Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (2024)

Likelihood to Recommend

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (1)

Splunk

Well suited: Splunk ES is highly recommended in an environment with many data sources and experienced computer engineers. It has a steep learning curve, but once that hurdle is crossed, it is absolutely a beast. It is also very expensive, so a company putting a high amount of budget in Security is needed. Not well suited: Splunk ES is not recommended if a company has only a few sources and some non-technical IT users. The price won't justify the fewer data sources and scratching just the surface level. Moreover, non-technical IT users would be better off with something that has a query builder, unlike Splunk.

Incentivized

Read full review

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (2)

Splunk

Our company has very complex and dynamic security operations because of the large number of security tools and systems that we need to manage and coordinate. Moreover, it helps us to meet many regulatory and compliance requirements because it helps us to automate and document our security operations. We also use it to streamline our security operations and improve our response to potential threats.

Incentivized

Read full review
Pros

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (3)

Splunk

  • Advanced Threat Detection and Correlation: ES stands out in its ability to detect sophisticated threats by correlating data from multiple sources. For instance, it can identify unusual patterns in user behavior, cross-referencing with network logs to flag potential insider threats.
  • Real-time Monitoring and Alerting: ES offers robust real-time monitoring capabilities. It excels in promptly alerting us to critical security events, such as suspicious network traffic spikes or unauthorized access attempts, allowing for immediate response.
  • Comprehensive Log Analysis: ES ingests and analyzes an extensive range of log data. It's particularly adept at parsing and making sense of complex log formats, making it a versatile tool for understanding system activities and security events.

Incentivized

Read full review

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (4)

Splunk

  • Its security orchestration and integration capability that supports multiple tools.
  • Easy coding that automates our security actions.
  • Enables us to easily collaborate and respond to security issues faster.
  • Splunk SOAR is a flexible product that is easy to deploy.
  • Efficient tracking and monitoring capability.
  • Excellent real-time reporting functionality.

Incentivized

Read full review
Cons

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (6)

Splunk

  • ES on the cloud (SaaS) has too many limitations with platform administration.
  • Supported integrations are not always on par with enterprise support especially when dependent on 3rd-party proprietary APIs.
  • In later versions, unforeseen glitches seem to show up that have no resolution except version upgrade. This used to not be the case in prior versions which were very stable.
Read full review

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (7)

Splunk

  • A lack of instruction It can be difficult to contact the support staff. Limited experience from current users.
  • It takes some effort to set up and learn new technology at first. More assistance is required from the support staff. The product's price needs to go down.
  • Cost of the larger version.

Incentivized

Read full review
Likelihood to Renew

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (9)

Splunk

We are very happy with Splunk and would advise anyone to take a serious look at it. It might look pricey but the rewards Splunk offers seem endless.

Incentivized

Read full review

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (10)

Splunk

As we already have a lot of clients being catered with Splunk SOAR and because Splunk SOAR is robust and efficient, we are already using it, and we have understood the product to a certain extent, I feel we are personally more enticed to use and scale it to a lot of business.

Incentivized

Read full review
Usability

You definitely need to learn how to use Splunk to get the most of the tool. There are many courses available for free to get up to speed on the usability of the tool but it's not that simple. It will take time to digest all the data and to understand how to query for what you are looking for.

Incentivized

Read full review

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (13)

Splunk

Not immediate: it always requires a training.

Incentivized

Read full review
Reliability and Availability

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (15)

Splunk

I'm not an ES user, but, in my implementation I usually try to prevent all service stops to guarantee High availability to the final customers.

Incentivized

Read full review

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (17)

Splunk

No answers on this topic

Performance

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (18)

Splunk

ES requires a very performant infrastructure: if it has it's performant, otherwise not. I had situation with a very performant infrastructure and I didn't notized that it was a distributed architecture, it seemed that there ware few data on my PC, othewise I experienced less performant infrastructures with less performaces.

Incentivized

Read full review

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (20)

Splunk

We are able to automate almost every one of our use cases, even our threat-hunting, and threat intel procedures. We have 20+ playbooks and cover almost everything, even searching logs into Splunk, looking into TIP and external systems, enrichment, and collecting evidence for analysts; it can perform concurrent playbooks running.

Incentivized

Read full review
Support Rating

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (22)

Splunk

It's good when it's responsive, but I've had times where I had to wait quite a while for a response. But these are typically the exceptions rather than the rule. When you do get a response it is always well-informed and appropriate. I would say they've been trending better over time with this.

Incentivized

Read full review

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (23)

Splunk

Splunk Support is always great! In addition the Community is very efficient and active.

Incentivized

Read full review
In-Person Training

I experienced only on-line training, but the trainers were very professional and competent. Maybe it could be more useful if they also have an experience in projects because sometimes they didn't have a real project experience to communicate to the students. Anyway, it was very interesting and I learned many thing that's very difficoult (or maybe impossible!) to have by myself, aven if I have more than 10 years of Splunk activity experience.

Incentivized

Read full review

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (27)

Splunk

I never followed an in-person training, I gave my evaluation based on the online training

Incentivized

Read full review
Online Training

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (29)

Splunk

It was very interesting and I learned many thing that's very difficoult (or maybe impossible!) to have by myself. The only problem was that, when I worked with the Splunk Professional Services, I found some difference between the training contents and the information from PS. In addition is required a long experience on Splunk Enterprise for the data ingestion part, in other words I'm able to work with ES because I'm worling on Splunk since 11 years, otherwise I'd some problem.

