Try our new research platform with insights from 80,000+ expert users
reviewer2137659 - PeerSpot reviewer
Assistant Director - Lead IT Security Engineer at a financial services firm with 501-1,000 employees
Real User
Helps to reduce security event volume and mean time to detection , but the UI has room for improvement
Pros and Cons
  • "Scalability is the best feature of the solution."
  • "The algorithm and machine learning have room for improvement and can be more user-friendly."

What is our primary use case?

We have around 95 different use cases for Splunk SOAR that help secure our environment. 

How has it helped my organization?

The solution has helped us automate and customize some of our servers.

I give an eight out of ten for the ease of creating a playbook. The visibility of the solutions playbook viewer is user-friendly.

We have integrated 15 plus services with Splunk SOAR. Splunk SOAR is easy to use for investigations as long as they have experience with the solution.

Splunk has helped us reduce our security event volume. The solution has also helped us reduce our mean detection time by 80 percent and has helped our security IT staff save time to work on other projects.

Splunk SOAR has as well helped us consolidate tools in our environment. 

What is most valuable?

Scalability is the best feature of the solution.

What needs improvement?

The algorithm and machine learning have room for improvement and can be more user-friendly.

The integration with the phone system, price, UI, and performance have room for improvement.

Buyer's Guide
Splunk SOAR
July 2025
Learn what your peers think about Splunk SOAR. Get advice and tips from experienced pros sharing their opinions. Updated: July 2025.
865,295 professionals have used our research since 2012.

For how long have I used the solution?

I have been using the solution for one year.

What do I think about the stability of the solution?

I give the stability a seven out of ten.

What do I think about the scalability of the solution?

I give the scalability an eight out of ten.

Which solution did I use previously and why did I switch?

I previously used Swimlane which has a better GI than Splunk SOAR.

How was the initial setup?

I give the initial setup an eight out of ten. There is a lot of documentation available online to help with deployment and as long as we know how to configure it, it is straightforward. For basic deployment, we do not require much time.

What about the implementation team?

The implementation was completed in-house.

What's my experience with pricing, setup cost, and licensing?

I give the price a six out of ten. Splunk SOAR is priced higher than most other solutions.

What other advice do I have?

I give the solution a seven out of ten.

I recommend Splunk SOAR for larger organizations.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Siddharth Matalia - PeerSpot reviewer
Senior Technical Specialist at a manufacturing company with 10,001+ employees
Real User
Reliable with a customizable playbook and helpful support
Pros and Cons
  • "The customizable playbook is the most valuable aspect of the solution."
  • "What we have seen is if the workflow gets halted or if we want to halt a workflow, it cannot be resumed."

What is our primary use case?

Basically, we are using it for most of our automation, and not as per the SOAR, although it is a SOAR application. We are not using it just for security purposes. We are using it for various purposes like maintenance. 

We do have our own data center where we have our maintenance on the infrastructure side, and the application has to be brought down. Here it has done exceptionally well. We shut down all our different applications by writing our code in the shell languages, and we upload through GitHub. It means that we can just call that script, and it gets triggered on the particular server, and it shuts down. It's like a workflow.

The workflow has been created in such a way that it helps us. Earlier, when we used to have to manage it manually, when we shut down the application, it used to take a lot of time. Now it is done within 30 minutes. In our environment, we have SAP applications, and SAP has its own commands to shut down the applications, databases, et cetera. So it is just not limited to all those shutdowns and this. We do have various other stuff as well, like upgrades. So we have written the upgrade codes, and now we can upgrade X number of SAP applications and databases as needed.

How has it helped my organization?

It has helped us with the SAP kernel upgrade. Recently, due to security fixes, and security bugs, we had to upgrade the various SAP applications. To do it manually, it would have taken around five to six months to complete. However, with this product, we were able to complete it within two months since we just wrote a script, and it got triggered in various systems, and it fixed everything. We were saved from the security perspective as well since it ensured we had less vulnerability for less time. Also, thanks to SOAR, only two people were needed to run all those scripts, and just have to monitor everything. That's less personnel. 

