Try our new research platform with insights from 80,000+ expert users

Splunk SOAR vs ThreatConnect Threat Intelligence Platform (TIP) comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 28, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Torq
Sponsored
Ranking in Security Orchestration Automation and Response (SOAR)
8th
Average Rating
8.8
Reviews Sentiment
4.9
Number of Reviews
4
Ranking in other categories
AI-SOC (13th), AI-Powered Security Automation (2nd)
Splunk SOAR
Ranking in Security Orchestration Automation and Response (SOAR)
2nd
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
53
Ranking in other categories
No ranking in other categories
ThreatConnect Threat Intell...
Ranking in Security Orchestration Automation and Response (SOAR)
15th
Average Rating
8.4
Reviews Sentiment
6.5
Number of Reviews
9
Ranking in other categories
Threat Intelligence Platforms (TIP) (6th)
 

Mindshare comparison

As of January 2026, in the Security Orchestration Automation and Response (SOAR) category, the mindshare of Torq is 4.9%, up from 4.5% compared to the previous year. The mindshare of Splunk SOAR is 7.8%, up from 7.3% compared to the previous year. The mindshare of ThreatConnect Threat Intelligence Platform (TIP) is 2.4%, up from 1.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Orchestration Automation and Response (SOAR) Market Share Distribution
ProductMarket Share (%)
Splunk SOAR7.8%
Torq4.9%
ThreatConnect Threat Intelligence Platform (TIP)2.4%
Other84.9%
Security Orchestration Automation and Response (SOAR)
 

Featured Reviews

Trevor R. - PeerSpot reviewer
Cybersecurity Engineer at a real estate/law firm with 10,001+ employees
Automation has transformed phishing triage and case management for our security team
In terms of increasing alert handling capability for our SecOps staff, Torq's Agentic AI is really strong in analysis, and recently, we started using what's called the AI Step, having really great success. Using that one piece of AI, we auto-closed 511 cases in quarter four alone. Torq has changed the day-to-day experience for my security analysts by enhancing their workload management and how they feel about their job, as they can now operate cases more quickly and have a nicer centralized location for information that previously required manual work. Torq's unified platform approach to AI SOC automation and case management has significantly benefited us by integrating the case management platform with the automation, which saves time compared to managing multiple point solutions across our security stack.
SS
Manager cybersecurity at Hexion Inc.
Automates threat response and reduces investigation time but needs better threat intelligence integration
One thing that we would like to see with Splunk SOAR is the expandability to the threat intelligence feed. Currently, we have limited ingestion to the threat intelligence feed for the correlation purpose. We would like to see it being integrated, with license cost or without license cost, to leading threat intelligence sources such as Recorded Future, Feedly, or Flare. That is something we would appreciate having integrated. The second thing on the improvement side is about exposed credential-related information. If we start ingesting those data to Splunk SOAR or SIEM with some sort of integration with threat intelligence feed, that will also improve our detection and prediction method or help us with the investigation.
Vyas Shubham - PeerSpot reviewer
Product Analyst at a consultancy with 51-200 employees
Centralized threat insights have streamlined detection and automated phishing response
Based on my experience, ThreatConnect Threat Intelligence Platform (TIP) is already doing a great job in the market by decreasing threats from external sources. A few improvements I would suggest include integration enhancements, as users report that some integrations could be tighter or easier to configure. Additionally, plug and play connectors for popular security tools and threat feeds could streamline operations. There could also be easier event generation and sharing, as some reviewers mentioned that generating and sharing events or intelligence with internal teams or external partners is not as smooth as it could be. Improved pricing or tiered options could make it more accessible, especially for smaller organizations that do not require all enterprise features. Some users find the interface complex, particularly for everyday tasks such as filtering, tagging, or navigating playbooks. A more intuitive UI that aligns with typical analyst workflows would reduce the learning curve and boost productivity. To improve my rating closer to ten, the user interface can be simplified, as it is complex. Enhancing user experience and providing richer enrichment sources would further increase its value. Addressing these areas would make the platform more intuitive, comprehensive, and easier to adopt across all teams.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"What I appreciate most about Torq is that it is an essential part of our system."
"Using that one piece of AI, we auto-closed 511 cases in quarter four alone."
"Once I started to use the system and I saw the potential, it changed all of our work in IT."
"As an analyst, it has demonstrated potential to reduce workforce requirements and time needed for related activities."
"It helps increase efficiency and productivity."
"In terms of deployment, there were no issues. It was pretty seamless."
"Splunk SOAR allows us to connect to multiple platforms, whether they are networks, security, or observability."
"When you design a playbook, you can integrate multiple log sources and define rules... After that, the platform automatically compiles all these activities and, based on the results, the analyst only has to indicate whether the result is a true or false positive. That reduces the time and effort involved."
"The automation part of the product is great."
"The most valuable feature of Splunk SOAR that stands out is it has a great SOAR. The automation and orchestration module is highly mature. A lot of use cases are on user entity and behavioral analytics (UEBA), which is artificial intelligence and machine learning-based (AIML)."
"The ability to automate Splunk SOAR and customize the playbook use cases is the most valuable feature and is very exciting for me."
"In Splunk SOAR, I find the playbooks valuable. We get to create multiple playbooks, and within each playbook, there is a different type of investigation attached to it, which helps out an analyst or new analysts coming on board."
"ThreatConnect Threat Intelligence Platform (TIP) has positively impacted our organization by significantly reducing response times and improving detection accuracy by ensuring only high-confidence, context-rich indicators are pushed to security controls."
"ThreatConnect Threat Intelligence Platform (TIP) has a significant positive impact on our organization by improving our ability to detect, prioritize, and respond to threats quickly through centralized and enriched threat intelligence."
"ThreatConnect Threat Intelligence Platform (TIP) is a robust platform that helps with advanced AI-driven intelligence, and it assists whenever there is a problem, serving as a single-stop solution."
"We have been able to see a return on investment as our clients believe in us more."
"I like their customer support."
"The tool's installation, integration, and playbooks are very straightforward."
"It's a solid platform and is stable enough. It is not complicated and is easy to use."
"The most valuable features are ease of use and the ability to customize it."
 

