What is our primary use case?
I have been using Swimlane for almost four years.
There are multiple use cases for Swimlane. I have mainly worked on phishing triage, building use cases for customers, automating their use cases using playbooks, and designing workflows. The implementation was for case and incident management, and we also have vulnerability management.
For phishing triage, we monitor a mailbox and as soon as any email arrives in the inbox folder, the workflow is triggered, and we grab all the details of that email. We parse it and then use VirusTotal for obtaining scores for the email, which is how phishing triage works in Swimlane.
What is most valuable?
Swimlane is a low-code security platform with most things having connectors and plugins available from the marketplace. You can directly download and configure them and use them instead of writing multiple lines of code; you can directly use the connectors and get your task automated.
Regarding my experience using those plugins from the marketplace, you can download whatever the use case is. Based on the use case, you just download the connectors or plugins available, configure them, and once those configurations are complete, create a playbook, design the workflow, and you can directly use an expression for obtaining the desired result. You can create a record for the SOC analyst team, and they can work on specific records, and you can also create UI buttons for the SOC analyst team. You can design another playbook that will be linked with the button. The SOC analyst will have a view to work on the records and can reassign tasks with everything done from the UI. You just need to integrate the workflow with the button. For instance, you can send notifications via multiple endpoints such as Microsoft Teams or Slack. You can configure the Slack connectors, create a playbook workflow, and then the SOC analyst can click a button to have the workflow post messages to the Slack channel, integrating multiple APIs using connectors.
Swimlane positively impacts my organization as it is a product company that provides cybersecurity automation. Initially, it was Swimlane, but with multiple releases, now we have a product called Turbine, where we can do the same thing in a more advanced way with agentic AI and the use of AI/ML capabilities.
What needs improvement?
You can improve Swimlane by allowing customers to raise feature requests if they feel some important fields are missing, and they can reach out to the support team to suggest features that need to be added or to request a simpler UI.
For how long have I used the solution?
I have been working in the cybersecurity domain for five years.
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
For Swimlane's scalability, we use Docker and Kubernetes for deployments, typically using three pods for task API and task API pods. It depends on the number of users, and if a company has many users, we can have three replicas of each pod. Standalone deployments are available for fewer users, ensuring Swimlane can handle multiple users without crashing.
How are customer service and support?
Customer support is quite good, taking time for resolution but acknowledging within the timeframe and trying to resolve use cases as quickly as possible, including escalations to senior staff if needed.
Which solution did I use previously and why did I switch?
This is the first SOAR product I have used in cybersecurity. I later transitioned to Splunk SOAR.
What was our ROI?
I have seen a return on investment with Swimlane. I generally worked on the automation side to develop playbooks and workflows. If a company uses Swimlane, the SOC analyst team typically handles multiple events such as true positives and false positives. If everything is automated, we can filter out false positives or true positives, allowing for UI customization where the SOC analysts can trigger notifications and actions with buttons to create another playbook or automate using cron jobs, saving time for the SOC analyst team.
Which other solutions did I evaluate?
I have not evaluated other options before choosing Swimlane.
What other advice do I have?
Swimlane offers this too, but it depends on the user's preference, similar to how some prefer Flipkart while others prefer Amazon. Since I worked with Swimlane, I felt more comfortable compared to Splunk.
Regarding Swimlane's AI capabilities, I think we have pretty good security for credentials with Bitwarden, which we promote for sharing all details. Additionally, there is an architect who designs the workflows or playbooks, and development will be done based on that, which is quite good.
Regarding Swimlane's AI capabilities, its accuracy and reliability are quite good. I have worked with multiple APIs, and when we have the proper credentials, everything gets done on time, the accuracy remains high, and it takes less time. We compare response times of the APIs, and since we use plugins and connectors, it depends totally on the API response and the result from the API. Swimlane automates the SOC analyst tasks.
Swimane is quite good without needing any additional improvements.
I would advise others to consider Swimlane as it is quite simple and user-friendly, with training provided for new customers or developers through good training materials, making it easy to learn for those unfamiliar with Swimlane. I would rate Swimlane around eight on a scale of one to ten.
I feel that compared to other tools such as Splunk, which has other functionalities and was in the market before Swimlane, the reason for my rating is that Splunk provides more flexibility in writing code. You can have a custom code block to write Python scripts.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?