What is most valuable?

The customizable playbook is the most valuable aspect of the solution. 

With the Splunk vendor itself, the vendor is supporting us in the creation of those playbooks. We have created playbooks in such a way that they are a universal playbook, where we just have to bring in any type of command which needs to be triggered, and it works. If we did things another way, we would have to install our agents to connect the particular application. Here, we don't have to have to do that. It can work in the playbook itself. We just have to give our credentials. The credentials also are in an encrypted format, so we are much more secure.

The solution is stable. 

Technical support is helpful. 

What needs improvement?

What we have seen is if the workflow gets halted or if we want to halt a workflow, it cannot be resumed. We have to trigger the entire plan from step one. That is a bit annoying. If something is wrong, we can't just resume stuff. We'd like it to be possible to pause things without having to start from square one. 

Reporting could be better. We are getting reports, yet not in the way we want. Whatever fails, for example, we want all those errors, the logs, in an attachment, which can be sent easily over an email just by the click of a button. Right now, we cannot send over an email. We have to pull everything, and we have to download it.

For how long have I used the solution?

We've been using the solution for the past two years.

What do I think about the stability of the solution?

The stability is great. I'd rate it eight out of ten. It's not breaking very often, and the playbook makes things easy for us. 

What do I think about the scalability of the solution?

I'd give the level of scalability seven out of ten. There is still room for improvement. We'd like to have more use cases and automation.

How are customer service and support?

Technical support has been good. I work on technical parts of the product and bring in use cases, et cetera. If there are any problems, my colleagues check with the vendor and so far, we have had good support from them. We haven't had many issues. 

Which solution did I use previously and why did I switch?

We were using IBM BigFix before this, and we used it for various purposes like patching on the Windows server. The same solution was also used for the automation of shutting down the system, upgrades, and many other things. Ultimately, we decommissioned it, and we moved ahead with the Splunk SOAR.

What about the implementation team?

The vendor was the one who deployed the solution. Later on, they just installed it on our site. We gave everything to the vendor, and the vendor supports everything since it is on the cloud. 

What was our ROI?

We have witnessed an ROI, and it is good. We've gotten good feedback from senior management. 

What's my experience with pricing, setup cost, and licensing?

I don't handle the pricing aspect of the product.

What other advice do I have?

We are both partners and customers of Splunk. 

If you are a company looking into SOAR and if you are a customer of Splunk, then you should definitely use it. And if your product is most probably looking for security or for some alerting purposes, it will help you to automate your many, many use cases. You can build many, many things with Splunk and on the SOAR side and you can automate your end-to-end process. Also, companies should know that a minimal language knowledge of Python is required.

I'd rate the solution eight out of ten overall. Even for people who are not too technical, it's a good product.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Splunk SOAR
July 2025
Learn what your peers think about Splunk SOAR. Get advice and tips from experienced pros sharing their opinions. Updated: July 2025.
865,295 professionals have used our research since 2012.
Srikanth Nuthalapati - PeerSpot reviewer
Software Engineering Manager at Deloitte
Real User
We can customize playbooks and incorporate custom code, but the support is subpar
Pros and Cons
  • "The solution allows us to customize playbooks and incorporate custom code, allowing us to drag and drop elements while still writing code to build the integrations we need."
  • "Splunk's support for integration is subpar and has room for improvement."

What is our primary use case?

We wanted to automate the process of creating playbooks, orchestrating events, customizing integrations, and deploying applications such as Thread Connect and Wireless Total for enrichment and threat hunting. We have tailored these applications to meet our specific needs and redeployed them.

What is most valuable?

As a programmer, I am glad that Splunk did not position itself as a no-code or low-code platform. The solution allows us to customize playbooks and incorporate custom code, allowing us to drag and drop elements while still writing code to build the integrations we need. This makes Splunk a great solution for a solid platform.

What needs improvement?

