IBM Cloud Pak for Security vs Splunk SOAR comparison

Cancel
You must select at least 2 products to compare!
IBM Logo
32 views|18 comparisons
0% willing to recommend
Splunk Logo
6,537 views|3,915 comparisons
86% willing to recommend
Comparison Buyer's Guide
Executive Summary

We performed a comparison between IBM Cloud Pak for Security and Splunk SOAR based on real PeerSpot user reviews.

Find out what your peers are saying about VMware, Cisco, Akamai and others in Cloud and Data Center Security.
To learn more, read our detailed Cloud and Data Center Security Report (Updated: May 2024).
772,422 professionals have used our research since 2012.
Featured Review
Quotes From Members
We asked business professionals to review the solutions they use.
Here are some excerpts of what they said:
Pros
"The interface is good and very user-friendly."

More IBM Cloud Pak for Security Pros →

"The most valuable feature of Splunk SOAR that stands out is it has a great SOAR. The automation and orchestration module is highly mature. A lot of use cases are on user entity and behavioral analytics (UEBA), which is artificial intelligence and machine learning-based (AIML).""The most valuable features of Splunk SOAR are the easy integration with other solutions, including other Splunk solutions. The most important playbooks we need on the market come already on the Frontend. However, nowadays, Splunk changed its name, it's not Frontend anymore, it's Splunk Store. This is a very strong point.""Technical support is helpful.""The ability to automate Splunk SOAR and customize the playbook use cases is the most valuable feature and is very exciting for me.""When you design a playbook, you can integrate multiple log sources and define rules... After that, the platform automatically compiles all these activities and, based on the results, the analyst only has to indicate whether the result is a true or false positive. That reduces the time and effort involved.""I like the integration capabilities of Phantom. It has a lot of integrations with other products. Its searching methodologies are also good. It is also easy to understand and easy to create playbooks.""The most valuable feature of Splunk SOAR is the automated playbooks, which saves analysts time.""Splunk SOAR's quick response to incidents is the most valuable part."

More Splunk SOAR Pros →

Cons
"Lacks sufficient technical support."

More IBM Cloud Pak for Security Cons →

"The algorithm and machine learning have room for improvement and can be more user-friendly.""In my opinion, the focus should be on improving its simplicity, specifically the interface, and configuration.""We've run into a few minor issues. Some of the playbook writing is a bit complicated. We've had a few hiccups with the source control. We'd really like to use GitHub deployment keys for a dedicated account. We haven't been able to do that. I think those are some of the major ones.""It could be easier to implement.""Creating playbooks using the solution’s playbook editor, for me, is very cumbersome. There have been instances where I have said to myself that I just don't want to use this editor. I might just use a code block and write my own code within it... The functionality in the playbook editor is 80 percent there, but that 20 percent is still lacking. They could make it more efficient.""The Splunk SOAR platform was not designed specifically for case management which is why this area needs improvement.""The application does not work properly and does not pass the log-based configuration. I feel that some kind of review should happen in the application. This review should validate things so that we can get the right information. Splunk does not tell us where the IP address is associated with.""The number of playbooks on offer should be increased."

More Splunk SOAR Cons →

Pricing and Cost Advice
Information Not Available
  • "I don't know the exact price, but for my region, it is very expensive."
  • "In my opinion, the price is high, but if you want good products, you have to be willing to pay for them."
  • "It's very overpriced because it is based on the number of users. There is no bulk licensing."
  • "Splunk SOAR is more expensive compared to other options for SOAR."
  • "The licensing cost is reasonable."
  • "When we first purchased our Splunk SOAR license, it was based on an event-count model. It was based on the number of events. I had strong opinions at the time that automation should not be stifled by the amount of automation you can accomplish, so the previous structure was not as beneficial for us. Later that year, we got told or saw at a conference that they announced user-based pricing. We are now in a renewal period, so we migrated to a user-based license model, which is more appropriate for us so that we no longer have to worry about stifling our automation based on the quantity."
  • "Splunk SOAR is an expensive solution for an organization of our size."
  • "The cost is high and the licensing is on an annual basis."
  • More Splunk SOAR Pricing and Cost Advice →

