One of our use cases is to automate any kind of process after investigation. When going into an investigation, we want to make sure that we have the right tools to use. Instead of having multiple tools, we can bring them all into one platform, such as Splunk SOAR, to provide us with that information.
Cyber Security Network Security Engineer at Cirrus Logic
We can automate and orchestrate our detections and quickly respond to them
Pros and Cons
- "In Splunk SOAR, I find the playbooks valuable. We get to create multiple playbooks, and within each playbook, there is a different type of investigation attached to it, which helps out an analyst or new analysts coming on board."
- "They can improve on what they are currently doing. They can provide more playbooks or at least template playbooks that are in their repository."
What is our primary use case?
How has it helped my organization?
Splunk SOAR has not benefited us yet because we are currently in the development process, but I believe that in the future, it will help us streamline our process and our RTR to respond and detect. It is going to help us in the future, but it has not brought us any benefit yet because we are currently building it up.
It is very important that Splunk SOAR has end-to-end visibility into our cloud-native environment. If there is no visibility, then there is no ability for us to detect on time and respond in time. It knocks out a lot of that time discrepancy.
Splunk SOAR has not yet helped reduce our mean time to resolve. It will be helping us in the future due to its playbooks and its compatibility with Mission Control and other Splunk integrations.
It has helped us with our business continuity and our ability to respond to different threats that might be out there.
Splunk SOAR has not saved us time in alert triage. We are still in the early stages of getting Splunk SOAR onboarded and developed, but I believe that it will significantly reduce our time to triage. Similarly, Splunk SOAR has not saved us time in threat response, but it will do so in the future.
Splunk's unified platform has helped consolidate networking, security, and IT observability tools. Splunk's unified platform has been great for every organization. Every analyst has been able to use one unified area.
What is most valuable?
In Splunk SOAR, I find the playbooks valuable. We get to create multiple playbooks, and within each playbook, there is a different type of investigation attached to it, which helps out an analyst or new analysts coming on board. When they get an incident, they do not need to find out where to start. All they have to do is to go to a particular playbook. It will give them end-to-end specifics on what to do and how to process it.
What needs improvement?
They can improve what they are currently doing. They can provide more playbooks or at least template playbooks that are in their repository. That is one area.
Another area would probably be related to onboarding different playbooks or different tool sets that new engineers have. Eventually, they will get there to ingest more tools and datasets into their SOAR.
In terms of additional features, it is hard to say. There can be more integration with other data ingestion platforms out there, not just Splunk.
Buyer's Guide
Splunk SOAR
May 2026
Learn what your peers think about Splunk SOAR. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
900,747 professionals have used our research since 2012.
For how long have I used the solution?
We have been using it for about one month.
What do I think about the stability of the solution?
We have not played with it too much yet. Once we are able to play with it more and get more details from it, we can respond to that.
What do I think about the scalability of the solution?
It can be very scalable just because of the number of different apps that the community pushes to it. Right now, it is not there yet, but I believe in the near future, it is going to be the best growing platform out there.
How are customer service and support?
Splunk's customer service is great and impeccable. I believe that they have been a very valuable resource to our organization and our team.
I would rate their support an eight out of ten just because I believe that no one really gets a ten. It is an eight just because the answers that they cannot answer for us, they are able to get from the community. The community really helps out, but they are always there to help, and they are always responsive.
How was the initial setup?
We are using Splunk Cloud, the public cloud, but we also have on-prem. We use AWS.
As the initial start of the Splunk SOAR, we are getting started with developing the playbooks and getting the configurations set up with our users and toolsets. It has been pretty easy so far. I have not had any hiccups, but we will see where that takes us as we finish our development.
What about the implementation team?
We did not use any integrator or reseller.
What was our ROI?
We have just started getting our metrics developed, ingesting into Splunk, and showing that to the executives.
What other advice do I have?
I would rate Splunk SOAR a nine out of ten just because it does hit all points for the use cases as an analyst, engineer, or developer. It allows us to automate and orchestrate all of our detections and respond to them very quickly.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Information Security Engineer at a tech company with 10,001+ employees
Provides a user-friendly GUI, and reduces manual work, but the playbooks have room for improvement
Pros and Cons
- "Splunk SOAR's extensive library of pre-built integrations allows it to connect with a vast array of popular security and IT applications, streamlining workflows across our existing security stack."
- "Various aspects of the playbook development process itself can be optimized."
What is our primary use case?
I use Splunk SOAR to create automation for our SOC team. These automations integrate with third-party applications, which is a key requirement for our SOC.
How has it helped my organization?
Splunk makes creating playbooks simple with its GUI. We can build playbooks by dragging and dropping different elements, eliminating the need for complex coding.
The visibility of the playbook viewer is good. We can add custom code while developing the playbook if required.
Splunk SOAR provides end-to-end visibility into our environment.
Troubleshooting our cloud-native environment with Splunk SOAR is a breeze thanks to its intuitive graphical interface. Unlike traditional tools requiring command lines, Splunk SOAR lets us manage integrations and cloud access entirely within the user-friendly GUI, streamlining the process.
Splunk SOAR has significantly reduced our manual workload by automating many previously time-consuming processes. We only began to see the full benefits after about five months.
