Mature SOC teams (10+ analysts) already running Splunk Enterprise Security where deep Python-extensible playbooks are critical and Splunk-native integration is non-negotiable.
Non-Splunk SOCs (XSOAR or Tines win), engineering-led teams wanting no-code (Tines, Torq win), or mid-market without Python skills on the security team.
Is Splunk SOAR a trustworthy vendor?
- 2018-04-09Splunk acquired Phantom Cyber for roughly $350M
- 2024-03-18Cisco acquired Splunk for $28BSplunk SOAR folded into the Cisco security portfolio alongside SecureX successor strategy.
- 2025-08-15Pricing complexity post-Cisco; multiple pricing models still settlingBuyers report inconsistent quotes across Cisco and Splunk channel.
What 320 reviews actually say
Synthesized from G2, Capterra, Reddit, Trustpilot. Patterns >15% prevalence shown.
Praise patterns
- Deepest playbook engine with Python extensibility87% →
- Native Splunk ES integration78% →
- Mature pre-built playbook library64% →
- Battle-tested at Fortune 500 scale51% →
Complaint patterns
- Pricing complexity post-Cisco71% ↑
- Phantom-to-Splunk SOAR rebrand caused confusion47% ↓
- Python-first excludes non-developer analysts51% →
- Implementation 8-20 weeks at scale41% →
What buyers actually pay
87 anonymized deal disclosures · last updated 2026-05-01
| Company size | Median annual |
|---|---|
| 500-2,000 employees | $144,000 |
| 2,000-10,000 employees | $420,000 |
Auto-verified certifications
Editorial: Strengths
- Deepest playbook engine with full Python extensibility
- Native Splunk Enterprise Security integration (single pane of glass)
- Mature pre-built playbook library (300+ apps)
- Battle-tested at Fortune 500 SOC scale
- Cisco network and observability integration post-2024 acquisition
- Strong enterprise partner ecosystem
Editorial: Weaknesses
- Pricing complexity post-Cisco; multiple pricing models still settling
- Phantom-to-Splunk SOAR rebrand caused customer confusion
- Cisco SecureX deprecation (2025) created intermediate uncertainty
- Python-first authoring excludes non-developer security analysts
- Implementation 8-20 weeks for Fortune 500 deployments
- Customer support response times flagged through Cisco transition
Key features & integrations
- +Python-extensible playbook engine
- +Native Splunk ES integration
- +300+ pre-built apps and connectors
- +Visual playbook editor
- +Case management
- +Mission Control (unified SecOps workspace)
- +Custom decision logic
- +Investigation workflows
Read our full ranking of SOAR Software
Splunk SOAR ranks #1 in our editorial review of 10 soar software platforms. The deep-dive covers methodology, comparison tables, decision matrix, migration scoring, and FAQs.
Read the full rankingClosest alternatives in SOAR Software
Contribute your verified deal price
Pricing in B2B software is opaque because vendors want it that way. Verified buyer prices fix that, anonymously. Share what you actually paid for Splunk SOAR; we’ll add it to the verified pricing dataset on this page (with company size band only, no identifying details).
Submit anonymously