Cisco SecureX vs Splunk SOAR comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Cisco SecureX
Average Rating
9.0
Number of Reviews
13
Ranking in other categories
Application Security Tools (18th), Vulnerability Management (16th), Extended Detection and Response (XDR) (13th), Cisco Security Portfolio (9th)
Splunk SOAR
Average Rating
8.0
Number of Reviews
33
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (3rd)
 

Featured Reviews

SC
Aug 5, 2022
When we need to investigate something, we only need to go to one place
The two biggest things that are great about SecureX: Orchestrator and visibility. We initially implemented it when it was first introduced because of the visibility piece. We could look at the performance and statistics associated with our entire security portfolio. When they introduced Orchestrator, it was a game changer because now we can actually develop Orchestrator scripts to handle a lot of the investigations that we were previously doing manually ourselves. We can actually set up Orchestrator to do things like investigations. If it discovers something that we need to look deeper into, it can just send us an email or text message for whatever we need to do, which has been huge. It has evolved a lot, just that monitoring piece to the current Orchestrator piece. The additional analytics are there. They now have something called Insight, which can basically take data from Microsoft Azure AD and Intune to give us information about our endpoints. This is detailed information about the endpoints, from Secure Endpoint and all these different products. So, it is just constantly evolving. Every time that it evolves, we have more information with more visibility. There are more features that we have that just make everything so much easier, and it is in one place. I don't have to keep going back and forth. I don't have to go to Secure Endpoint and ISE to get the data. I don't have to go to Intune on Microsoft to get the information. It is all in one place.
SA
Jul 20, 2023
Has the ability to connect it to external apps
The ability to connect it to external apps is the most valuable feature. We've also gotten a lot of use from writing custom apps for some of our authentication systems for password scramble. Splunk's ability to predict, identify, and problem-solve in real time is really good. Splunk's ability to provide business resilience by empowering staff is fairly high. It detects issues as they come up and responds to them. We have seen time to value. I did help configure it, but we do have the cloud solution, so it was mostly in place. It has definitely helped to reduce our meantime to resolve. Having it there to automatically take action as events come in and not needing the analysts to have to go out and have a look is how it saved time.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Our customers find the product's third-party integrations valuable. Our customers are also impressed with the tool's capability to pick up third-party threat feeds and use that as part of the decision-making process."
"It has evolved a lot, just that monitoring piece to the current Orchestrator piece. The additional analytics are there. They now have something called Insight, which can basically take data from Microsoft Azure AD and Intune to give us information about our endpoints. This is detailed information about the endpoints, from Secure Endpoint and all these different products. So, it is just constantly evolving. Every time that it evolves, we have more information with more visibility. There are more features that we have that just make everything so much easier, and it is in one place. I don't have to keep going back and forth. I don't have to go to Secure Endpoint and ISE to get the data. I don't have to go to Intune on Microsoft to get the information. It is all in one place."
"The most valuable feature is its ability to manage all the applications and visibility. For example, if there is malware, spam, or another component that wants to attack the company in my servers, network, or applications, then SecureX will react to the problem."
"The automation and orchestration tools are the most valuable features."
"Integrates well with our existing security infrastructure."
"One of the most valuable features is the simplicity of deploying SecureX. It's very easy to do that and then you gain very detailed visibility into everything that's going on in your network and, obviously, at the device level. There's just a wealth of information that you can pull from all of these products that are part of SecureX. You know exactly if you have an issue or not."
"SecureX enables us to have all the threat intelligence and threat event data in one place."
"The forensics are amazing because when you have enrichment, and the solutions talk with each other, when you need it, you have the ability to know everything in the organization: when, why, whatever."
"The most valuable feature is the risk-based access control."
"The playbooks are valuable. They are the core component. Being able to implement and build a code process to work through and scale out what we want to do is valuable."
"The automation part of the product is great."
"My understanding is the initial setup isn't too hard."
"The most valuable features of Splunk SOAR are the easy integration with other solutions, including other Splunk solutions. The most important playbooks we need on the market come already on the Frontend. However, nowadays, Splunk changed its name, it's not Frontend anymore, it's Splunk Store. This is a very strong point."
"Scalability is the best feature of the solution."
"So far, the interface is very easy to use."
"It's pretty easy when it comes to setting up assets. If you want to fetch emails or call a REST API, you can set up an asset and grab that information."
 

