No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer1260045 - PeerSpot reviewer
Senior Analyst at a computer software company with 11-50 employees
Real User
Jun 20, 2022
Easy to install wth good documentation and automation capabilities
Pros and Cons
  • "The automation part of the product is great."
  • "The automation part of the product is great, Splunk SOAR can easily be connected with a lot of solutions that are available out there, and the in-built apps are pretty useful to me."
  • "The scalability could be better."
  • "The scalability could be better."

What is most valuable?

The automation part of the product is great. 

Splunk SOAR can easily be connected with a lot of solutions that are available out there. The in-built apps are pretty useful to me.

It's easy to install and offers good documentation. 

What needs improvement?

I don't have much experience with that. I'm not sure as I don't have much technical knowledge about SOAR in general. I have a little bit of experience with SOAR. I can't speak to any shortcomings right now. 

The scalability could be better.

It's an expensive solution. 

For how long have I used the solution?

I've worked with the solution for the last year or so.

What do I think about the stability of the solution?

The solution is stable. There are no bugs or glitches and it doesn't crash or freeze. It's reliable. 

Buyer's Guide
Splunk SOAR
April 2026
Learn what your peers think about Splunk SOAR. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
893,244 professionals have used our research since 2012.

What do I think about the scalability of the solution?

We faced a couple of issues scalability-wise, I would say it is average. 

How are customer service and support?

I've never contacted technical support. I wouldn't be able to comment on their level of helpfulness. 

How was the initial setup?

The solution's initial setup is easy and straightforward. They do offer great documentation, which helps with the process.

I'm not sure how many people were involved in the deployment or maintenance of the product. 

What about the implementation team?

I can't speak to if consultants or integrators were involved. I just have general knowledge of the setup and the solution itself. 

What's my experience with pricing, setup cost, and licensing?

I use a trial version, not an actual version. We are partners. We have our work license. My understanding is that the cost is pretty high compared to others, however, I'm not sure of the exact price. 

Users just need to pay for their package. There are no add-on costs on top of that. 

Which other solutions did I evaluate?

I'm not able to compare it with other solutions as I don't have experience with other solutions.

What other advice do I have?

We're a Splunk partner. 

I'm dealing with the latest version of the solution. 

I'd recommend the solution to companies just starting out. 

I would rate the solution eight out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Filip Stojkovski - PeerSpot reviewer
VP - Security Automation Lead at a financial services firm with 10,001+ employees
Real User
May 3, 2022
Feature rich, useful automation playbook, and reliable
Pros and Cons
  • "I have found all the security automation platform features of Splunk SOAR to be good. The Automation playbook development is highly useful."
  • "I have found all the security automation platform features of Splunk SOAR to be good, and the automation playbook development is highly useful."
  • "The Splunk SOAR platform was not designed specifically for case management which is why this area needs improvement."
  • "The Splunk SOAR case management feature lacks some of the functionalities like the possibility to fully customize the fields for the tickets/events and create custom statuses."

What is our primary use case?

Security Operations and Incident response processes automation and alerts enrichment.

What is most valuable?

I have found all the security automation platform features of Splunk SOAR to be good. The Automation playbook development is highly useful.

What needs improvement?

The Splunk SOAR case management feature lacks some of the functionalities like the possibility to fully customize the fields for the tickets/events and create custom statuses. 

For how long have I used the solution?

I have used Splunk SOAR within the last 12 months.

What do I think about the stability of the solution?

Splunk SOAR is a stable solution.

What do I think about the scalability of the solution?

The scalability of Splunk SOAR is good.

We have approximately 100 people using this solution in my organization.

How are customer service and support?

The technical support is good.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup of Splunk SOAR is complex. It has multiple integrations, deployable on many different development infrastructure stages of production. It has a full life cycle.

What about the implementation team?

We have approximately two people for the maintenance and support of Splunk SOAR.

What's my experience with pricing, setup cost, and licensing?

The price of Splunk SOAR is reasonable.

What other advice do I have?