    report
    Use our free recommendation engine to learn which Cloud and Data Center Security solutions are best for your needs.
    772,422 professionals have used our research since 2012.
    Questions from the Community
    Top Answer:The interface is good and very user-friendly.
    Top Answer:The pricing is reasonable and it's a lot easier to make the calculation than it used to be. Of course the cost increases with the size of the infrastructure. Licensing is on an annual basis and is… more »
    Top Answer:Some of our customers would like to have more technical support from the vendor.
    Top Answer:Splunk SOAR's quick response to incidents is the most valuable part.
    Top Answer:The cost is high and the licensing is on an annual basis.
    Top Answer:The cost of Splunk SOAR has room for improvement.
    Ranking
    Views
    32
    Comparisons
    18
    Reviews
    0
    Average Words per Review
    0
    Rating
    N/A
    Views
    6,537
    Comparisons
    3,915
    Reviews
    23
    Average Words per Review
    779
    Rating
    8.0
    Comparisons
    Also Known As
    Phantom
    Learn More
    Overview

    IBM Cloud Pak for Security is comprised of containerized software pre-integrated with Red Hat OpenShift. The platform connects to your existing security tools – and through the use of open standards – allows you to search for threat indicators across your hybrid, multicloud environment.

    Splunk SOAR offers features like automation and orchestration of manual tasks, speeding up work, detection and response to advanced and emerging threats. 

    Go from overwhelmed to in-control

    Automate manual tasks. Address every alert, every day. Establish repeatable procedures that allow security analysts to stop being reactive and focus on mission-critical objectives to protect your business.

    Force multiply your team

    Orchestrate and automate repetitive tasks, investigation and response to increase efficiency and productivity, and do more with the people you already have. Make a team of three feel like a team of 10.

    From 30 minutes to 30 seconds

    Work faster with Splunk SOAR. Respond to threats in seconds. Lower your mean time to respond (MTTR) by automating security tasks and workflows across all of your security tools.

    End-to-end security operations made easy

    Take advantage of Splunk Enterprise Security and Splunk SOAR joining forces to provide a seamless and intuitive SecOps platform to prevent, detect and respond to advanced and emerging threats.

    Sample Customers
    Information Not Available
    Recorded Future, Blackstone
    Top Industries
    VISITORS READING REVIEWS
    Retailer14%
    Government14%
    Real Estate/Law Firm11%
    Financial Services Firm9%
    REVIEWERS
    Financial Services Firm35%
    Computer Software Company18%
    University12%
    Comms Service Provider6%
    VISITORS READING REVIEWS
    Financial Services Firm14%
    Computer Software Company14%
    Manufacturing Company10%
    Government10%
    Company Size
    VISITORS READING REVIEWS
    Small Business41%
    Midsize Enterprise15%
    Large Enterprise44%
    REVIEWERS
    Small Business29%
    Midsize Enterprise18%
    Large Enterprise53%
    VISITORS READING REVIEWS
    Small Business18%
    Midsize Enterprise13%
    Large Enterprise69%
    Buyer's Guide
    Cloud and Data Center Security
    May 2024
    Find out what your peers are saying about VMware, Cisco, Akamai and others in Cloud and Data Center Security. Updated: May 2024.
    772,422 professionals have used our research since 2012.

    IBM Cloud Pak for Security is ranked 21st in Cloud and Data Center Security with 1 review while Splunk SOAR is ranked 3rd in Security Orchestration Automation and Response (SOAR) with 32 reviews. IBM Cloud Pak for Security is rated 0.0, while Splunk SOAR is rated 8.0. The top reviewer of IBM Cloud Pak for Security writes "Great user-friendly interface; provides many functionalities and many free applications ". On the other hand, the top reviewer of Splunk SOAR writes "Takes most of the work away, but the time they take to implement new features is a little bit of concern". IBM Cloud Pak for Security is most compared with IBM Security QRadar and IBM Resilient, whereas Splunk SOAR is most compared with Palo Alto Networks Cortex XSOAR, Cortex XSIAM, ServiceNow Security Operations, Torq and Tines.

    We monitor all Cloud and Data Center Security reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.