Splunk simplifies security investigations by offering pre-built processes and leveraging the rich functionality embedded within Phantom's alerts. This combination provides a powerful toolkit for investigators.
Splunk SOAR has significantly improved our security alert resolution efficiency. While the specific time saved depends on the individual case, we've seen a general reduction in resolution time from around 20 minutes to five minutes thanks to the variety of use cases it supports.
Splunk has reduced our mean time to detection by 15 minutes.
Our mean time to resolution is now down to five minutes.
Splunk SOAR streamlined our security operations by consolidating multiple tools. We've successfully integrated and replaced approximately 15 individual applications into a more unified environment.
What is most valuable?
The most valuable features are the third-party integrations and the playbook development that can be done using Python.
Splunk SOAR's extensive library of pre-built integrations allows it to connect with a vast array of popular security and IT applications, streamlining workflows across our existing security stack. This includes tools like Salesforce, Microsoft Outlook, and abuseIP, empowering our organization's SOC and security teams to leverage these familiar applications within SOAR's automation and orchestration capabilities.
What needs improvement?
Playbooks offer significant room for improvement, as custom code is often required during development. Various aspects of the playbook development process itself can be optimized.
For how long have I used the solution?
I have been using Splunk SOAR for one and a half years.
What do I think about the stability of the solution?
Splunk SOAR is extremely stable.
What do I think about the scalability of the solution?
Splunk SOAR is scalable to our needs.
How are customer service and support?
The technical support is good.
How would you rate customer service and support?
Positive
What other advice do I have?
I would rate Splunk SOAR five out of ten.
Early on, we encountered some issues automating tasks with playbooks. However, a recent Splunk version upgrade resolved those problems.
We have 50 users spread across different regions.
The resilience of Splunk SOAR is great.
A thorough evaluation of the SOAR landscape is recommended to identify the best fit for your needs. If Splunk aligns with your requirements after this assessment, it can be a strong option.
Which deployment model are you using for this solution?
On-premises
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Buyer's Guide
Splunk SOAR
May 2026
Learn what your peers think about Splunk SOAR. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
900,747 professionals have used our research since 2012.
SOAR PS Consultant at a tech vendor with 11-50 employees
Offers great visibility, and we can customize the playbook use cases and integrate it with other solutions
Pros and Cons
- "The ability to automate Splunk SOAR and customize the playbook use cases is the most valuable feature and is very exciting for me."
- "The UI can be more customizable for the clients."
What is our primary use case?
Splunk SOAR is primarily used for automating security use cases for clients who want to reduce human intervention and personnel involvement. It facilitates end-to-end security workflows and helps to decrease the time spent on manual investigations.
Splunk SOAR can be deployed both in the cloud and on-premises. The cloud deployment comes pre-installed, so if we want to connect to any on-premises applications, we may need an additional server.
How has it helped my organization?
Building playbooks using Splunk SOAR is an easy process.
Splunk SOAR's playbook viewer is excellent. The viewer underwent an update a couple of years ago, making it much more streamlined and easier to use.
Splunk SOAR offers end-to-end visibility throughout our environment. The solution provides us with information about the actions being executed, the flow of the playbooks, where failures occur, and everything in between. It also collects logs of the actions in the backend.
Splunk SOAR simplifies the visualization and troubleshooting of our cloud-native environment. We only need to set up an additional server to connect to our cloud-based applications. Once that is done, the process becomes very straightforward.
Splunk SOAR has the ability to integrate with other system applications in our environment. Currently, SOAR is integrated with nearly 300 applications through APIs.
Splunk SOAR, as a whole, has helped numerous clients automate processes, reduce investigation time, and free up personnel to focus on other tasks. It is a highly effective tool for security automation.
Using Splunk SOAR in an investigation is extremely easy.
Splunk SOAR has significantly reduced our mean time to detect in a relatively short period.
Splunk SOAR has helped reduce our mean time to resolve.
Splunk SOAR has helped free up our IT staff's time to work on other projects.
Splunk SOAR has saved our organization a good amount of time overall.
With Splunk SOAR, we have been able to consolidate tools in our environment, such as Radius and CrowdStrike.
What is most valuable?
The ability to automate Splunk SOAR and customize the playbook use cases is the most valuable feature and is very exciting for me.
What needs improvement?
The UI can be more customizable for the clients.
For how long have I used the solution?
I have been using Splunk SOAR for almost five years.
What do I think about the stability of the solution?
Splunk SOAR is highly stable. The benefits that Resilience offers to SIEM are crucial at the moment, given the vast amount of data and other factors. It aids us in efficiently handling that data, and, with these additional tools, it helps to manage the data with minimal human intervention. As a result, we can reduce the mean time to resolve, the mean time to detect, and save money as well.
What do I think about the scalability of the solution?
Splunk SOAR's scalability is great. I have never had a client complain about the solution's ability to scale.
How are customer service and support?
The technical support team prioritizes all the tickets based on their criticality. They genuinely provide end-to-end support and contact us via email before scheduling calls. If it's a cloud instance, they simply attempt to push changes over the stack, making them extremely helpful.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial deployment is straightforward. It can be completed by a single person, who handles the installation and setup.