Cons

"For us, the biggest sticking point is that the product is not being designed for multi-tenancy use at present, from an MSP perspective."
"what's missing right now is the multi-tenant capability."
"They could put in more third-party [integrations]... also more playbooks, out-of-the-box, for automation [would be helpful]."
"If they could make the Cisco Umbrella piece a little bit more advanced or easier to manage, that would help. We use it for filtering and when you compare it to a normal content filter, it lacks some functionality."
"Enhancing automation capabilities could further improve the product."
"I'm not sure that I would call it a bug, but sometimes the solution is a little slow."
"The documentation can be improved and the on-prem integration. The set of applications that it was integrated with wasn't comprehensive."
"Remediation stuff could be integrated into the product's automation."
"And most of the challenges that I have faced with the solution can be found in the documentation itself."
"In my opinion, the focus should be on improving its simplicity, specifically the interface, and configuration."
"Creating playbooks using the solution’s playbook editor, for me, is very cumbersome. There have been instances where I have said to myself that I just don't want to use this editor. I might just use a code block and write my own code within it... The functionality in the playbook editor is 80 percent there, but that 20 percent is still lacking. They could make it more efficient."
"The technical support for the Splunk SIEM solution was average."
"The pricing could be a bit more reasonable. It would be great if it were feasible for smaller organizations."
"Splunk SOAR should improve its ease of upgrade, which is a pain point for us right now."
"Splunk's support for integration is subpar and has room for improvement."
"We've had trouble implementing the solution with Microsoft products. There seems to be an integration gap."
 

Pricing and Cost Advice

"For the value you get, the pricing of the solution is excellent."
"It is free. It can't get any better than that."
"The pricing is competitive, especially for education institutions. Licensing can be a little bit difficult to navigate, especially with resellers with Cisco, but for us it has been pretty easy."
"It would be nice if they had a different pricing model. Most of our budget for projects goes towards Cisco."
"It comes free with all Cisco products. So, it is a good price."
"The pricing is the best part of this solution. It is free if you buy Umbrella or Duo Security. It is also a good solution."
"You can spend less money for another solution, but if you really want to have a good solution you have to pay. We are happy that we are getting such a good solution for what we are spending."
"Cisco SecureX is more expensive than Trend Micro. However, considering the integration capabilities with other solutions and the quality of technical support, I believe there's justification for the price difference."
"Splunk SOAR is more expensive compared to other options for SOAR."
"The cost is high and the licensing is on an annual basis."
"In my opinion, the price is high, but if you want good products, you have to be willing to pay for them."
"Splunk SOAR is an expensive solution for an organization of our size."
"I don't know the exact price, but for my region, it is very expensive."
"The licensing cost is reasonable."
"It's very overpriced because it is based on the number of users. There is no bulk licensing."
"When we first purchased our Splunk SOAR license, it was based on an event-count model. It was based on the number of events. I had strong opinions at the time that automation should not be stifled by the amount of automation you can accomplish, so the previous structure was not as beneficial for us. Later that year, we got told or saw at a conference that they announced user-based pricing. We are now in a renewal period, so we migrated to a user-based license model, which is more appropriate for us so that we no longer have to worry about stifling our automation based on the quantity."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
787,061 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
36%
Financial Services Firm
7%
Manufacturing Company
6%
Government
5%
Computer Software Company
14%
Financial Services Firm
14%
Government
10%
Manufacturing Company
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Cisco SecureX?
Integrates well with our existing security infrastructure.
What is your experience regarding pricing and costs for Cisco SecureX?
Cisco SecureX is more expensive than Trend Micro. However, considering the integration capabilities with other solutions and the quality of technical support, I believe there's justification for th...
What needs improvement with Cisco SecureX?
One area for improvement in SecureX could be additional on-premises options for organizations like ours that require more control over certain aspects of the platform. I also think enhancing automa...
What do you like most about Splunk Phantom?
Splunk SOAR's quick response to incidents is the most valuable part.
What is your experience regarding pricing and costs for Splunk Phantom?
The cost is high and the licensing is on an annual basis.
What needs improvement with Splunk Phantom?
The tool's response is slower because it has to search through a huge dataset, which can be improved for latency.
 

Also Known As

Kenna.AppSec, Kenna.VI
Phantom
 

Learn More

 

Overview

 

Sample Customers

NHS, Rackspace, UNC Pembroke, University of North Carolina at Charlotte, Missing Piece
Recorded Future, Blackstone
Find out what your peers are saying about Sonar, Veracode, Checkmarx and others in Application Security Tools. Updated: June 2024.
787,061 professionals have used our research since 2012.