Splunk SOARFormerly Phantom
Overview
What is Splunk SOAR?
Splunk now offers a security orchestration, automation, and response (SOAR) platform via its acquisition of Phantom. Splunk Security Orchestration and Automation (Splunk SOAR) provides playbook automation and is available as a standalone solution.
Awesome tool for Security Monitoring.
Splunk SOAR Robust and efficient.
Splunk SOAR Review
Great tool, wish for more documentation
A product that although has some qwirks, is one of the more flexible SOAR platforms to work with
General feedback
Exceptional threat reporting and efficient and robust algorithm based bug handling
Leading security automated orchestration platform
Splunk SOAR: A great orchestration and automation tool
We fuel our growth by having great protection in our system with automatic alerts.
"SOAR" your return on investments.
Splunk SOAR - The CIA of Software Security
This is a review from a consultant not from a final user
Ladies & Gentlemen ! Splunk SOAR with you anywhere and everywhere.
Top Performing Splunk SOAR with top-tier automation.
Awards
Products that are considered exceptional by their customers based on a variety of criteria win TrustRadius awards. Learn more about the types of TrustRadius awards to make the best purchase decision. More about TrustRadius Awards
Reviewer Pros & Cons
Pricing
What is Splunk SOAR?
Splunk now offers a security orchestration, automation, and response (SOAR) platform via its acquisition of Phantom. Splunk Security Orchestration and Automation (Splunk SOAR) provides playbook automation and is available as a standalone solution.
Entry-level set up fee?
- No setup fee
Offerings
- Free Trial
- Free/Freemium Version
- Premium Consulting/Integration Services
Would you like us to let the vendor know that you want pricing?
68 people also want pricing
Alternatives Pricing
What is KnowBe4 PhishER/PhishER Plus?
PhishER is presented as a lightweight Security Orchestration, Automation and Response (SOAR) platform to orchestrate threat response and manage the high volume of potentially malicious email messages reported by users. And, with automatic prioritization of emails, PhishER helps InfoSec and Security…
Product Details
- About
- Competitors
- Tech Details
- FAQs
What is Splunk SOAR?
Splunk SOAR Competitors
- Palo Alto Networks Cortex XSOAR
- Google Security Operations
- IBM QRadar SOAR
Splunk SOAR Technical Details
Operating Systems | Unspecified |
---|---|
Mobile Application | No |
Frequently Asked Questions
Comparisons
Compare with
Reviews and Ratings
(85)Community Insights
- Business Problems Solved
- Pros
- Cons
Splunk SOAR has proven to be a valuable tool for organizations seeking to automate and manage their security operations. Users have reported improvements in overall security posture and efficiency, particularly in the areas of threat detection, incident response, and vulnerability management. The software offers automation capabilities that help achieve almost zero downtime, along with user-friendly dashboards that provide valuable insights for analysts and managers.
One of the key use cases of Splunk SOAR is its ability to create playbooks based on widely recognized frameworks such as MITRE and NIST. This feature allows users to streamline their security operations by automating repetitive tasks and responding to security incidents effectively. The software also supports case management and offers integrated threat intelligence, enabling users to make informed decisions.
Consultants who have implemented Splunk SOAR have found it particularly helpful when receiving alerts from SIEM systems and undergoing training. It has proven to be a reliable tool for active threat detection, alert monitoring, and managing threats efficiently with its algorithm-based signature handling.
The customization feature of Splunk SOAR is highly valued by users as it enables them to include custom codes in their playbooks. This flexibility allows organizations to tailor the software to their specific needs and enhance its functionality.
Managed IT service providers have been deploying and managing Splunk SOAR for mid-sized businesses with great success. By automating tasks, detecting threats, and fostering innovation, the software helps these providers deliver efficient and effective security services.
In cybersecurity research sectors, Splunk SOAR is frequently employed for threat monitoring, logging, security analysis, and addressing fixes. Its comprehensive capabilities support improved incident response capabilities, build robust log analytics, and strengthen defense through security orchestration and integration.
Overall, Splunk SOAR provides organizations with the tools they need to respond quickly to security issues, automate workflows, enhance collaboration among team members, and improve incident resolution processes. With its powerful automation features and user-friendly interface, the software streamlines threat investigation, enriches actions based on alerts, and facilitates the monitoring and management of security alerts and notifications for various applications.
Effective Automation and Optimization: Many users have found that the automation and optimization features of the security system have been effective in reducing the probability of security incidents.
Seamless Integration with Other Security Tools: Reviewers appreciate the seamless integration of the security system with other security tools and systems, which allows them to address their specific needs and requirements. This integration enhances overall efficiency and effectiveness in managing security operations.
Centralized Platform for Managing Security Operations: The centralized platform for managing and coordinating security operations is considered a valuable feature by many users. It provides a unified interface to monitor, manage, and respond to security issues, streamlining workflows and enhancing productivity.
