What is our primary use case?
We agreed to speak about Splunk SOAR this time.
I have worked with Splunk SOAR since 2025.
I work with Splunk SOAR as an integrator.
Splunk SOAR is used for cyber security or security operations relative to cyber security, SOC, DevOps, or where security is more important than other things, such as banking and insurance.
How has it helped my organization?
Splunk SOAR consolidates tools in my environment significantly, notifying users about ongoing malicious activities based on integrated security features in my banking app.
Before implementing Splunk SOAR, we did not utilize any enterprise solutions but integrated security features in our applications with our own antivirus and log provider.
It substantially improves business resilience as it helps predict, identify, and solve problems in real time, providing significant security to systems against various threats.
What is most valuable?
The biggest advantage I see from my personal experience as an integrator with Splunk SOAR is that it integrates with most of the security features among the Defenders, Microsoft Defender, firewalls, CloudWatch, and AWS security agents, as well as EC2 machines, firewalls, EDR, IAM, email security, and antivirus. It automates the security process over phishing emails and any other brute force attacks. It helps quite a lot because if 100 phishing emails were sent to a domain, a developer can only reach one, two, or five, but for hundreds of others, it actually supports better automated playbooks and provides major security.
Splunk SOAR introduced some new and innovative capabilities or approaches that transformed the way my SOC operates.
Splunk SOAR provides playbooks for automatic security features, such as for firewalls, phishing mails, and utilizing Defenders or virtual tools. A playbook maintains its algorithms or processes, so if any kind of security issue arises, the playbook automatically runs and handles actions such as IP blocking or resolving brute force attacks, notifying the admin about suspicious users.
After implementing Splunk SOAR, the training process for my SOC team to use playbooks takes a long time during the whole integration part, as it retrieves all credentials from us, whether for an EC2 machine or any antivirus. It takes about one to two months for the team to fully sustain and know the processes of the playbooks and security, particularly for three or four individuals in the cyber security or DevOps team.
Splunk SOAR significantly reduces the time spent on monotonous security tasks. In banking, insurance, or healthcare, automated services for addressing phishing emails and security threats are common. Having a manual workforce of two or three individuals can only handle five or ten security threats while Splunk SOAR automates the entire process across apps and machines, making it easier and notifying the admin about the threats.
If someone tries to breach, Splunk SOAR immediately processes incoming requests, validating them and blocking any unsecured requests, which reduces a lot of time and effort.
With the help of the playbook viewer, I assess the visibility provided by Splunk SOAR as very positive, especially for security purposes. If someone is attacked by 100 users, it blocks all the users, while individual developers such as myself can only handle two or three at a time. The automated process of Splunk SOAR handles all the processes concurrently, making it a game-changing solution.
It helps reduce mean time to resolve (MTTR).
It takes around 10 to 20 minutes to resolve one incident through the whole process and notify the admin of the issue. If there are multiple incidents, calculating the time taken for each, it generally requires around 40 to 50 minutes to resolve five incidents.
What needs improvement?
They should elaborate on existing features or add new ones. They provide good documentation on all their features, and any new features will come with corresponding documentation and support.
They should add an AI assistant to automate the entire process, summarizing it for the admin, which will ease debugging and re-implementation, providing robust security features against future incidents.
The installation of Splunk SOAR is complex, requiring integration with various tools such as CloudWatch, antivirus, and EC2 machines, making it difficult.
For how long have I used the solution?
I have worked with Splunk SOAR since 2025.
What do I think about the stability of the solution?
I would rate the solution at about 97 to 98 percent stable; it can resolve threats but needs to operate faster, possibly by integrating an AI assistant.
What do I think about the scalability of the solution?
It is easy to scale as it provides many integration tools.
How are customer service and support?
I have reviewed its documentation, which covers many integration details. I have not yet contacted customer service, but I have seen good reviews regarding guidance and support.
Which solution did I use previously and why did I switch?
Before implementing Splunk SOAR, we did not utilize any enterprise solutions but integrated security features in our applications with our own antivirus and log provider.
How was the initial setup?
The installation of Splunk SOAR is complex, requiring integration with various tools such as CloudWatch, antivirus, and EC2 machines, making it difficult.
What was our ROI?
It is a good investment and effectively reduces threats and major incidents for security purposes, thus is beneficial for major industries such as banking and cyber security-related issues such as DevOps.
Which other solutions did I evaluate?
There are many competitors such as IBM QRadar SOAR, FortiSOAR, Science, and D3 Security, but I used Splunk SOAR directly for our consent project without exploring competitors due to cost considerations.
What other advice do I have?
It is a hybrid model, using EC2 instances for deployed applications and utilizing antivirus on the machines.
We use Azure.
I believe the pricing varies depending on our use case. Although the consent project is moderate, it becomes quite expensive for banking solutions due to covering around seven to eight products.
Splunk SOAR makes it easy to visualize and troubleshoot my cloud-native environments by providing dashboards to analyze and manage.
It saves time in alert triage, directly notifying the admin of security issues in the apps within milliseconds, around 200 to 300 milliseconds.
It also saves time for threat response.
I would rate this review an 8 out of 10.