What was our ROI?
I've heard from clients that they are receiving more value from the fit than they initially expected. They are also pleased with how much Splunk SOAR has been assisting them with various tasks. Additionally, a couple of companies have reduced the number of personnel in their security team due to the implementation of SOAR.
For completely new users, it may take some time to perceive the benefits. However, for those who are already familiar with the solution and hold certifications, they can quickly recognize the advantages.
What's my experience with pricing, setup cost, and licensing?
The licensing cost is reasonable.
What other advice do I have?
I give Splunk SOAR a ten out of ten.
I started looking into security automation at that time. Initially, it was Phantom, which was quite popular five years ago. Splunk bought it and changed it to SOAR, so it became pretty easy to use. It's a relatively new concept, which is why we wanted to see how it works.
Once Splunk SOAR is deployed, it takes a couple of weeks to train the SOC team of our clients to use the playbooks.
Splunk SOAR requires maintenance if we plan to scale up the database, increase the number of users involved, and expand our development efforts. Additionally, the amount of data processed and other factors should be considered. For a premium user who actively uses it daily and is heavily involved in development, the solution may need regular maintenance. However, apart from such cases, I believe it doesn't require significant maintenance.
For those considering using Splunk SOAR, there is ample documentation available on the Splunk website. Additionally, they can download a free trial version, which can be installed on their server for experimentation.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
Principal Security Engineer at a tech company with 51-200 employees
Integrates well, and uses custom Python code, but the UI has room for improvement
Pros and Cons
- "The best feature is the integration and the custom Python code that we can write. Splunk SOAR provides us with both of these capabilities, allowing us to integrate different security solutions with Splunk SOAR and take remediation actions directly on those security tools."
- "There is a lot of room for improvement with the UI."
What is our primary use case?
We utilize Splunk SOAR to automate our incident response process. I am the sole engineer in my current organization, responsible for working on Splunk to automate the incident response process followed by our team. This involves investigating various incident response procedures established within our security operations center.
The main problem we want to solve is the time it takes to invoice tickets and remediate incidents. Therefore, we aim to reduce that time. If our analysts manually handle and investigate each incident, it will take longer compared to using this solution, which automates most of the processes. Whenever an incident occurs, the playbook and Splunk automatically initiate the necessary actions to gather the required data, enabling the analyst to make informed decisions and address the incident promptly.
How has it helped my organization?
Creating a playbook using the Solutions Playbook Editor, is relatively easy if we possess some knowledge of Python code and the ability to write various types of flow diagrams.
The visibility of the solution's playbook viewer is excellent. There is adequate documentation that assists individuals in learning how to utilize the playbook to construct solutions.
Splunk SOAR's ability to integrate with other systems and applications in our environment is straightforward. It has numerous capabilities to integrate with various security tools, as it supports open APIs. If the solution supports the API, we only need to write the corresponding APIs in the pipeline code and utilize those API tools to construct the integration, enabling us to take action accordingly.
The most significant improvement I have observed is time-saving in the Security Operations Center incidents. We receive approximately a thousand to eleven hundred incidents per day, and if we were to manually investigate these incidents, we would require a team of ten to twelve people. However, by utilizing Splunk SOAR, we are able to handle the investigation of these thousand alerts with just six or seven people.
Splunk SOAR is not difficult to use in an investigation; it depends on the use case. I haven't encountered any issues with the implementation of the case solution, and there don't seem to be any limitations in that regard.
Splunk SOAR assists us in reducing the volume of security events. Whenever an incident occurs, the playbook initiates actions simultaneously with its generation in our security operations center. These incidents are automatically handled by the playbook, while incidents requiring manual intervention are assigned to our analysts. All other incidents are handled automatically through Splunk SOAR playbooks. Splunk SOAR has reduced the security event volume by forty-five percent.
Our mean time to detect has been drastically reduced. Before Splunk SOAR our security operation center, analysts worked on a queue. Whenever an alert was received, it was placed in a queue, and the incidents were investigated one by one. However, with the implementation of Splunk SOAR, we now have instant knowledge and analysts can start investigating more effectively. The required data is already gathered by the playbook itself, aiding analysts in making more accurate decisions in less time. This has resulted in a reduction of our mean time to detection by at least eighty percent. Previously, without Splunk SOAR, we experienced significant mean time to detect because analysts had to focus on one incident at a time, leaving other incidents waiting. Now, there is no need for incidents to wait for an analyst to take over. The playbook automatically gathers the data, allowing the analyst to have all the necessary information as soon as they start, enabling them to make prompt decisions.
Splunk SOAR has helped reduce our mean time to resolve. The resolution of incidents sometimes depends on different teams that need to investigate and send notifications for action. However, the notification of those incidents has been significantly reduced, and we can confidently say that we have achieved a fifty percent reduction in our mean time to resolve.
Fifty percent of our IT staff's time is saved through using Splunk SOAR, and we can utilize that time to work on the other project we have.
Splunk SOAR has saved our organization forty-five percent of our time.
What is most valuable?
The best feature is the integration and the custom Python code that we can write. Splunk SOAR provides us with both of these capabilities, allowing us to integrate different security solutions with Splunk SOAR and take remediation actions directly on those security tools. Additionally, we can write our own Python code, which can be used and embedded in a Splunk SOAR playbook, enabling us to utilize that code directly within the solution itself.