My advice to others is they will need some Python developers for Splunk SOAR because it's not possible to only throw some blocks of Python code and it will work. You will need some experienced Python developers if you want to work with this platform.

I rate Splunk SOAR a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Splunk SOAR
April 2026
Learn what your peers think about Splunk SOAR. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
893,244 professionals have used our research since 2012.
Hari Haran. - PeerSpot reviewer
Technical Associate at Positka
Reseller
Top 20
Jan 23, 2021
Very stable with a straightforward setup and good performance
Pros and Cons
  • "The customization continues to be excellent."
  • "Compared to other products, Phantom seems to be easy to use and the ability to customize is high."
  • "In the beginning, we couldn't find any specific documents for every function. It wasn't easy to navigate to what we needed."
  • "The solution is a bit more expensive than other offerings."

What is our primary use case?

We are doing some automation on the SIM and we are getting some SIMS and we are looking for some automation to improve the security environment. That's how we are currently using Splunk.

What is most valuable?

Comparing this product to other SOAR tools, most of the items are the same, however, the UI of Phantom is pretty good if you compare it against other SOAR tools.

The work formation and the templates based on some use cases all look good.

The product is very easy to use and has a very good user experience.

The solution is very stable.

The initial setup is pretty straightforward.

We've found the written documentation to be excellent.

The performance is very good.

We've found the solution has recently improved its UI.

The customization continues to be excellent.

What needs improvement?

In the beginning, we couldn't find any specific documents for every function. It wasn't easy to navigate to what we needed. However, lately, it has improved and we are able to find Splunk documents for all the functionalities of Phantom. 

It would be helpful, on the other hand, if there were videos regarding each functionality. That would make it even easier to work with Phantom. We are able to find some documentation in written form, and that's fine. If it is in a video format, then it would be better due to the fact that, in some environments, we find some other issues or something and it would be nice to have a visualization of the process.

The solution is a bit more expensive than other offerings.

I'd recommend that the solution add some new apps, or some average services, like bots or G-Suite. We may already have G Suite in Phantom. Bots, like any common VPN service, would be great, however.

For how long have I used the solution?

I've used the solution for about one year or so. It hasn't been an extremely long amount of time just yet.

What do I think about the stability of the solution?

We haven't had any stability issues at all. It doesn't crash or freeze. It's not buggy. There aren't glitches that I've seen. It seems very stable and very reliable. 

We have had an issue related to the firewall. However, that had nothing to do with Splunk directly.

What do I think about the scalability of the solution?

We have five or six individuals that handle Phantom at any given time, as needed.

We didn't try to scale Splunk due to the fact that we already have a VM and we are working on that. We don't use Phantom too much as we have some community license. Based on the license, we are running simple actions only, and therefore we are not giving that much of a workload to Phantom.

How are customer service and technical support?

I haven't been in contact with technical support at all. I can't speak to their responsiveness or how helpful they would be.

That said, some of my colleagues have done a boot camp with technical support, and they likely have had contact. I haven't heard of anything negative.

Which solution did I use previously and why did I switch?

I didn't previously use a different tool. This is my first SOAR tool. I've also used Demisto. These are the two tools that I have and that I currently work with.

It's my understanding, from a customer's perspective, that the better solution is Demisto based on licensing costs, however, in terms of the performance and efficiency involved, it's Phantom. Phantom is a bit more expensive in general.

How was the initial setup?

The initial set up seems pretty easy. While I didn't personally handle any part of it, it's my understanding that it's not a big issue to implement everything. We were able to install the file easily. It was straight forward. When we were handling the clustering part, it was a little difficult as we had some license issues. We need a license to get that clustering part set up. It would be ideal if they offered at least a trial license so that we could see how it works and the formation, etc. Right now, without any license, we aren't able to do this clustering part.

I'm unsure as to how maintenance is handled on the solution. I believe we need to handle it manually as we did not install any bot that would handle anything. There may be alternative workarounds in newer versions.

What about the implementation team?

I'm not working deeply on Phantom. In fact, I'm concentrating more on SIM. My colleagues are the ones working on Phantom. Therefore, I'm not sure if we actually had outside assistance or handled everything internally.

