TrustRadius: an HG Insights company

Splunk SOAR

Score8.9 out of 10

84 Reviews and Ratings

What is Splunk SOAR?

Splunk now offers a security orchestration, automation, and response (SOAR) platform via its acquisition of Phantom. Splunk Security Orchestration and Automation (Splunk SOAR) provides playbook automation and is available as a standalone solution.

My experience deploying Splunk SOAR in multi-client SOC

Use Cases and Deployment Scope

It plays a central role in bridging detection with response automation. As a SOC analyst, I oversee threat response operations from multiple enterprise clients. Splunk SOAR obviously does a ton for us but at its core, the problem it solves is alert fatigue and triage inconsistency.

Pros

  • My go-to is the visual playbook editor. It's clean enough for new analyst but still flexible for power users who want to script with python. I've built more than 50 playbooks from scratch.

Cons

  • Splunk SOAR is powerful, but when you operate it at MSSP scale, a few rough edges become apparent like debugging visibility within playbooks. when a step fails, the log traces aren't always intuitive

Return on Investment

  • 70 % of low to mid tier alerts are now auto resolved through playbooks
  • MTTD and MTTR are significantly low

Usability

Alternatives Considered

IBM Security QRadar SOAR

Other Software Used

Splunk Enterprise Security

Splunk SOAR Robust and efficient.

Use Cases and Deployment Scope

We're using it for Automation to address different clients to help them reduce their working time on certain things, which helps them increase their efficiency and thereby help them meet the SLA. Splunk SOAR helps us with a lot of customization to include custom codes in the playbook, which is a deal breaker.

Pros

  • Playbook Design.
  • Robust and Speed.
  • Flexibility

Cons

  • Integration with On-Prem.
  • Access to more APIs in the apps section.
  • Improving API actions.

Return on Investment

  • Achieveing SLA.
  • Saving Analysts time.
  • Automation.

Other Software Used

Splunk Enterprise Security (ES), Securonix Next-Generation SIEM, Palo Alto Networks Cortex XDR

Exceptional threat reporting and efficient and robust algorithm based bug handling

Use Cases and Deployment Scope

We were largely depending on Splunk SOAR for active threat detection and alert monitoring .It has a good algorithm based signature handling which efficiently manages threats. Also our cyber security researchers constantly use this software for advanced research based on their specialisations. Advanced penetration testing also helped us to enhance the security of our hosted applications

Pros

  • effective threat monitoring
  • Score based threat level detection for handling attacks that require priority.
  • highly effective reporting templates for vulnerability testing

Cons

  • Advanced features are not cost effective.
  • Live monitoring and threats require more clarity
  • Require professional and sound knowledge on networking to operate.

Return on Investment

  • Execution time for handling threats has been reduced considerably
  • Alerts are more real time, and ease of categorising events.
  • Saved a lot of budget without going with traditional analysers.

Other Software Used

PRTG Network Monitor, Observium, SolarWinds IP Address Manager (IPAM)

"SOAR" your return on investments.

Use Cases and Deployment Scope

Splunk SOAR has helped us to improve our overall security posture, efficiency and effectiveness by automating and managing our security operations through streamlining most of our manual processes such as threat detection, incident response and vulnerability management. Therefore, our team has been able to respond more quickly to potential threats and reduce the impact of security incidents on the organization.

Pros

  • Automation and optimization of security systems which help to reduce the probability of security incidents.
  • It seamlessly integrates with other security tools and systems to help us address our specific needs and requirements.
  • Centralized platform for managing and coordinating our security operations.

Cons

  • Due to its complex nature, it is quite difficult to learn and master.
  • The cost of purchasing and implementing it is quite high.

Return on Investment

  • We have been able to reduce security incidents and the costs associated with it therefore increasing our revenue by 30% and we have been able to maintain our reputation.
  • We have improved our productivity by 20% by automating manual processes therefore concentrating on more important tasks.
  • We have improved the overall control of our security operations.

Other Software Used

Splunk Enterprise Security (ES), Zoom, HCL BigFix

We fuel our growth by having great protection in our system with automatic alerts.

Use Cases and Deployment Scope

This software is very fast to protect our system, we require the services of Splunk SOAR to implement improvements in our internal system, since our network has always been a constant victim of the threats that abound on the web, in the installation process we had problems, but we loved having technical support, the implementation was completed in a short time, it is a complete system to automate alerts in advance, it has very good scans to neutralize threats and protect our information. We reduce manual analysis, and we are more effective because Spunk SOAR has an automated system to eliminate any threat that even tries to appear in our company.

Pros

  • Automated analyzes that eliminate manual work.
  • Order of priority in the analysis, determining greater efficiency in the detection of threats.
  • Great time savings and easy code writing, without being experts we achieve good cases of alerts.

Cons

  • We found no major flaws with Splunk SOAR, but it is slightly disadvantaged by the acquisition price, as it is high and some companies may think twice before buying it.

Return on Investment

  • Decrease in manual errors, since the entire analysis process is automated.
  • It has priority on threats, which ensures that there are no false positives.
  • Good quality of automated responses.

Other Software Used

AccessPay, Book Systems, Acodis – Intelligent Document Processing (IDP)