What needs improvement?
There is a lot of room for improvement with the UI.
I would like to have more integrations with cloud technologies and functionalities such as AI within Splunk SOAR.
For how long have I used the solution?
I have been using Splunk SOAR for five years.
What do I think about the stability of the solution?
Splunk SOAR is stable.
What do I think about the scalability of the solution?
Splunk SOAR is a hundred percent scalable.
How was the initial setup?
The initial setup was straightforward and took approximately three hours. Four individuals from our network team and one individual from the Splunk personal service team were required for the deployment as we needed to configure the server.
What was our ROI?
We have observed approximately a forty-five percent return on investment with Splunk SOAR.
What's my experience with pricing, setup cost, and licensing?
Splunk SOAR is more expensive compared to other options for SOAR.
Which other solutions did I evaluate?
We assessed various open-source options prior to choosing Splunk SOAR, such as Securonix SOAR and Shuffle.
What other advice do I have?
I would rate Splunk SOAR a seven out of ten. The solution necessitates expertise in Python coding, which is challenging to find in individuals. Additionally, Splunk SOAR lacks sufficient AI integration.
Before using Splunk SOAR, it took us approximately six hours to block certain IPs on our firewalls. However, after implementing Splunk SOAR, we were able to accomplish the same task within just five minutes.
We deployed Splunk SOAR on a single server.
We have around nine people that use Splunk SOAR in our organization.
Maintenance is sometimes required based on the incident volume we receive. If we experience a higher volume, we need to maintain the RAM and other components in our server. Therefore, it is important for us to exercise caution in this regard.
I highly recommend Splunk SOAR for individuals seeking to automate the incident response process in their security operation centers.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Security Engineer at a retailer with 10,001+ employees
Saves a lot of time and the mobile app makes it easy for our analysts to get alerted and respond
Pros and Cons
- "Surprisingly, the mobile app is valuable because it is very convenient for our on-call analysts to respond and get alerted to security alerts and events wherever they are. We are able to harness the power of Splunk SOAR and everything that we are doing, and we are also able to alert our on-call analysts 24/7. From their mobile phone, they can respond to those alerts."
- "Unfortunately, not all of our analysts are iPhone users or iOS users. The mobile app is only supported on iOS. Our analysts who have Android do not have that benefit. That would be a nice thing to have so that we can have it across the board and not just for iOS."
What is our primary use case?
The primary use case is for our Security Operation Center. We use it for automation and responding to some of our cybersecurity alerts. It is being used for performance enrichment and automation on those events.
We do not use Splunk SOAR to predict things or try to predict things that can happen in the future. We are mainly using it to respond to things. It is more for responding to events that have happened.
How has it helped my organization?
We implemented Splunk SOAR because we had a lot of repetitive tasks that our analysts do. In our area, it was hard, and it still is hard, to find cybersecurity graduates and analysts, so any time that we can save for our analysts can be better spent.
There has been a lot of time-saving which equals to dollars-savings for the company. We have a lot of automation of repetitive tasks and things like that. We do not have to do things manually, so it saves a lot of time for our analysts. It is hard to measure the time savings because we are always developing or trying to develop new things. We are not that far along. We have been using it for three years but we have used it in production for maybe a year and a half. There is a big learning curve, so I am still learning.
Our cloud endeavors are still in their infancy phase. We have not even started to look at that part yet. For our on-prem environment, there is definitely an advantage. There are a lot of features and capabilities not only from a security perspective. We have real-time alerting based on the system downtime and certain logs that are collected and things like that. I am sure we can apply it to the cloud infrastructure in the future as well.
We have definitely saved a lot of time with the things that we have automated. We have probably saved the amount of one analyst in a year.
In terms of Splunk SOAR's impact on our organization’s business resilience, it is on the way to getting there. This year and next year, we will definitely set that stage. We have some initiatives that are just starting that would definitely put us into that area. We have not crossed that bridge yet.
Splunk's unified platform has helped consolidate networking, security, and IT observability tools. A simple example is the ability to use SOAR integrations and API integrations in all the different tool sets that we have. Our analysts can use those tools from Splunk instead of having to log in to each one of those tool sets to do things. It is saving a lot of time as well for our analysts.
What is most valuable?
Surprisingly, the mobile app is valuable because it is very convenient for our on-call analysts to respond and get alerted to security alerts and events wherever they are. We are able to harness the power of Splunk SOAR and everything that we are doing, and we are also able to alert our on-call analysts 24/7. From their mobile phone, they can respond to those alerts. They do not necessarily have to have a laptop with them. That is one of the most convenient features or parts of Splunk SOAR that we use. This type of integration with the mobile app is not very common.
What needs improvement?
Unfortunately, not all of our analysts are iPhone users or iOS users. The mobile app is only supported on iOS. Our analysts who have Android do not have that benefit. That would be a nice thing to have so that we can have it across the board and not just for iOS.
For how long have I used the solution?
I have been using Splunk SOAR for three years.
What do I think about the stability of the solution?
It is very stable. It is pretty rare that it goes down. It crashed just once last week.