Splunk's support for integration is subpar and has room for improvement. 
Splunk should make more effort to keep up with the latest developments in the external world, so that their applications, integrations, and enrichment apps are up to date. Additionally, the documentation and support should be improved, as the experience, their users have had in the past has been unsatisfactory. We were very disappointed that our queries were left unresolved for six months, as it was a time for response rather than solutions. Additionally, several tickets were lodged with Splunk, yet the issue persisted for half a year.

I would request that SOAR add a feature that allows the extraction of documentation from playbooks. This would enable developers to quickly understand the features and use cases associated with a playbook, so they can modify or interact with it. This would eliminate the need for someone to manually explain each playbook in detail. 

I would suggest making the app customizable and deployable in an easy and straightforward manner. This would save time and effort compared to the current process.

For how long have I used the solution?

I have been using the solution for four years.

What do I think about the stability of the solution?

Although not the most stable solution, I would say the overall stability of the updates is satisfactory. I give the stability a seven out of ten.

What do I think about the scalability of the solution?

We had difficulty with scalability, but I would not attribute this to Splunk. It could have been due to our lack of knowledge or lack of support from Splunk. I give the scalability a six out of ten.

Which solution did I use previously and why did I switch?

Our company utilizes a variety of SOAR tools, including Splunk SOAR, Swimlane, and Palo Alto XSOAR, along with ServiceNow for SecOps. Initially, Splunk SOAR was chosen as the SOAR tool due to its compatibility with the majority of our other tools. Unfortunately, it became apparent that SOAR was difficult to install, service, and price, leading some teams to switch to SwimLane and Palo Alto XSOAR.

How was the initial setup?

The initial setup is not necessarily an easy task, nor is it overly complex, so I would say it's of medium difficulty. Splunk could have provided more documentation and support, considering it is not a free product. It would have been much more helpful if Splunk had provided basic understanding and assistance for those installing the solution.

Deployment took several hours each time to install and upgrade, and we often encountered broken pieces of functionality due to miscoordination or non-sequential startup processes. I remember there were five items that came with Splunk SOAR. Deployment was a difficult process, and we ran into issues every time we had an upgrade.

We used Git version control to deploy our playbooks to SOAR, and then we would pull them back to the production SOAR to bring them into use.

What other advice do I have?

I give the solution a six out of ten because of the scope of building playbooks and automation. Unfortunately, this is accompanied by a downside due to a lack of support, bad applications, inadequate documentation, and a general lack of support.

We have thousands of people using the solution.

I would suggest alternatives to Splunk SOAR due to the cost and poor support. However, if cost and support are satisfactory I would recommend the solution.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. customer/partner
PeerSpot user
Volodymyr-Savov - PeerSpot reviewer
Splunk BDM at Clicko
Real User
Top 10
Is user-friendly, integrates well, and is stable
Pros and Cons
  • "Splunk SOAR's quick response to incidents is the most valuable part."
  • "The cost of Splunk SOAR has room for improvement."

What is our primary use case?

Splunk SOAR streamlines the handling of common customer scenarios that arise across diverse situations. Even when specific expertise within our team varies, Splunk SOAR empowers all users with pre-built playbooks, guiding them through the required actions in any circumstance.

How has it helped my organization?

Splunk SOAR's UI is user-friendly for managing workflows.

The integration of Splunk SOAR is good.

When we implemented Splunk SOAR we were able to reduce our team of five down to three.

What is most valuable?

Splunk SOAR's quick response to incidents is the most valuable part.

What needs improvement?

The cost of Splunk SOAR has room for improvement.

For how long have I used the solution?

I have been using Splunk SOAR for a couple of years.

What do I think about the stability of the solution?

Splunk SOAR is stable. We have not heard of any issues from our customers.

What do I think about the scalability of the solution?

Splunk SOAR is scalable.

What's my experience with pricing, setup cost, and licensing?

The cost is high and the licensing is on an annual basis.

What other advice do I have?

