Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (2024)

Likelihood to Recommend

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (1)

Splunk

Well suited: Splunk ES is highly recommended in an environment with many data sources and experienced computer engineers. It has a steep learning curve, but once that hurdle is crossed, it is absolutely a beast. It is also very expensive, so a company putting a high amount of budget in Security is needed. Not well suited: Splunk ES is not recommended if a company has only a few sources and some non-technical IT users. The price won't justify the fewer data sources and scratching just the surface level. Moreover, non-technical IT users would be better off with something that has a query builder, unlike Splunk.

Incentivized

Read full review

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (2)

Splunk

Our company has very complex and dynamic security operations because of the large number of security tools and systems that we need to manage and coordinate. Moreover, it helps us to meet many regulatory and compliance requirements because it helps us to automate and document our security operations. We also use it to streamline our security operations and improve our response to potential threats.

Incentivized

Read full review
Pros

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (3)

Splunk

  • Advanced Threat Detection and Correlation: ES stands out in its ability to detect sophisticated threats by correlating data from multiple sources. For instance, it can identify unusual patterns in user behavior, cross-referencing with network logs to flag potential insider threats.
  • Real-time Monitoring and Alerting: ES offers robust real-time monitoring capabilities. It excels in promptly alerting us to critical security events, such as suspicious network traffic spikes or unauthorized access attempts, allowing for immediate response.
  • Comprehensive Log Analysis: ES ingests and analyzes an extensive range of log data. It's particularly adept at parsing and making sense of complex log formats, making it a versatile tool for understanding system activities and security events.

Incentivized

Read full review

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (4)

Splunk

  • Its security orchestration and integration capability that supports multiple tools.
  • Easy coding that automates our security actions.
  • Enables us to easily collaborate and respond to security issues faster.
  • Splunk SOAR is a flexible product that is easy to deploy.
  • Efficient tracking and monitoring capability.
  • Excellent real-time reporting functionality.

Incentivized

Read full review
Cons

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (6)

Splunk

  • ES on the cloud (SaaS) has too many limitations with platform administration.
  • Supported integrations are not always on par with enterprise support especially when dependent on 3rd-party proprietary APIs.
  • In later versions, unforeseen glitches seem to show up that have no resolution except version upgrade. This used to not be the case in prior versions which were very stable.
Read full review

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (7)

Splunk

  • A lack of instruction It can be difficult to contact the support staff. Limited experience from current users.
  • It takes some effort to set up and learn new technology at first. More assistance is required from the support staff. The product's price needs to go down.
  • Cost of the larger version.

Incentivized

Read full review
Likelihood to Renew

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (9)

Splunk

We are very happy with Splunk and would advise anyone to take a serious look at it. It might look pricey but the rewards Splunk offers seem endless.

Incentivized

Read full review

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (10)

Splunk

As we already have a lot of clients being catered with Splunk SOAR and because Splunk SOAR is robust and efficient, we are already using it, and we have understood the product to a certain extent, I feel we are personally more enticed to use and scale it to a lot of business.

Incentivized

Read full review
Usability

You definitely need to learn how to use Splunk to get the most of the tool. There are many courses available for free to get up to speed on the usability of the tool but it's not that simple. It will take time to digest all the data and to understand how to query for what you are looking for.

Incentivized

Read full review

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (13)

Splunk

Not immediate: it always requires a training.

Incentivized

Read full review
Reliability and Availability

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (15)

Splunk

I'm not an ES user, but, in my implementation I usually try to prevent all service stops to guarantee High availability to the final customers.

Incentivized

Read full review

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (17)

Splunk

No answers on this topic

Performance

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (18)

Splunk

ES requires a very performant infrastructure: if it has it's performant, otherwise not. I had situation with a very performant infrastructure and I didn't notized that it was a distributed architecture, it seemed that there ware few data on my PC, othewise I experienced less performant infrastructures with less performaces.

