Try our new research platform with insights from 80,000+ expert users

IBM Resilient vs Splunk SOAR comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 15, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

IBM Resilient
Ranking in Security Orchestration Automation and Response (SOAR)
11th
Average Rating
7.4
Reviews Sentiment
6.6
Number of Reviews
18
Ranking in other categories
Security Incident Response (3rd)
Splunk SOAR
Ranking in Security Orchestration Automation and Response (SOAR)
3rd
Average Rating
8.0
Reviews Sentiment
6.8
Number of Reviews
45
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of July 2025, in the Security Orchestration Automation and Response (SOAR) category, the mindshare of IBM Resilient is 1.9%, down from 2.7% compared to the previous year. The mindshare of Splunk SOAR is 7.6%, down from 8.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Orchestration Automation and Response (SOAR)
 

Featured Reviews

Usman Bhatti - PeerSpot reviewer
Simple deployment, scalable, but lacking third-party solution compatibility
Integrating IBM Resilient with other applications can be very difficult and technically challenging. Often, they use the excuse that you are using the latest version of an application, such as an endpoint security system, and they don't have an API or support for it at the moment. There is no automation in the SOAR solution. It's worth noting that many third-party add-on applications needed to be purchased separately to integrate with IBM Resilient. While there were built-in applications available for incident remediation, the selection was limited. Additionally, integrating third-party applications was often a difficult and time-consuming process due to the technical complexity involved.
Hamada Elewa - PeerSpot reviewer
Playbook complexity challenges integration but customization enables professional operation
We work with Splunk SOAR from a security perspective, focusing on User Behavior Analytics (UBA) and Security Orchestration, Automation, and Response (SOAR) The customization of the playbook in Splunk SOAR is very beneficial. After building the playbook, it operates professionally. There is an AI…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution is simple to use and to integrate with IBM QRadar."
"What I like most about IBM Resilient is that it has a complete stack, which means you don't need to use different OEM products because you have all you need under the IBM Resilient umbrella. You don't need to worry much about integrations and components because you're working with tested and proven architecture."
"The product is very good at incident response."
"The integration with IBM SIM and the ability to block users during brute force attacks are particularly effective."
"This is a good solution that we recommend for customers."
"As a whole, the product is stable...Technical support is very good."
"Its flexibility is the most valuable."
"The UBA, User Behavior Analytics, is very good."
"Our customers find it easy to conduct searches and consider it an excellent content management system."
"Scalability is the best feature of the solution."
"The customizable playbook is the most valuable aspect of the solution."
"In Splunk SOAR, I find the playbooks valuable. We get to create multiple playbooks, and within each playbook, there is a different type of investigation attached to it, which helps out an analyst or new analysts coming on board."
"Splunk SOAR's extensive library of pre-built integrations allows it to connect with a vast array of popular security and IT applications, streamlining workflows across our existing security stack."
"The most valuable features are the Splunk SOAR apps and playbooks."
"The solution’s dashboard is really good and customizable. It also has a good UI."
"Splunk SOAR has made a huge impact across security operations and the business overall."
 

Cons

"It is not very straightforward to set up custom integrations, especially with services like Azure. You need an additional server for integration."
"The response time of the support is an area of concern where improvements are required."
"The ability to analyze incidents needs to be improved in the solution."
"Integrating IBM Resilient with other applications can be very difficult and technically challenging. Often, they use the excuse that you are using the latest version of an application, such as an endpoint security system, and they don't have an API or support for it at the moment. There is no automation in the SOAR solution."
"One thing to improve is how it handles data formats, which currently might require scripting for conversion to CSV before uploading."
"IBM Resilient is quite complex, including its configuration."
"The implementation could be a bit simpler."
"Its price needs improvement."
"We want to see improvements made to the APIs such that we can connect to many different systems and data sources."
"Some of the training materials are on a basic level."
"The tool's response is slower because it has to search through a huge dataset, which can be improved for latency."
"The scalability could be better."
"Splunk SOAR can improve IoT/OT security-related case studies or your use cases. Their integration with identity and access management (IAM) solutions is a bit shaky. They don't have good integration with a lot of IAM solutions. They do have good capability in terms of user access management internally, but even with privileged user access, they have a good module. However, if they have to integrate with solutions, such as CyberArk or IBM IAM solutions they are lacking, the visibility of user access is not that much."
"In my opinion, the focus should be on improving its simplicity, specifically the interface, and configuration."
"Improving the integration ecosystem can raise the quality of the bottom tier of the integrations so that they can work better out of the box."
"Providing Splunk app developers and playbook developers Python Stub files so that way when they create custom code through their IDE, they can have IntelliCode suggestions."
 

Pricing and Cost Advice

"The cost of the product is quite high."
"We could create unlimited users using the license we had purchased."
"I feel it is an expensive product when my company pays annually for renewal, support, and follow-up."
"Pricing for the solution is good, in my opinion."
"It is very expensive."
"There are no costs except for the support services that our company pays in addition to the licensing charges attached to the solution."
"There is a license you need to pay for in order to use this product."
"I would rate the tool’s pricing a three out of ten. The tool’s pricing is on a yearly basis."
"I found the price of Splunk SOAR to be good."
"Splunk SOAR is more expensive compared to other options for SOAR."
"The licensing cost is reasonable."
"I don't know the exact price, but for my region, it is very expensive."
"Splunk SOAR is an expensive solution for an organization of our size."
"The tool is not cheap."
"In my opinion, the price is high, but if you want good products, you have to be willing to pay for them."
"The cost is high and the licensing is on an annual basis."
report
Use our free recommendation engine to learn which Security Orchestration Automation and Response (SOAR) solutions are best for your needs.
861,524 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
33%
Computer Software Company
12%
Manufacturing Company
8%
Government
6%
Computer Software Company
13%
Financial Services Firm
13%
Manufacturing Company
11%
University
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about IBM Resilient?
It is a stable solution...It is a scalable solution.
What is your experience regarding pricing and costs for IBM Resilient?
I am not the one in charge of pricing, so I am not sure about the costs.
What needs improvement with IBM Resilient?
Integration with some devices, including Cisco PowerPower and certain antivirus products, has limitations.
What do you like most about Splunk Phantom?
Splunk SOAR's quick response to incidents is the most valuable part.
What is your experience regarding pricing and costs for Splunk Phantom?
Splunk SOAR is moderately priced, neither cheap nor overly expensive.
What needs improvement with Splunk Phantom?
There are areas in Splunk SOAR that have room for improvement. To make Splunk SOAR a better solution, there could be better built-in debugging tools, smarter playbook suggestions, and enhanced life...
 

Also Known As

No data available
Phantom
 

Overview

 

Sample Customers

Golden Living, Health Equity, USA Funds
Recorded Future, Blackstone
Find out what your peers are saying about IBM Resilient vs. Splunk SOAR and other solutions. Updated: June 2025.
861,524 professionals have used our research since 2012.