What's my experience with pricing, setup cost, and licensing?

We use a community license. We don't have to pay for any actual licensing. However, the solution, when you have a paid version, is quite costly. That said, in terms of performance, it's worth the extra cost. Also, it's my understanding that everything is included in the licensing cost, once you pay for the product. There aren't any added fees.

What other advice do I have?

We have a business relationship with Splunk. We're partners.

We're using the solution on our VM and also on our database cloud.

I'd recommend the solution to other organizations. Compared to other products, Phantom seems to be easy to use and the ability to customize is high. Compared to the older version, the newer version is very customizable. We can very easily create custom functions. The UI looks good and is also improved. 

I would rate the solution eight out of ten.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
General Manager at Adeline
Reseller
Mar 21, 2023
Robust, easy to expand, and thoroughly documented
Pros and Cons
  • "Our customers find it easy to conduct searches and consider it an excellent content management system."
  • "In my opinion, the focus should be on improving its simplicity, specifically the interface, and configuration."

What is our primary use case?

We use Splunk SOAR internally.

We are resellers and an integration company.

What is most valuable?

Our customers find it easy to conduct searches and consider it an excellent content management system.

What needs improvement?

The initial setup could be simplified.

In my opinion, the focus should be on improving its simplicity, specifically the interface, and configuration.

For how long have I used the solution?

I have been familiar with Splunk SOAR for six years.

What do I think about the stability of the solution?

In our experience, Splunk is very good. When it comes to stability, it's the best of the best. 

We have worked with many other products, and we have not encountered any issues or received any negative feedback regarding Splunk's stability.

What do I think about the scalability of the solution?

Splunk SOAR is a scalable product.

Splunk is used by 20 of our customers. They are large enterprises such as banks and government agencies.

How are customer service and support?

My engineer recently stated that there was no need to reach out to Splunk support because the product is very stable and well-documented.

Which solution did I use previously and why did I switch?

We work with both Splunk Enterprise and Splunk Enterprise Security.

We only have limited expertise with Splunk SOAR.

We work with various other products besides Symantec. Around six or seven years ago, we also worked with Symantec, where we evaluated Symantec Closet, our Configuration Management (CM) solution. However, we eventually chose Splunk as our preferred product and currently use only Splunk, not any other products.

How was the initial setup?

The initial setup is complex.

We don't have much experience with this project as we have only been working with it for a year. I may not be able to provide you with extensive information about it.

What's my experience with pricing, setup cost, and licensing?

In my opinion, the price is high, but if you want good products, you have to be willing to pay for them.

There is a licensing fee required.

I believe that the cost per customer typically ranges from one hundred thousand to one million US Dollars.

Which other solutions did I evaluate?

I believe that Splunk is essential for us and our customers, and we require qualified engineers to use it effectively. However, if we have a skilled engineer, they will likely not have any further questions or issues with the solution.

What other advice do I have?

I would rate Splunk SOAR a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
Splunk Consultant at Yssy
Real User
Jun 21, 2022
Useful playbooks, easy integration, and helpful community support
Pros and Cons
  • "The most valuable features of Splunk SOAR are the easy integration with other solutions, including other Splunk solutions. The most important playbooks we need on the market come already on the Frontend. However, nowadays, Splunk changed its name, it's not Frontend anymore, it's Splunk Store. This is a very strong point."
  • "The most valuable features of Splunk SOAR are the easy integration with other solutions, including other Splunk solutions, and the most important playbooks we need on the market come already on the Splunk Store, which is a very strong point."
  • "Splunk SOAR has room to improve its offering for small-sized customers. The price is not fair for smaller-sized customers."
  • "Splunk SOAR has room to improve its offering for small-sized customers. The price is not fair for smaller-sized customers."

What is our primary use case?

Splunk SOAR can be deployed on-premise and in the cloud.

What is most valuable?

The most valuable features of Splunk SOAR are the easy integration with other solutions, including other Splunk solutions. The most important playbooks we need on the market come already on the Frontend. However, nowadays, Splunk changed its name, it's not Frontend anymore, it's Splunk Store. This is a very strong point.