What do I think about the scalability of the solution?
This is an aspect that we have not yet explored. We have a single instance on-prem.
How are customer service and support?
From my experience, Splunk support has always been top-notch. I would rate them a nine out of ten. One point that is missing is because of the bad experience that we had while starting out with Phantom. It was hard for the support to assist us. There were definitely some breakdowns in communication that resulted in delays.
Which solution did I use previously and why did I switch?
Before SOAR, it was called Phantom. It was the same thing, and then they changed the name of it. We did not use any other solution previously.
How was the initial setup?
It was a pretty rocky start. That was when it was Phantom, and there were a lot of problems. I had a lot of problems with Phantom. A lot of that was why we had hesitation with renewing Splunk SOAR. A lot of the problems were related to bad code and poor instructions and guidance. Some of it was things that we may not have done right, but a lot of it was related to code. It definitely got off to a rocky start. It was not as smooth as we anticipated the whole thing to be.
Our environment is on-prem. We have some things in AWS, but I am not privy to the cloud aspect.
What about the implementation team?
We deployed Phantom ourselves.
What's my experience with pricing, setup cost, and licensing?
We renewed it this year. This year was the first time there was a dramatic increase in the price. It was kind of non-negotiable. It was just a high increase. We had internal communications, and it was definitely a surprise to us. In a short time frame, we renewed it this year. Prices are going up everywhere, but they are not always justifiable, at least not to our eyes. The pricing this year was definitely a big shock.
Instead of a gradual increase from time to time, it was just a big sticker shock increase. The price is never going to decrease again. I am not saying it was justifiable or not, but the message that was relayed to us and the unwillingness to negotiate at least to a more reasonable number were surprising.
Which other solutions did I evaluate?
The only one that we pursued was a product called Siemplify which has been bought out by Google since then. Our primary reason for going with Splunk SOAR was that we were already a Splunk customer. It made sense to wrap Splunk SOAR into that as well. We use Splunk ES. With Siemplify, the integration piece was lacking just because it was not a Splunk product.
What other advice do I have?
I would rate Splunk SOAR a ten out of ten, especially as compared to other options out there, such as XSOAR and Siemplify. A lot of my decision is based on the fact that we were already a Splunk customer, so the integration was beneficial.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Manager Ict & Innovations at Bangalore International Airport Limited
Helps with visibility, offers helpful playbooks, and has good automation
Pros and Cons
- "It helps increase efficiency and productivity."
- "The number of playbooks on offer should be increased."
What is our primary use case?
We primarily use the solution for security automation. It's used to investigate and remediate threats.
How has it helped my organization?
Normally, we would have to manually investigate events. However, with Splunk, everything is automatically investigated.
What is most valuable?
The playbooks are great. They are very useful. We can define rules, including what the remediation should be. Everything gets clearly defined. You can set up different types of automation. It helps increase efficiency and productivity.
The solution provides us with end-to-end visibility.
It's easy to visualize and troubleshoot our cloud-native environment using Splunk. There's simple product management and quick detection and response that helps minimize risks. I can handle continuous monitoring from an operation control center.
We can integrate with other systems. It's helped minimize incident tickets and my overall response time has been lowered. We began to realize benefits within three to four months of deployment.
Splunk is very easy to use during an investigation. It's very straightforward.
We've been able to reduce our security event volume by 50%. We've also been able to reduce our mean time to detect by about 25%. It's helped us save time and consolidate tools in our environment so that we can minimize staff appropriately. The automation makes all of this possible.
What needs improvement?
The number of playbooks on offer should be increased.
For how long have I used the solution?
I have been using the solution for two years.
What do I think about the stability of the solution?
The solution has consistently been stable.
What do I think about the scalability of the solution?
We have about 300 people using the solution. It's scalable. We may increase usage in the future. We want to get the enterprise license.
How are customer service and support?
Technical support has been good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We did not previously use a different solution.
How was the initial setup?
It was easy to implement the solution. It took our team about four months to be trained on how to use the playbooks.
We had two people managing the deployment process. One handled configuration, and the other handled integration.
No maintenance is required for the product once implemented.
What about the implementation team?
We handled the implementation in-house.
What's my experience with pricing, setup cost, and licensing?
I'm not aware of the exact pricing.
Which other solutions did I evaluate?
We did not evaluate other options.
What other advice do I have?
It's a valuable solution. It enables SIEM capabilities. We're able to orchestrate when events are happening, and this minimizes event tickets. We are able to handle security challenges while gaining good visibility.
I'd rate the solution nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Engineer at a university with 501-1,000 employees
Has the ability to connect it to external apps
Pros and Cons
- "It has definitely saved a decent amount of time for our analysts so they can focus on other tasks."
- "We've run into a few minor issues. Some of the playbook writing is a bit complicated. We've had a few hiccups with the source control. We'd really like to use GitHub deployment keys for a dedicated account. We haven't been able to do that. I think those are some of the major ones."
What is our primary use case?
We are primarily using it to automate tasks for our incident response team. They use it to block suspicious traffic from our network detection system and for alerts from our endpoint security system. Those are the two major use cases we're using it for right now.
How has it helped my organization?