Incentivized

Read full review

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (31)

Splunk

I followed training for Phantom admins and it opened a world for me

Incentivized

Read full review
Implementation Rating

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (33)

Splunk

It's a fantatic product and it was very useful the presence of Splunk Professional Services for the Design Phase and the final Health Check.

Incentivized

Read full review

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (35)

Splunk

I already said that the main key insight is the knowledge of Phantom, so a detailed training for all the people involeved.

Incentivized

Read full review
Alternatives Considered

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (37)

Splunk

Splunk enterprise is the only solution that we’ve been able to identify that provides risk based alerting, which allows our SOC to reduce analyst fatigue which would be a huge problem without it. Before RBA, there were thousands of alerts a day and it was impossible to review all of them

Incentivized

Read full review

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (38)

Splunk

Splunk Phantom integrates well with Splunk ES and has many integrations. One thing that I liked about XSOAR as compared to Phantom is that it has an "app-store" where you can download not only app integrations (similar to Phantom) but Playbooks and dashboards as well.

Incentivized

Read full review
Contract Terms and Pricing Model

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (39)

Splunk

for my exterience, unit pricing and billing frequency are correct. As I already said, I hint to have more discount flexibility, expecially with new customers, because there are competitors less expensive and very aggressive that are dangerous. In addition the possibility to don't pay the license for the development period could be a very interesting feature for the final customers.

Incentivized

Read full review

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (41)

Splunk

No answers on this topic

Scalability

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (42)

Splunk

- 8 out of 10 and took 2 for the data pipeline and administration part. Even if you'd like to improve yourself or your team, you have to pay a lot of money and it could be more than GIAC education + cert. - Normalization for Data models and CPU-based searches can be a problem sometimes.

Incentivized

Read full review

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (43)

Splunk

me and the customers I encountered found it flexible and scalable

Incentivized

Read full review
Professional Services

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (45)

Splunk

I had a fantastic experience with Splunk Professional Services: they worked with us in our last SON project (a SOC migration for a very large customer) and helped to build a multi tenent environment even if ES isn't a multi tenant platform. Th Splunk PS was a very professional and competent people, he is italian and was able to speak with our italian customers.

Incentivized

Read full review

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (47)

Splunk

No answers on this topic

Return on Investment

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (48)

Splunk

  • ES has highly impacted ROI because as the customer of the ES the work we do for creating use cases for clients in terms of security-related aspects by their logs has given more return than investment.
  • The correlation searches we run to get detailed results from the Data models are very less time-consuming than Splunk Enterprise itself we can get quick responses to the use cases and dashboards populated because of ES.
  • The CIM compliance feature is ES has made more jobs easy in the terms of finding more Authentication related data we can get data onboarded in the Email data model from O365 and search is email data model instead of searching for particular indexes.

Incentivized

Read full review

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (49)

Splunk

  • The playbooks are valuable. They are the core component. Being able to implement and build a code process to work through and scale out what we want to do is valuable
  • Before its use, analyzing each email would take at least 15 to 20 minutes, with some complex cases taking up to 30 minutes...With the automation provided by Splunk Phantom, we could significantly reduce the amount of time and human effort required to complete this task

Incentivized

Read full review
ScreenShots
Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (2024)
Top Articles
Where to Get Cards Graded in Person: Local Options & Prices
How to Forget Someone You Love and Move on
English Bulldog Puppies For Sale Under 1000 In Florida
Katie Pavlich Bikini Photos
Gamevault Agent
Pieology Nutrition Calculator Mobile
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Compare the Samsung Galaxy S24 - 256GB - Cobalt Violet vs Apple iPhone 16 Pro - 128GB - Desert Titanium | AT&T
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Craigslist Dog Kennels For Sale
Things To Do In Atlanta Tomorrow Night
Non Sequitur
Crossword Nexus Solver
How To Cut Eelgrass Grounded
Pac Man Deviantart
Alexander Funeral Home Gallatin Obituaries
Energy Healing Conference Utah
Geometry Review Quiz 5 Answer Key
Hobby Stores Near Me Now
Icivics The Electoral Process Answer Key
Allybearloves
Bible Gateway passage: Revelation 3 - New Living Translation
Yisd Home Access Center
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
Marquette Gas Prices
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Vera Bradley Factory Outlet Sunbury Products
Pixel Combat Unblocked
Movies - EPIC Theatres
Cvs Sport Physicals
Mercedes W204 Belt Diagram
Mia Malkova Bio, Net Worth, Age & More - Magzica
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Teenbeautyfitness
Where Can I Cash A Huntington National Bank Check
Topos De Bolos Engraçados
Sand Castle Parents Guide
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Holzer Athena Portal
Hello – Cornerstone Chapel
Stoughton Commuter Rail Schedule
Nfsd Web Portal
Selly Medaline
Latest Posts
Article information

Author: Allyn Kozey

Last Updated:

Views: 6138

Rating: 4.2 / 5 (43 voted)

Reviews: 82% of readers found this page helpful

Author information

Name: Allyn Kozey

Birthday: 1993-12-21

Address: Suite 454 40343 Larson Union, Port Melia, TX 16164

Phone: +2456904400762

Job: Investor Administrator

Hobby: Sketching, Puzzles, Pet, Mountaineering, Skydiving, Dowsing, Sports

Introduction: My name is Allyn Kozey, I am a outstanding, colorful, adventurous, encouraging, zealous, tender, helpful person who loves writing and wants to share my knowledge and understanding with you.