Cons

"Regarding stability, I have noticed some lagging, crashing, and downtime, which is one of my largest gripes."
"It was able to capture data but was unable to differentiate between the agent hostname we are using and the hostname that resides on the back end of the Internet."
"The initial deployment of Torq was not easy."
"Creating playbooks using the solution’s playbook editor, for me, is very cumbersome. There have been instances where I have said to myself that I just don't want to use this editor. I might just use a code block and write my own code within it... The functionality in the playbook editor is 80 percent there, but that 20 percent is still lacking. They could make it more efficient."
"There are areas in Splunk SOAR that have room for improvement. To make Splunk SOAR a better solution, there could be better built-in debugging tools, smarter playbook suggestions, and enhanced lifecycle management."
"One thing that we would like to see with Splunk SOAR is the expandability to the threat intelligence feed."
"I'd rate Splunk's technical support around five because compared to IBM QRadar, their support is much better. I feel Splunk should enhance their support, as it appears lacking, especially considering the costs associated with higher licenses."
"We have playbooks written to extract these events and put them into the workflow since it wasn't structured as expected. It was a miss for us. We couldn't figure out why it broke or what actually happened there. It was something in this feed with legitimate and security events, so we tried to understand the names and what we would call them."
"The UI can be more customizable for the clients."
"Improving the integration ecosystem can raise the quality of the bottom tier of the integrations so that they can work better out of the box."
"Portability is one thing that is currently lacking. The open-source product that I evaluated had portability. It would require a lot of development effort, but it will save the cost of rewriting all the playbooks."
"Some users find the interface complex, particularly for everyday tasks such as filtering, tagging, or navigating playbooks."
"I would like to see improvements in the time zone support of their customer service, considering users are from different time zones."
"Support is an area with which nobody is ever fully satisfied, so it can be improved."
"It would be good to have more feeds and more integrated sources for enrichment."
"ThreatConnect Threat Intelligence Platform (TIP) could be improved by simplifying the user interface to better fit day-to-day analyst workflow and reducing the complexity of configuring playbook and score logic."
"Sometimes, when using the solution, it slows down, affecting our ability to mitigate threats."
"Integration is an area that could use some improvement."
"ThreatConnect Threat Intelligence Platform (TIP) could be better in terms of cost, as the basic needs of the software are emphasized."
 