For how long have I used the solution?

I have been using Splunk SOAR for approximately two years.

What do I think about the scalability of the solution?

We have approximately six users from one client and four from another client using Splunk SOAR.

How are customer service and support?

The technical support from Splunk SOAR is good. However, you can always resolve the problem with the community. Splunk has a very good community, and most of the time, we find a solution much better, it is easier and quicker in the community, instead of waiting to open a ticket for Splunk. When you open a ticket, you go into a queue, then the feedback is a little bit slower.

How was the initial setup?

The initial implementation of Splunk SOAR is in the middle range of difficulty. It is not very easy because you need to understand a little bit of the solution to deploy it, but as soon as you learn it, it becomes very easy because most of the integrations are ready. It's very easy to change playbooks, or create a new playbook because you do not need to know how to code. It doesn't matter how the language of the coding it's running in the back end to learn your playbook. It is up to you to create a playbook using the UI interface. If you want, you can code your own if you enjoy coding. You can have the opportunity to change or create some playbooks with Python codes, but you don't need to do that, it is optional. Anyone can develop their own playbooks.

The deployment of Splunk SOAR on premises took approximately 15 days, and deployments in the cloud took approximately two days. You learn how to integrate the solution by doing it. It took about two days because it was my first time, but the next time, when I do it, it will take approximately half a day.

What's my experience with pricing, setup cost, and licensing?

Splunk SOAR has room to improve its offering for small-sized customers. The price is not fair for smaller-sized customers.

The price of Splunk SOAR is based on the number of people using it. Once you increase the users, the prices go goes up. The customer receives a license for the user that is going to operate it in their environment.

What other advice do I have?

I rate Splunk SOAR a ten out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1540500 - PeerSpot reviewer
Head of Cyber Security Operations Centre at a comms service provider with 1,001-5,000 employees
Real User
May 14, 2021
Easy to use and popular with our team but is a bit expensive
Pros and Cons
  • "I'm just a beginner on the solution and it's pretty easy for me to use."
  • "I'm just a beginner on the solution and it's pretty easy for me to use."
  • "We've had trouble implementing the solution with Microsoft products. There seems to be an integration gap."
  • "We've had trouble implementing the solution with Microsoft products. There seems to be an integration gap."

What is most valuable?

I'm just a beginner on the solution and it's pretty easy for me to use. 

Our team likes it. They've been using it for a while and they really seem to like it. They know more about it than I do at this point, as I'm still new.

It's a default for a lot of things on our system.

What needs improvement?

We've had trouble implementing the solution with Microsoft products. There seems to be an integration gap. 

The pricing of the product could be more reasonable.

For how long have I used the solution?

While I am a beginner on the Splunk platform, our team has a good amount of experience with it overall. I've personally only been working with it for two or three months or so. It hasn't been that long.

How are customer service and technical support?

I've never actually opened a ticket with Splunk technical support in the past. I can't speak to how helpful or responsive they are. I don't have any experience with them to discuss how helpful or responsive they are.

What's my experience with pricing, setup cost, and licensing?

The licenses are quite expensive at this time. They need to work on the pricing in order to make the costs much more reasonable.

What other advice do I have?

We are a customer and an end-user. We don't have a business relationship with Splunk.

I can't speak to which version of the solution we're using.

I'd rate the solution at seven out of ten overall. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user1561083 - PeerSpot reviewer
Cyber Security Solution Architect at a tech services company with 11-50 employees
Real User
Apr 30, 2021
Easy to create playbooks, easy to deploy, and good integration capabilities and searching methodologies
Pros and Cons
  • "I like the integration capabilities of Phantom. It has a lot of integrations with other products. Its searching methodologies are also good. It is also easy to understand and easy to create playbooks."
  • "I like the integration capabilities of Phantom; it has a lot of integrations with other products, its searching methodologies are also good, and it is easy to understand and easy to create playbooks."
  • "I haven't used it fully, but based on my usage, I could not find simulation tools and features. It currently lacks simulation features, which are important for me for creating a playbook. It is also very expensive for my region."
  • "It currently lacks simulation features, which are important for me for creating a playbook."