It has definitely saved a decent amount of time for our analysts so they can focus on other tasks. This gives us more value for man hours.
It has definitely improved our business resilience. It's given us greater visibility into the environment we have and the ability to collect all of the threat and log data and put it into one central place.
What is most valuable?
The ability to connect it to external apps is the most valuable feature. We've also gotten a lot of use from writing custom apps for some of our authentication systems for password scramble.
Splunk's ability to predict, identify, and problem-solve in real time is really good.
Splunk's ability to provide business resilience by empowering staff is fairly high. It detects issues as they come up and responds to them.
We have seen time to value. I did help configure it, but we do have the cloud solution, so it was mostly in place.
It has definitely helped to reduce our meantime to resolve. Having it there to automatically take action as events come in and not needing the analysts to have to go out and have a look is how it saved time.
What needs improvement?
We've run into a few minor issues. Some of the playbook writing is a bit complicated. We've had a few hiccups with the source control. We'd really like to use GitHub deployment keys for a dedicated account. We haven't been able to do that. I think those are some of the major ones.
There is a general learning curve as far as playbook writing goes.
For how long have I used the solution?
I have been using SOAR for four to five months.
What do I think about the stability of the solution?
Stability is good. We've had a few hiccups with apps, but never a major outage. I would rate it an eight out of ten.
What do I think about the scalability of the solution?
I haven't really grown it very wide yet, but I could easily foresee us doing that.
How are customer service and support?
I've opened a few tickets for different issues with apps, and they have always been responded to fairly quickly. I'd give support a ten out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I did help configure it but we have a cloud solution, so it was mostly in place.
The development was fairly straightforward. There were some issues setting up the single sign-on, but we were able to get help from Splunk to get all that straightened out. The roles in user accounts and onboarding were all fairly straightforward. App configuration is also something that's pretty streamlined and intuitive.
We did it all in-house.
What was our ROI?
We have seen ROI in its ability to streamline and automate mundane tasks that we would run into on a daily basis. It freed up DevOps people from having to maintain custom tools that were previously used to complete similar tasks.
What other advice do I have?
I would rate Splunk SOAR a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cybersecurity Analyst at a energy/utilities company with 10,001+ employees
An affordable and easy-to-deploy solution that has an extremely helpful technical support team
Pros and Cons
- "The product’s integration with other Splunk products is valuable."
- "Some of the training materials are on a basic level."
What is our primary use case?
We use the solution to automate some of our legacy processes. We review items like phishing and emails.
What is most valuable?
The product’s integration with other Splunk products is valuable. It's easier to collect and enrich all the data to give our incident response teams better access to the information to make their decisions.
What needs improvement?
Some of the training materials are on a basic level. They don't feel like they're really in-depth. I would like to have more advanced and in-depth training.
For how long have I used the solution?
My organization has been using the solution for two months.
What do I think about the stability of the solution?
There have been no issues whatsoever with stability. I wouldn't expect there to be any downtime.
What do I think about the scalability of the solution?
We have a large environment. We have more than 10,000 devices in our organization. It's a complex environment, depending on which areas we're working with. We have different types of regulations.
How are customer service and support?
The team we're working with right now is extremely helpful, and it's easy to coordinate with them and get them involved. They're very welcoming and open to helping us. They are going out of their way to set up meetings to answer questions and help us with the process.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
There's a lot of overlap of concepts between our current SOAR solution and Splunk SOAR. The dashboard's functionality in Splunk SOAR has great value compared to our current platform. It was not easy to make dashboards or reports at a high level in our current solution. It was a bit tedious and difficult. It’s a lot easier to facilitate with Splunk SOAR. Splunk SOAR integrates nicely with all the other Splunk products. We can enrich the data.
How was the initial setup?
We are still going through the initial deployment of the product. The deployment is easy since it is a SaaS solution. There's not much for us to configure right out of the box.
What's my experience with pricing, setup cost, and licensing?
One of the biggest factors that helped the management to decide to switch to Splunk SOAR was its cost. The solution's cost model, Mission Control, and other features make it cost-effective.
What other advice do I have?
We are fairly new to the solution. We are still adjusting Splunk SOAR. As I use the platform more, it'll become more intuitive. My core focus is on the SOAR platform. We're still beginning to get the tool fully customized for us. We are going through the basics to get all the way to fully leveraging the tool. We are still considering how to go from our current setup and expand it.
Our organization monitors multiple cloud environments with Splunk SOAR. It is important for our organization that the product has end-to-end visibility into our cloud-native environment. It allows us to have better incident response. Having visibility on where the attacks or different issues are coming from allows us to better respond to them.
The workshops are the biggest value I get from attending Splunk conferences. I'm getting a lot of real-world examples from different companies. It helps with networking and meeting other individuals who are going through the same type of process or are already leveraging Splunk SOAR. I can get feedback on how they're leveraging the platform. It gives us a lot of insight into things we should consider as we start to set up and build environments.
Overall, I rate the product a ten out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Manager at a financial services firm with 5,001-10,000 employees
The Smooth User Experience Currently Offered Can Further Be Enhanced By Offering Customization Options To Its Users
Pros and Cons
- "Before its use, analyzing each email would take at least 15 to 20 minutes, with some complex cases taking up to 30 minutes...With the automation provided by Splunk Phantom, we could significantly reduce the amount of time and human effort required to complete this task."