Confusing and complex user interface: Several users have found the user interface of the product to be confusing and complex, requiring extensive training to understand its functionality. Some users have described it as overwhelming and in need of improvement, especially for beginners.
High cost: The cost of purchasing and implementing the product is considered high by some customers, making it difficult for them to afford. Additionally, some users have mentioned that the advanced features of the software do not necessarily provide enough value for the price.
Lack of integration with other tools: Many users have encountered challenges when trying to integrate the product with other tools outside the Splunk environment. They have expressed limitations in integration with other products and a need for better documentation on the API.
Attribute Ratings
Reviews
(1-25 of 40)Awesome tool for Security Monitoring.
- We are able to focus more on resolution instead of monitoring incidents.
- Has helped us to reduce human efforts by almost 20 - 30 %.
Splunk SOAR Robust and efficient.
- Achieveing SLA.
- Saving Analysts time.
- Automation.
Splunk SOAR Review
- The playbooks are valuable. They are the core component. Being able to implement and build a code process to work through and scale out what we want to do is valuable
- Before its use, analyzing each email would take at least 15 to 20 minutes, with some complex cases taking up to 30 minutes...With the automation provided by Splunk Phantom, we could significantly reduce the amount of time and human effort required to complete this task
Great tool, wish for more documentation
- time to resolve
- fewer engineer hours spent on repetitive tasks
- easy customization if changes need to be made
A product that although has some qwirks, is one of the more flexible SOAR platforms to work with
- Data Orchestration for Metrics and Logging
- Faster Process Execution
- System Monitoring efforts for failures, etc
General feedback
- Reduced man hours on common tasks
- Execution time for handling threats has been reduced considerably
- Alerts are more real time, and ease of categorising events.
- Saved a lot of budget without going with traditional analysers.
- freeing secops time
- Reduced MTTR by almost 30%
- Improved our speed to resolve issues
Splunk SOAR: A great orchestration and automation tool
- Reduced MTTR by almost 40-50% on average
- Automated response based on certain events
- Helps a lot with process standardisation
- Decrease in manual errors, since the entire analysis process is automated.
- It has priority on threats, which ensures that there are no false positives.
- Good quality of automated responses.
"SOAR" your return on investments.
- We have been able to reduce security incidents and the costs associated with it therefore increasing our revenue by 30% and we have been able to maintain our reputation.
- We have improved our productivity by 20% by automating manual processes therefore concentrating on more important tasks.
- We have improved the overall control of our security operations.
Splunk SOAR - The CIA of Software Security
- Automation with Splunk SOAR is more accurate than humans.
- Enables us to use less time on repetitive tasks drive innovation.
- It is fast to use especially during threat times.
This is a review from a consultant not from a final user
- Satisfy customers
- Have an integrated solution for our proposal
- Avoid the presence (as much as possible) of external products in security management
- MTTR
- Dashboard and war room for analysts and C suite - easy to show them results and benefits of Splunk soar.
- Faster process execution, playbook action and results.
Top Performing Splunk SOAR with top-tier automation.
- Has improved internal operational efficiencies though automation
- Has fast response to threats times
- Less time on the repetitive tasks drives innovation
- Faster detection and removal of threats.
- Improved productivity and innovation within the business.
- Less time spent on grunt work and analysis since Splunk SOAR automates the repetitive works.
Splunk SOAR best for Security Orchestration
- Alerts
- Automation
- Security
SOAR it
- Reduce MTTR
- Reduce manual TOIL
- Consistent Investigation workflow
Splunk SOAR Review
- Currently a work in progress
Soar Up Your Security Automation with Splunk SOAR.
- Improved delivery time
- It has improved our IT and security processes automation
- Upgraded our compliance and risk management
SPLUNK SOAR REVIEW.
- The computerized playbook makes the life small bit simpler on job.
- Simple to utilize GUI, you'll be able to have with you possess add-ons, Numerous integrations in existing arrangements and tools. It may be an extraordinary coordination tool that can be utilized for any kind of organization, not as it were security.
- It holds the nerve center of the security environment, giving groups the knowledge to rapidly detect.
- Reporting errors and rectifying security loopholes are relatively simple.
- Many required features are available in the free version
- Data security and management is more controlled with Splunk SOAR
- Automated security tasks saved considerable amount of time.
- Precise and detailed logging , stopped relying on hardware based log analyses.
- Much improved control of organisational data security.
Highly powerful SIEM tool with Endless Capabitlies
- Lesser Workflow
- Easy Turnaround time for Detection and Preventions
- Automation capabilities saved times.
- Better exposure to reports.
- Saves our teams plenty of hours each week.
- Is a great homegrown approach to addressing manual workflows and repetitive tasks, keeping teams on our toes and us on top?
- Turns data into outcomes in log analytics