012.
MohitGupta2 - PeerSpot reviewer
Chief Information Security Officer Teleperformance India And Global Business Services at a financial services firm with 10,001+ employees
Aug 12, 2026
Splunk SOAR really automates triaging and investigation, reducing an engineer's one-hour incident investigation to just a few minutes while automatically closing false positive tickets with a high level of granularity.
Abhishek Nayak - PeerSpot reviewer
Soc L1 Engineer at Softcell Technologies Limited
Jun 23, 2026
We decided to use Splunk SOAR because it's a powerful, reliable engine that has significantly improved our SOC operations, especially in terms of incident response time and scaling features.
Vaibhav Mahendra Kolhe - PeerSpot reviewer
Soc Analyst at Softcell Technologies Limited
Jun 2, 2026
Splunk SOAR helps a lot with consolidating our networking, security, and observability tools, and we are saving almost 200 hours compared to not using Splunk SOAR.
Jabez Daniel - PeerSpot reviewer
Advance Data Engineer(Cyber Security) at Novo Nordisk
Jan 19, 2026
In terms of time savings in threat responses, as a team, we save more than 30%, estimated around 30-40%.
reviewer2890704 - PeerSpot reviewer
Engineer at a tech vendor with 10,001+ employees
Aug 20, 2026
The visibility for Splunk SOAR is extremely clear and very user-friendly and intuitive.
Mack Scott - PeerSpot reviewer
Cyber Security Network Security Engineer at Cirrus Logic
Sep 9, 2025
In terms of deployment, there were no issues. It was pretty seamless.
SN
Identity and Access Management Specialist at a university with 10,001+ employees
Feb 22, 2026
Since deploying Splunk SOAR, there has been a notable reduction in time spent on monotonous security tasks, which I estimate to be around 95%, enabling my team to focus on more strategic initiatives.
 

Splunk SOAR Cons review quotes

Vikash Kushwaha - PeerSpot reviewer
Full-Stack Software Engineer at mindpathtech
Aug 10, 2026
The installation of Splunk SOAR is complex, requiring integration with various tools such as CloudWatch, antivirus, and EC2 machines, making it difficult.
SS
Manager cybersecurity at Hexion Inc.
Nov 11, 2025
One thing that we would like to see with Splunk SOAR is the expandability to the threat intelligence feed.
Sydney D'Souza - PeerSpot reviewer
Security Consultant at SoftwareONE
Jul 17, 2026
When it comes to Splunk SOAR, in terms of improvement, I feel there should be some pre-deployed solutions available.
Learn what your peers think about Splunk SOAR. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,806 professionals have used our research since 2012.
MohitGupta2 - PeerSpot reviewer
Chief Information Security Officer Teleperformance India And Global Business Services at a financial services firm with 10,001+ employees
Aug 12, 2026
The primary concern with Splunk SOAR is the learning curve and coding expertise required.
Abhishek Nayak - PeerSpot reviewer
Soc L1 Engineer at Softcell Technologies Limited
Jun 23, 2026
I have found a challenge in my three months with Splunk SOAR in that it is quite a heavy tool to maintain.
Vaibhav Mahendra Kolhe - PeerSpot reviewer
Soc Analyst at Softcell Technologies Limited
Jun 2, 2026
The price of Splunk SOAR is high. From a price perspective, the cost for an organization is very high.
Jabez Daniel - PeerSpot reviewer
Advance Data Engineer(Cyber Security) at Novo Nordisk
Jan 19, 2026
I'd rate Splunk's technical support around five because compared to IBM QRadar, their support is much better. I feel Splunk should enhance their support, as it appears lacking, especially considering the costs associated with higher licenses.
reviewer2890704 - PeerSpot reviewer
Engineer at a tech vendor with 10,001+ employees
Aug 20, 2026
A pain point is that you cannot debug from the console or widget within the playbook itself.
Mack Scott - PeerSpot reviewer
Cyber Security Network Security Engineer at Cirrus Logic
Sep 9, 2025
They should integrate Splunk Enterprise Security better into Splunk Cloud.
SN
Identity and Access Management Specialist at a university with 10,001+ employees
Feb 22, 2026
While I appreciate Splunk SOAR, there are areas for improvement, notably regarding the CI/CD pipeline for playbook lifecycle management, as transitioning playbooks from development to production currently feels cumbersome and requires more manual effort than I would prefer.