- "The technical support for the Splunk SIEM solution was average."
What is our primary use case?
As part of the cybersecurity incident response team, we were responsible for handling phishing emails related to business-as-usual operations. It was a manual process that would include five to six checks to determine the category of the email, its legitimacy, if it was malicious, and if it was an impersonation or a phishing email. We also worked on a use case for our infrastructure's proxy solutions. End users would request that certain websites be unblocked, as they had been blocked by the proxy's default policy or categorically blocked by the proxy. For this, we evaluated publicly available information about the website and the justification provided by the users, to determine whether the website should be whitelisted or made accessible.
Then, we implemented the automation process to simplify such tedious processes. In addition, we had a manual process in place for our threat hunting and threat intelligence platform, where we monitored leaked data on the dark web. This was documented as a use case. Our account management team also conducted weekly checks on the status of accounts. The process also made the team check if they were logged in on their accounts and if the account was disabled, which were manual processes that were later integrated into Splunk SOAR.
How has it helped my organization?
As a security analyst in the SOC center, I have seen the impact of implementing Splunk SOAR on our phishing email analysis process. Before its use, analyzing each email would take at least 15 to 20 minutes, with some complex cases taking up to 30 minutes. Of all the emails received, 30% were complex, 50% were average, and 20% were straightforward and would only take five to ten minutes to analyze. With the automation provided by Splunk SOAR, we can significantly reduce the amount of time and human effort required to complete this task. Instead of two analysts taking two to three hours to analyze 20 to 30 emails, one analyst can now complete the same task within one to two hours.
What is most valuable?
The most advantageous feature of Splunk SOAR is its ease of writing search queries, which can be attributed to Splunk's powerful analytics tool running in the background, offering a smooth user experience.
What needs improvement?
Improvements are needed in automation options as customization is limited, which may make complex use cases challenging despite the solution being able to meet basic requirements.
Currently, the tool only allows categorization into two categories, malicious and non-malicious, which has been identified as a limitation by security analysts in various group brainstorming sessions. The ability to create custom categories for emails can benefit security analysts.
For how long have I used the solution?
I was associated with this solution for almost three years. In my previous organization, Meredith, we initially deployed Splunk. Before that, we were using the ArcSight SIEM solution. Later on, after moving on to the Splunk environment, Meredith thought of opting for an automation process. So, we onboarded Splunk SOAR, but the user Splunk was managed by a third-party company.
What do I think about the stability of the solution?
Stability-wise, it is good. It doesn't have any downtime issues. If you consider Splunk SOAR as an independent solution to be deployed at work, then that would not be easy. The challenge is that Splunk SOAR cannot work without the Splunk SIEM solution. But if you have Splunk as your base, then Splunk Phantom works well. So the issues with Splunk Phantom are very minimal. I would rate it an eight on a scale of one to 10, where one is considered the worst and 10 is the best.
What do I think about the scalability of the solution?
In terms of scalability, I believe Splunk SOAR is decent. I haven't encountered any stability issues, even with a large infrastructure of over 10,000 end-user devices and high log inflows. I would rate its scalability as an eight or nine out of ten, where one is the worst and ten is the best. It works well in both large and small work environments.
How are customer service and support?
The technical support for the Splunk SIEM solution was average. Splunk is still working on improving its customer support, as they do not directly support SOAR, which is a separate entity. Other vendors, on the other hand, support various environments. I believe that Splunk can improve its customer support services.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I previously used Demisto, a security automation tool, in one of my previous organizations, Dell Technologies. The ease of writing custom queries and making granular modifications were the key reasons why we used it. In my next organization, I used Splunk SOAR because we already had Splunk in our environment. Currently, I am working in a bank that does not have a Splunk environment, so I am using a different automation tool.
How was the initial setup?
The deployment warranted collecting information on the external and internal parameters of our network system. A network engineer along with a team of four to five people from Hurricane Labs was involved in the deployment of the Splunk SIEM solution for the company. The deployment of the Splunk SIEM solution took approximately six to nine months. During the first three months, the team familiarized themselves with the environment and started the transition from an off-site setup. Over the next six to nine months, the team worked to mature the solution and address any issues with logs not being collected properly and displayed on the Splunk screen.
What about the implementation team?
Splunk SIEM was deployed by a third-party vendor. The vendor was responsible for the end-to-end deployment and was the main point of contact for the project. However, I am not familiar with the specific details of the deployment and therefore cannot accurately explain how the deployment of the solution was done.
What's my experience with pricing, setup cost, and licensing?
In terms of pricing, I would rate it a six or seven out of 10, where one is the highest and 10 is the lowest. It’s on the expensive side, and I'm not sure if a lot of the small-sized organizations will be able to afford it. A medium enterprise environment will be able to afford it. We had to pay for the cost of the licenses for the services we received.
What other advice do I have?
If you use Splunk as your SIEM solution, you can consider Splunk SOAR as your automation tool. However, automation tools such as AutomationEdge or Demisto may provide better value if you have other SIEM solutions.