I would rate Splunk SOAR an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
reviewer2239854 - PeerSpot reviewer
Cyber Security Architect at a financial services firm with 201-500 employees
Real User
A stable solution that can be used for security, but its version upgrading requires expertise and time commitment
Pros and Cons
  • "The most valuable feature of Splunk SOAR is the automated playbooks, which saves analysts time."
  • "Splunk SOAR should improve its ease of upgrade, which is a pain point for us right now."

What is our primary use case?

We use Splunk SOAR mainly for security.

What is most valuable?

The most valuable feature of Splunk SOAR is the automated playbooks, which saves analysts time. The results that are returned provide additional context that we would have to look up manually in different tools. Splunk SOAR provides it in one pane of glass.

What needs improvement?

Splunk SOAR should improve its ease of upgrade, which is a pain point for us right now. Each upgrade to the version requires expertise and time commitment. Then, we usually have to troubleshoot it with support.

For how long have I used the solution?

I have been using Splunk SOAR for two years.

What do I think about the stability of the solution?

Except for the upgrade challenges, Splunk SOAR is stable when it's operational.

What do I think about the scalability of the solution?

Splunk SOAR is a scalable solution.

How are customer service and support?

Splunk SOAR's technical support has been responsive. We have to go through tiers to get to the correct person for support.

How would you rate customer service and support?

Positive

How was the initial setup?

Splunk SOAR's initial setup is complex.

What about the implementation team?

The solution's deployment requires Splunk's outsourced professional services, who take care of the complexity for you. The professional services were good, and they knew what needed to be done for the solution's implementation.

Two people were required for the solution's deployment. These two people were responsible for administration, the use cases we needed to develop, our integration with the platforms, and integration with Splunk Enterprise.

What was our ROI?

We've had some challenges justifying our return on investment because of the development work and the continual efforts to maintain the solution. We haven't seen the return on investment yet, but I'm hopeful it can get us there.

What's my experience with pricing, setup cost, and licensing?

Splunk SOAR is an expensive solution for an organization of our size. I don't like the solution's licensing model.

Which other solutions did I evaluate?

Before choosing Splunk SOAR, we evaluated other options. Splunk SOAR easily integrated with our Splunk solution, which was our main key. We are already a Splunk customer, which made the contracting easy.

What other advice do I have?

Our organization monitors multiple cloud environments. Monitoring multiple cloud environments using Splunk SOAR is fairly easy when the integrations work. Some apps within Splunk SOAR require you to configure them and ensure they maintain their connection and that they're updated. We've had several issues with third-party ones and those developed by Splunk.

It is important for your organization that Splunk SOAR has end-to-end visibility into your cloud-native environment. We're security-focused, and we want to be able to look at the logs that are in our native applications.

For the use cases we've implemented, Splunk SOAR has helped reduce our mean time to resolve. However, there's been a lot of time to develop that. Overall, I haven't seen that I've saved time yet, but I expect we will in the future. Splunk SOAR can save the analyst up to 30 minutes for a single malware analysis playbook.

Overall, I rate Splunk SOAR a six out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2239935 - PeerSpot reviewer
Security Engineer at a university with 501-1,000 employees
Real User
Has the ability to connect it to external apps
Pros and Cons
  • "It has definitely saved a decent amount of time for our analysts so they can focus on other tasks."
  • "We've run into a few minor issues. Some of the playbook writing is a bit complicated. We've had a few hiccups with the source control. We'd really like to use GitHub deployment keys for a dedicated account. We haven't been able to do that. I think those are some of the major ones."

What is our primary use case?

We are primarily using it to automate tasks for our incident response team. They use it to block suspicious traffic from our network detection system and for alerts from our endpoint security system. Those are the two major use cases we're using it for right now.

How has it helped my organization?

It has definitely saved a decent amount of time for our analysts so they can focus on other tasks. This gives us more value for man hours.

It has definitely improved our business resilience. It's given us greater visibility into the environment we have and the ability to collect all of the threat and log data and put it into one central place.