Pricing and Cost Advice

Information not available
"While I can't confirm the exact pricing, some colleagues have mentioned that Splunk SOAR may be on the costlier side."
"When we first purchased our Splunk SOAR license, it was based on an event-count model. It was based on the number of events. I had strong opinions at the time that automation should not be stifled by the amount of automation you can accomplish, so the previous structure was not as beneficial for us. Later that year, we got told or saw at a conference that they announced user-based pricing. We are now in a renewal period, so we migrated to a user-based license model, which is more appropriate for us so that we no longer have to worry about stifling our automation based on the quantity."
"Splunk SOAR is an expensive solution for an organization of our size."
"It's very overpriced because it is based on the number of users. There is no bulk licensing."
"I found the price of Splunk SOAR to be good."
"Splunk is a fast enterprise tool, but it costs too much. At the same time, it's worth what we pay, in my opinion. We can efficiently perform all the functions and tie together the data. It's the perfect tool for our needs."
"The tool is not cheap."
"I don't know the exact price, but for my region, it is very expensive."
"The tool is expensive."
"The price of this product is in the mid-range, not too expensive, nor inexpensive."
"I rate the product price as six on a scale of one to ten, where one is extremely expensive, and ten means it is cheap."
"The price could be better."
report
Use our free recommendation engine to learn which Security Orchestration Automation and Response (SOAR) solutions are best for your needs.
880,844 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Computer Software Company
8%
Manufacturing Company
7%
Healthcare Company
6%
Financial Services Firm
12%
Manufacturing Company
11%
Computer Software Company
9%
University
6%
Financial Services Firm
17%
Computer Software Company
6%
Comms Service Provider
6%
Retailer
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business12
Midsize Enterprise7
Large Enterprise33
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise23
Large Enterprise4
 

Questions from the Community

What needs improvement with Torq?
From our research and testing with the tool, we determined there need to be modifications and changes to train the LL...
What is your primary use case for Torq?
I used Torq for conducting one of the proof of evaluations for a vendor we are connected with. I am currently working...
What advice do you have for others considering Torq?
One of our members uses AWS, and we receive their feed. This involves triaging AWS-related logs. While I do not have ...
What do you like most about Splunk Phantom?
Splunk SOAR's quick response to incidents is the most valuable part.
What is your experience regarding pricing and costs for Splunk Phantom?
I am familiar with the pricing aspect, setup cost, and licensing cost of Splunk SOAR, and it is pretty much similar t...
What needs improvement with Splunk Phantom?
The visibility of Splunk SOAR's playbook viewer is rather unclear to me; I wonder what the visibility is for. There a...
What needs improvement with ThreatConnect Threat Intelligence Platform (TIP)?
ThreatConnect Threat Intelligence Platform (TIP) could be improved by simplifying the user interface to better fit da...
What is your primary use case for ThreatConnect Threat Intelligence Platform (TIP)?
ThreatConnect Threat Intelligence Platform (TIP) serves as the primary platform in our organization for IOC aggregati...
 

Also Known As

No data available
Phantom
No data available
 

Interactive Demo

Demo not available
Demo not available
 

Overview

 

Sample Customers

Information Not Available
Recorded Future, Blackstone
Customer Case Studies & Use Cases
Find out what your peers are saying about Splunk SOAR vs. ThreatConnect Threat Intelligence Platform (TIP) and other solutions. Updated: December 2025.
880,844 professionals have used our research since 2012.