Incentivized

Read full review

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (20)

Splunk

We are able to automate almost every one of our use cases, even our threat-hunting, and threat intel procedures. We have 20+ playbooks and cover almost everything, even searching logs into Splunk, looking into TIP and external systems, enrichment, and collecting evidence for analysts; it can perform concurrent playbooks running.

Incentivized

Read full review
Support Rating

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (22)

Splunk

It's good when it's responsive, but I've had times where I had to wait quite a while for a response. But these are typically the exceptions rather than the rule. When you do get a response it is always well-informed and appropriate. I would say they've been trending better over time with this.

Incentivized

Read full review

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (23)

Splunk

Splunk Support is always great! In addition the Community is very efficient and active.

Incentivized

Read full review
In-Person Training

I experienced only on-line training, but the trainers were very professional and competent. Maybe it could be more useful if they also have an experience in projects because sometimes they didn't have a real project experience to communicate to the students. Anyway, it was very interesting and I learned many thing that's very difficoult (or maybe impossible!) to have by myself, aven if I have more than 10 years of Splunk activity experience.

Incentivized

Read full review

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (27)

Splunk

I never followed an in-person training, I gave my evaluation based on the online training

Incentivized

Read full review
Online Training

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (29)

Splunk

It was very interesting and I learned many thing that's very difficoult (or maybe impossible!) to have by myself. The only problem was that, when I worked with the Splunk Professional Services, I found some difference between the training contents and the information from PS. In addition is required a long experience on Splunk Enterprise for the data ingestion part, in other words I'm able to work with ES because I'm worling on Splunk since 11 years, otherwise I'd some problem.

Incentivized

Read full review

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (31)

Splunk

I followed training for Phantom admins and it opened a world for me

Incentivized

Read full review
Implementation Rating

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (33)

Splunk

It's a fantatic product and it was very useful the presence of Splunk Professional Services for the Design Phase and the final Health Check.

Incentivized

Read full review

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (35)

Splunk

I already said that the main key insight is the knowledge of Phantom, so a detailed training for all the people involeved.

Incentivized

Read full review
Alternatives Considered

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (37)

Splunk

Splunk enterprise is the only solution that we’ve been able to identify that provides risk based alerting, which allows our SOC to reduce analyst fatigue which would be a huge problem without it. Before RBA, there were thousands of alerts a day and it was impossible to review all of them

Incentivized

Read full review

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (38)

Splunk

Splunk Phantom integrates well with Splunk ES and has many integrations. One thing that I liked about XSOAR as compared to Phantom is that it has an "app-store" where you can download not only app integrations (similar to Phantom) but Playbooks and dashboards as well.

Incentivized

Read full review
Contract Terms and Pricing Model

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (39)

Splunk

for my exterience, unit pricing and billing frequency are correct. As I already said, I hint to have more discount flexibility, expecially with new customers, because there are competitors less expensive and very aggressive that are dangerous. In addition the possibility to don't pay the license for the development period could be a very interesting feature for the final customers.

Incentivized

Read full review

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (41)

Splunk

No answers on this topic

Scalability

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (42)

Splunk

- 8 out of 10 and took 2 for the data pipeline and administration part. Even if you'd like to improve yourself or your team, you have to pay a lot of money and it could be more than GIAC education + cert. - Normalization for Data models and CPU-based searches can be a problem sometimes.

Incentivized

Read full review

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (43)

Splunk

me and the customers I encountered found it flexible and scalable

Incentivized

Read full review
Professional Services

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (45)

Splunk

I had a fantastic experience with Splunk Professional Services: they worked with us in our last SON project (a SOC migration for a very large customer) and helped to build a multi tenent environment even if ES isn't a multi tenant platform. Th Splunk PS was a very professional and competent people, he is italian and was able to speak with our italian customers.