What is most valuable?

The ability to connect it to external apps is the most valuable feature. We've also gotten a lot of use from writing custom apps for some of our authentication systems for password scramble.

Splunk's ability to predict, identify, and problem-solve in real time is really good.

Splunk's ability to provide business resilience by empowering staff is fairly high. It detects issues as they come up and responds to them.

We have seen time to value. I did help configure it, but we do have the cloud solution, so it was mostly in place.

It has definitely helped to reduce our meantime to resolve. Having it there to automatically take action as events come in and not needing the analysts to have to go out and have a look is how it saved time.

What needs improvement?

We've run into a few minor issues. Some of the playbook writing is a bit complicated. We've had a few hiccups with the source control. We'd really like to use GitHub deployment keys for a dedicated account. We haven't been able to do that. I think those are some of the major ones. 

There is a general learning curve as far as playbook writing goes. 

For how long have I used the solution?

I have been using SOAR for four to five months.

What do I think about the stability of the solution?

Stability is good. We've had a few hiccups with apps, but never a major outage. I would rate it an eight out of ten.  

What do I think about the scalability of the solution?

I haven't really grown it very wide yet, but I could easily foresee us doing that.

How are customer service and support?

I've opened a few tickets for different issues with apps, and they have always been responded to fairly quickly. I'd give support a ten out of ten. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I did help configure it but we have a cloud solution, so it was mostly in place.

The development was fairly straightforward. There were some issues setting up the single sign-on, but we were able to get help from Splunk to get all that straightened out. The roles in user accounts and onboarding were all fairly straightforward. App configuration is also something that's pretty streamlined and intuitive.

We did it all in-house.

What was our ROI?

We have seen ROI in its ability to streamline and automate mundane tasks that we would run into on a daily basis. It freed up DevOps people from having to maintain custom tools that were previously used to complete similar tasks.

What other advice do I have?

I would rate Splunk SOAR a nine out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Mack Scott - PeerSpot reviewer
Cyber Security Network Security Engineer at Cirrus Logic
Real User
Top 20
We can automate and orchestrate our detections and quickly respond to them
Pros and Cons
  • "In Splunk SOAR, I find the playbooks valuable. We get to create multiple playbooks, and within each playbook, there is a different type of investigation attached to it, which helps out an analyst or new analysts coming on board."
  • "They can improve on what they are currently doing. They can provide more playbooks or at least template playbooks that are in their repository."

What is our primary use case?

One of our use cases is to automate any kind of process after investigation. When going into an investigation, we want to make sure that we have the right tools to use. Instead of having multiple tools, we can bring them all into one platform, such as Splunk SOAR, to provide us with that information.

How has it helped my organization?

Splunk SOAR has not benefited us yet because we are currently in the development process, but I believe that in the future, it will help us streamline our process and our RTR to respond and detect. It is going to help us in the future, but it has not brought us any benefit yet because we are currently building it up.

It is very important that Splunk SOAR has end-to-end visibility into our cloud-native environment. If there is no visibility, then there is no ability for us to detect on time and respond in time. It knocks out a lot of that time discrepancy.

Splunk SOAR has not yet helped reduce our mean time to resolve. It will be helping us in the future due to its playbooks and its compatibility with Mission Control and other Splunk integrations.

It has helped us with our business continuity and our ability to respond to different threats that might be out there.

Splunk SOAR has not saved us time in alert triage. We are still in the early stages of getting Splunk SOAR onboarded and developed, but I believe that it will significantly reduce our time to triage. Similarly, Splunk SOAR has not saved us time in threat response, but it will do so in the future.

Splunk's unified platform has helped consolidate networking, security, and IT observability tools. Splunk's unified platform has been great for every organization. Every analyst has been able to use one unified area.

What is most valuable?

In Splunk SOAR, I find the playbooks valuable. We get to create multiple playbooks, and within each playbook, there is a different type of investigation attached to it, which helps out an analyst or new analysts coming on board. When they get an incident, they do not need to find out where to start. All they have to do is to go to a particular playbook. It will give them end-to-end specifics on what to do and how to process it.