What is our primary use case?

My primary use case was for the MITRE ATT&CK parameters. I have some experience with MITRE ATT&CK for SIEM and SOAR solutions.

What is most valuable?

I like the integration capabilities of Phantom. It has a lot of integrations with other products.

Its searching methodologies are also good. It is also easy to understand and easy to create playbooks.

What needs improvement?

I haven't used it fully, but based on my usage, I could not find simulation tools and features. It currently lacks simulation features, which are important for me for creating a playbook.

It is also very expensive for my region.

For how long have I used the solution?

I have been using this solution for one year.

What do I think about the scalability of the solution?

I didn't focus on that feature, so I cannot say anything about that.

How are customer service and technical support?

I don't have any experience with their technical support. My customer was using it in their company, and I had some experience with this solution over there while managing their security solutions, but I didn't get in touch with Splunk specialists.

How was the initial setup?

Its initial setup is straightforward. It is similar to most of the solutions. I didn't have any complexity.

What's my experience with pricing, setup cost, and licensing?

I don't know the exact price, but for my region, it is very expensive.

What other advice do I have?

I would recommend this solution, but it also depends on the price. Splunk is number one for SIEM or SOAR. Another solution that I would recommend is Palo Alto XSOAR. 

I would rate Splunk Phantom a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user1404753 - PeerSpot reviewer
Senior Data Analyst at a financial services firm with 10,001+ employees
Real User
Aug 24, 2020
Great automation capabilities, easy to use, and offers good GUI
Pros and Cons
  • "So far, the interface is very easy to use."
  • "If a company wants to automate redundant work, this solution is perfect for that."
  • "It would be ideal if we could automate processes even more."
  • "It would be ideal if we could automate processes even more."

What is our primary use case?

We're not really creating the use cases. Our internal team is developing the use cases. Right now, we have automated the whole phishing process. After that we are still planning to automate a few more things like malware investigation and then from there other processes.

What is most valuable?

We're in the POC phase. We need more time to get used to the solution and to understand it better to discover the most useful features.

So far, the interface is very easy to use.

The GUI is great.

The features in the Phantom playbook are all very good.

You can build different playbook and you can play with the playbook. One playbook can give you insights into URL applications, one playbook you can give the reputation about the file access. You can build different playbooks and after integrating all the playbooks you can come up with some organizational directions and decisions. It will give you very good insights into various incidents.

The solution is great for automating redundant work.

It's difficult sometime to manage the amount of reported suspicious emails. Using an intervention like this solution helps make that task easier.

What needs improvement?

We haven't had too much experience on the solution.

The solution is relatively new in the market.

It would be ideal if we could automate processes even more.

The interface is great, however, they could still keep refining it to make it even more user friendly.

For how long have I used the solution?

We have used the solution over the past year.

Which solution did I use previously and why did I switch?

At a previous organization, I did work with another tool in Beta. It was able to provide UVA capacity. I'm not sure if they used a different tool at this current organization.

The Phantom has better GUI, however, I'm not able to clearly see the risk fabric.

How was the initial setup?

I wasn't part of the deployment team. I have no idea if the initial implementation is straightforward or complex.

Technically, we are still in the deployment phase. We haven't finished yet. We are yet to go live. IN the next few weeks we'll go live, however, only on the phishing features.

Which other solutions did I evaluate?

I'm not aware of the company looking into other options before choosing this solution. All of this was handled by the procurement team, and I am not a party to their decision-making process.

What other advice do I have?

I'm not sure which version of the solution we're currently using.

If a company wants to automate redundant work, this solution is perfect for that. Very specific processes can be easily automated to save time. That way, analysts can invest their time elsewhere. Phantom is one of the great tools for reducing redundancies. 

I'd rate the solution eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Splunk SOAR Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2026
Buyer's Guide
Download our free Splunk SOAR Report and get advice and tips from experienced pros sharing their opinions.