Incentivized

Read full review

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (47)

Splunk

No answers on this topic

Return on Investment

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (48)

Splunk

  • ES has highly impacted ROI because as the customer of the ES the work we do for creating use cases for clients in terms of security-related aspects by their logs has given more return than investment.
  • The correlation searches we run to get detailed results from the Data models are very less time-consuming than Splunk Enterprise itself we can get quick responses to the use cases and dashboards populated because of ES.
  • The CIM compliance feature is ES has made more jobs easy in the terms of finding more Authentication related data we can get data onboarded in the Email data model from O365 and search is email data model instead of searching for particular indexes.

Incentivized

Read full review

Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (49)

Splunk

  • The playbooks are valuable. They are the core component. Being able to implement and build a code process to work through and scale out what we want to do is valuable
  • Before its use, analyzing each email would take at least 15 to 20 minutes, with some complex cases taking up to 30 minutes...With the automation provided by Splunk Phantom, we could significantly reduce the amount of time and human effort required to complete this task

Incentivized

Read full review
ScreenShots
Splunk Enterprise Security (ES) vs Splunk SOAR | TrustRadius (2024)
Top Articles
How We Paid Off $40,000 of Debt in 18 Months with Low Income
Eight Ways I Wasted Money...Trying to Save Money!
Fighter Torso Ornament Kit
Is Paige Vanzant Related To Ronnie Van Zant
Play FETCH GAMES for Free!
Television Archive News Search Service
Skamania Lodge Groupon
Lifewitceee
Merlot Aero Crew Portal
Decaying Brackenhide Blanket
Cars For Sale Tampa Fl Craigslist
Bbc 5Live Schedule
Student Rating Of Teaching Umn
Space Engineers Projector Orientation
The Binding of Isaac
Craigslist Boats For Sale Seattle
Sarpian Cat
United Dual Complete Providers
Vanessa West Tripod Jeffrey Dahmer
The Ultimate Style Guide To Casual Dress Code For Women
Inter-Tech IM-2 Expander/SAMA IM01 Pro
Loves Employee Pay Stub
Publix Super Market At Rainbow Square Shopping Center Dunnellon Photos
Craigslist Pearl Ms
Empire Visionworks The Crossings Clifton Park Photos
Yugen Manga Jinx Cap 19
How To Tighten Lug Nuts Properly (Torque Specs) | TireGrades
Shelby Star Jail Log
TMO GRC Fortworth TX | T-Mobile Community
Gt7 Roadster Shop Rampage Engine Swap
Page 2383 – Christianity Today
Top Songs On Octane 2022
Armor Crushing Weapon Crossword Clue
Publix Daily Soup Menu
Wbli Playlist
How does paysafecard work? The only guide you need
Mgm Virtual Roster Login
Rise Meadville Reviews
Tal 3L Zeus Replacement Lid
Austin Automotive Buda
Studio 22 Nashville Review
Riverton Wyoming Craigslist
Tableaux, mobilier et objets d'art
Hanco*ck County Ms Busted Newspaper
Avance Primary Care Morrisville
Movie Hax
Ratchet And Clank Tools Of Destruction Rpcs3 Freeze
Kaamel Hasaun Wikipedia
Wpne Tv Schedule
Rick And Morty Soap2Day
Sitka Alaska Craigslist
Sam's Club Fountain Valley Gas Prices
Latest Posts
Article information

Author: Allyn Kozey

Last Updated:

Views: 6138

Rating: 4.2 / 5 (43 voted)

Reviews: 82% of readers found this page helpful

Author information

Name: Allyn Kozey

Birthday: 1993-12-21

Address: Suite 454 40343 Larson Union, Port Melia, TX 16164

Phone: +2456904400762

Job: Investor Administrator

Hobby: Sketching, Puzzles, Pet, Mountaineering, Skydiving, Dowsing, Sports

Introduction: My name is Allyn Kozey, I am a outstanding, colorful, adventurous, encouraging, zealous, tender, helpful person who loves writing and wants to share my knowledge and understanding with you.