Splunk SOAR
by Splunk Inc. (Cisco)
Splunk SOAR (formerly Phantom) is a leading soar platform that enables security teams to automate repetitive tasks and orchestrate complex response workflows — natively integrated with Splunk Enterprise Security SIEM to deliver a unified detect-and-respond soar platform for enterprise SOC operations.
Starting Price
Splunk SOAR Cloud from ~$30,000/year; enterprise bundle pricing on quote; contact splunk.com
G2
Gartner
Capterra
Ratings & Reviews
Key Features
- Visual Playbook Editor — Drag-and-Drop Automation Builder
- 300+ Pre-Built Apps & Integrations
- Mission Control — Unified SOC Workbench (with Splunk ES)
- Event & Case Management
- Automated Threat Intelligence Enrichment
- Splunk AI — ML-Based Alert Prioritization
- REST API — Full Programmatic Access
- Workbook Templates — Standardized Response Procedures
- Audit Trail & Compliance Reporting
- On-Premise & Cloud Deployment
- Multi-Tenancy (MSSP Support)
- Risk-Based Alerting Integration with Splunk ES
- Custom Dashboards & KPI Reporting
Pros & Cons
Pros
- +Best soar platform for existing Splunk ES customers — native SIEM + SOAR integration in Mission Control
- +60-day free trial — longest evaluation period of any enterprise soar platform
- +300+ pre-built apps reduce custom development
- +Cisco acquisition adds network intelligence and broader security portfolio
- +FedRAMP High authorized for U.S. government
- +Risk-Based Alerting + SOAR = automated response to highest-risk incidents only
Cons
- −Best value only for existing Splunk Enterprise Security customers
- −Cisco acquisition introducing product roadmap uncertainty
- −Smaller integration library vs. Palo Alto XSOAR (300 vs 800+)
- −Per-action pricing model can escalate for high-volume automation environments
Best For
Organizations already running Splunk Enterprise Security who want native SOAR automation — eliminating the need for a separate SOAR platform and unifying detection and response in the Splunk Mission Control console.
Target Audience
Enterprise, Fortune 500, Government, Financial Services, Healthcare
Key Integrations
Competitor Tools
Pricing
Model
Annual subscription — per automation action or per user; bundled with Splunk Enterprise Security
Starting At
Splunk SOAR Cloud from ~$30,000/year; enterprise bundle pricing on quote; contact splunk.com
Free Trial
Yes — 60-day free trial of Splunk SOAR available at splunk.comCompany Info
Founded
2003
Headquarters
San Francisco, CA, USA (Cisco acquisition 2024)
Employees
8,000+ (part of Cisco — 85,000+)
Company Size
Mid-Market & Enterprise (500+ employees)
Funding
Acquired by Cisco (NASDAQ: CSCO) in March 2024 for $28 billion
Certifications
Awards & Recognition
Gartner Magic Quadrant Leader — SOAR 2025 | Forrester Wave Strong Performer — SOAR Q2 2025 | SC Awards SOAR Finalist 2025 | IDC MarketScape Leader — SOAR 2025
Data sourced from G2, Gartner & Capterra · Verified by Firmographic
