Splunk SOAR - Good security and UI features but needs improvement with integration and setup
March 01, 2022

Splunk SOAR - Good security and UI features but needs improvement with integration and setup

Shalini Kr | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User

Overall Satisfaction with Splunk SOAR (Security Orchestration, Automation and Response), formerly Phantom

Splunk is a very handy tool that is used to create dashboards to view multiple data points of our customers at a glance. To make it even better, we have leveraged the automation in a place where we can generate a default template at the click of a button. This has been a very useful feature for systematic logging with a User-friendly experience.
  • New Splunk version is faster
  • Data ingestion is efficient
  • new addon features for dashboards
  • more official training session
  • better newsletter
  • make installation process simpler
  • faster loading time has resulted in faster analysis
  • automations that has saved the business the budget
  • fewer resources with more productivity
The community was really helpful and it gives us more understanding of some specific scenarios where we were facing difficulty with business logic and not just that we discovered new features for falcon which we were of earlier. This helped us optimize our Splunk usage and also helps in creating a UI experience.
It helps in providing access to only the users who needs it with just a click. Most of the competitive products require an admin to perform such tasks which is expensive and troublesome as the resource might/might not be available. Also, we have observed now a large amount of data i.e 30 days of data is retrieved faster than expected.

Do you think Splunk SOAR delivers good value for the price?


Are you happy with Splunk SOAR's feature set?


Did Splunk SOAR live up to sales and marketing promises?

I wasn't involved with the selection/purchase process

Did implementation of Splunk SOAR go as expected?


Would you buy Splunk SOAR again?


We have a use case where on a daily basis, our engineers have to update cases based on data points connected with Splunk. On average, it usually takes 25 min for one update, however, with the Splunk dashboard and its automation in place, the analysis time has been reduced from 25 min to 5 min which is something every business wants