I rate this solution a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
CTO at a tech services company with 11-50 employees
Customized workflows, easy to onboard, and lots of time savings
Pros and Cons
- "Workflow management is most valuable. It is easily customizable"
- "Portability is one thing that is currently lacking. The open-source product that I evaluated had portability. It would require a lot of development effort, but it will save the cost of rewriting all the playbooks."
What is our primary use case?
I am the CTO of a startup. We evaluated this product.
Our major requirement was to open APIs to our product. I felt that the open-source product that I evaluated was better in terms of open APIs to integrate into the existing product because Splunk SOAR is an enterprise product and not an open-source one. However, after evaluating the go-to-market time and how soon we can implement things, the customer preferred Splunk SOAR because it could be easily integrated. Over time, they may choose to have the capabilities inside the in-house product instead of using Splunk SOAR, but at this point, they are using Splunk SOAR.
We have our own product. We were developing our in-house engine based on user analytics and behaviors, but because of funding issues, we stopped working on that. During that time, I started looking at Splunk SOAR to compare its features, and that is how I was able to recommend it to the customer. I told them that instead of creating these capabilities in the in-house product, they could start using Splunk SOAR. In the future, we will be able to import the workflow from Splunk SOAR into the product. We would need a standardized backend to be able to import the workflows. At this point, it is not available, but in the future, just like JSON or XML, it should happen. There should be portability. I am not sure if it is in their roadmap. It is their loss in one aspect, but it is a gain in another aspect because they can claim that workflows are portable across platforms.
How has it helped my organization?
A major use case for my customer was dealing with DDoS attacks. The customer is in the BFSI industry. The major issue for them was people trying to get access to customer accounts by logging in or generating OTPs from different locations. They wanted to limit access to OTPs and logins from particular geographies because 95% of their customer base is from an Asia-Pacific country. They were able to do that and solve that issue. They were also able to reduce the cost of customer care because when a customer gets a message about an OTP for a withdrawal, they tend to call customer care. Instead of generating an OTP, they created a workflow to avoid generating an OTP when it is requested from other geographies. They developed a workflow to make a call to the customer and confirm if they have requested the OTP for money withdrawal. In our geography, rules are becoming stricter and stricter, and banks are held responsible for such cases. The customer was able to meet the requirements of the government. They were also able to save money and reduce operational costs. They could save 75% of operational costs.
I have used the solution's playbooks and the visual playbook editor to help automate tasks. I am a technical person, so it is easy for me to use the playbooks and visual playbook editor. I also write playbooks at the code level.
Spunk SOAR has saved us time in alert triage.
Spunk SOAR has saved time in threat response. They were able to stop 75% of the cases of sending OTPs to the wrong people.
Spunk SOAR's automation helped reduce tedious manual tasks. Based on the input that I got for the first two quarters, there was somewhere about a 75% reduction.
What is most valuable?
Workflow management is most valuable. It is easily customizable.
What needs improvement?
Portability is one thing that is currently lacking. The open-source product that I evaluated had portability. It would require a lot of development effort, but it will save the cost of rewriting all the playbooks.
What do I think about the stability of the solution?
Its stability is pretty good. UI is more responsive than other tools for writing playbooks and other things.
What do I think about the scalability of the solution?
When I evaluated, there were just one or two users. They have been using it only for two quarters. I will know its scalability better after a year or so.
How was the initial setup?
It is SaaS-based. Being a BFSI business, most of their core applications are on-premises, but the applications that we have evaluated stay on AWS.
It is much quicker to onboard compared to the open-source tools I have used. We were able to onboard initial applications in a day. It is very fast.
What about the implementation team?
I helped the customer to onboard it. There was also help available from the Splunk team.
Which other solutions did I evaluate?
I evaluated Splunk SOAR and a few other SOAR solutions. I evaluated an open-source solution and the IBM solution. I preferred Splunk SOAR because of its log processing and the way it allows you to customize workflows. I felt it was better than any other competitor in the market because it is a next-generation SOAR tool.
What other advice do I have?
I would rate Splunk SOAR a nine out of ten because there is no portability.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Splunk SOAR Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2026
Product Categories
Security Orchestration Automation and Response (SOAR)Popular Comparisons
IBM Security QRadar
Microsoft Sentinel
Elastic Security
AWS Security Hub
Palo Alto Networks Cortex XSOAR
Exabeam
Stellar Cyber Open XDR
NetWitness NDR
Sumo Logic Security
Logpoint
Tines
Google Security Operations
ThreatConnect Threat Intelligence Platform (TIP)
ServiceNow Security Operations
Buyer's Guide
Download our free Splunk SOAR Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which Do You Recommend, Phantom or Demisto?
- What are the Top 5 cybersecurity trends in 2022?
- What is the difference between SIEM and SOAR platforms?
- What is an incident response playbook and how is it used in SOAR?
- What are the latest trends in Security Operations Center (SOC)?
- What tools and solutions do you use for automated incident response in an enterprise in 2022?
- How to evaluate SIEM detection rules?
- Why a Security Operations Center (SOC) is important?
- What types of Security Operations Center (SOC) deployment models do exist?
- Why is Security Orchestration Automation and Response (SOAR) important for companies?




