What needs improvement?

They can improve what they are currently doing. They can provide more playbooks or at least template playbooks that are in their repository. That is one area.

Another area would probably be related to onboarding different playbooks or different tool sets that new engineers have. Eventually, they will get there to ingest more tools and datasets into their SOAR. 

In terms of additional features, it is hard to say. There can be more integration with other data ingestion platforms out there, not just Splunk.

For how long have I used the solution?

We have been using it for about one month.

What do I think about the stability of the solution?

We have not played with it too much yet. Once we are able to play with it more and get more details from it, we can respond to that.

What do I think about the scalability of the solution?

It can be very scalable just because of the number of different apps that the community pushes to it. Right now, it is not there yet, but I believe in the near future, it is going to be the best growing platform out there.

How are customer service and support?

Splunk's customer service is great and impeccable. I believe that they have been a very valuable resource to our organization and our team.

I would rate their support an eight out of ten just because I believe that no one really gets a ten. It is an eight just because the answers that they cannot answer for us, they are able to get from the community. The community really helps out, but they are always there to help, and they are always responsive.

How was the initial setup?

We are using Splunk Cloud, the public cloud, but we also have on-prem. We use AWS.

As the initial start of the Splunk SOAR, we are getting started with developing the playbooks and getting the configurations set up with our users and toolsets. It has been pretty easy so far. I have not had any hiccups, but we will see where that takes us as we finish our development.

What about the implementation team?

We did not use any integrator or reseller.

What was our ROI?

We have just started getting our metrics developed, ingesting into Splunk, and showing that to the executives.

What other advice do I have?

I would rate Splunk SOAR a nine out of ten just because it does hit all points for the use cases as an analyst, engineer, or developer. It allows us to automate and orchestrate all of our detections and respond to them very quickly.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Pulkit Thakur - PeerSpot reviewer
Data Engineering Sr Analyst at Accenture
Real User
Automates many of your threat-related activity and give you alerts based on the criteria
Pros and Cons
  • "The solution’s dashboard is really good and customizable. It also has a good UI."
  • "The application does not work properly and does not pass the log-based configuration. I feel that some kind of review should happen in the application. This review should validate things so that we can get the right information. Splunk does not tell us where the IP address is associated with."

What is our primary use case?

The solution provides information on user accounts. The solution has playbooks that check the user with server ID. It checks the domain name and IP address of the web page.

How has it helped my organization?

The solution has helped my company in many ways. It gives us information on the IP or server that is related to physical services. The tool also gives us alerts.

What is most valuable?

The solution’s dashboard is really good and customizable. It also has a good UI.

What needs improvement?

The application does not work properly and does not pass the log-based configuration. I feel that some kind of review should happen in the application. This review should validate things so that we can get the right information.

Splunk does not tell us where the IP address is associated with.

For how long have I used the solution?

I have been using Splunk SOAR for more than one year.

What do I think about the stability of the solution?

I would rate the solution’s stability an eight out of ten.

What do I think about the scalability of the solution?

I would rate the solution’s scalability a ten on ten. There are more than twenty users of the solution in our company. We plan to increase the usage.

How are customer service and support?

I would rate the solution’s support around seven to eight.

How would you rate customer service and support?

Positive

How was the initial setup?

The solution’s setup is easy.

What was our ROI?

The solution gives us better ROI.

What's my experience with pricing, setup cost, and licensing?

The solution’s pricing is costing at some points.

What other advice do I have?

I would rate the overall solution a nine out of ten. The tool automates many of your threat-related activity and gives you alerts based on our criteria. This solution is definitely useful. The product gives us the power to handle anything.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Splunk SOAR Report and get advice and tips from experienced pros sharing their opinions.
Updated: July 2025
Buyer's Guide
Download our free Splunk SOAR Report and get advice and tips from experienced pros sharing their opinions.