Try our new research platform with insights from 80,000+ expert users

Splunk SOAR vs ThreatConnect Threat Intelligence Platform (TIP) comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 28, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Splunk SOAR
Ranking in Security Orchestration Automation and Response (SOAR)
2nd
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
51
Ranking in other categories
No ranking in other categories
ThreatConnect Threat Intell...
Ranking in Security Orchestration Automation and Response (SOAR)
15th
Average Rating
8.4
Reviews Sentiment
6.5
Number of Reviews
8
Ranking in other categories
Threat Intelligence Platforms (TIP) (6th)
 

Mindshare comparison

As of January 2026, in the Security Orchestration Automation and Response (SOAR) category, the mindshare of Splunk SOAR is 7.8%, up from 7.3% compared to the previous year. The mindshare of ThreatConnect Threat Intelligence Platform (TIP) is 2.4%, up from 1.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Orchestration Automation and Response (SOAR) Market Share Distribution
ProductMarket Share (%)
Splunk SOAR7.8%
ThreatConnect Threat Intelligence Platform (TIP)2.4%
Other89.8%
Security Orchestration Automation and Response (SOAR)
 

Featured Reviews

SS
Manager cybersecurity at Hexion Inc.
Automates threat response and reduces investigation time but needs better threat intelligence integration
One thing that we would like to see with Splunk SOAR is the expandability to the threat intelligence feed. Currently, we have limited ingestion to the threat intelligence feed for the correlation purpose. We would like to see it being integrated, with license cost or without license cost, to leading threat intelligence sources such as Recorded Future, Feedly, or Flare. That is something we would appreciate having integrated. The second thing on the improvement side is about exposed credential-related information. If we start ingesting those data to Splunk SOAR or SIEM with some sort of integration with threat intelligence feed, that will also improve our detection and prediction method or help us with the investigation.
Zaid bin junaid  - PeerSpot reviewer
Growth and Product Manager at Flash.co
Detects cyber threats early and improves incident response with AI-driven insights
The main focus for using ThreatConnect Threat Intelligence Platform (TIP) is advanced threat prediction and data protection of the organization, which has a great response to threat detection. If there is a cyber security attack, it helps significantly. The platform is exceptionally efficient and provides a very good response whenever required. The advanced threat detection helps identify suspicious activity, and whenever there is a cyber attack, it focuses on the process, analyzes the cyber security attacks on time, and provides advance warning if there is a problem. The artificial intelligence used is something relied upon and is truly excellent. Key features of ThreatConnect Threat Intelligence Platform (TIP) include a Unified Threat Library that centralizes the threat intelligence data sources and normalizes the scoring data to ensure that it is ready for action. It also provides AI-powered analytics that uses AI-driven tools like CAL and ATT&CK analysis to provide insights and contextualize the threats and behaviors. The Unified Library helps unify the data, enables advanced detection, and provides centralized analysis of the threat library, connecting to ongoing or incoming threats. It helps with strategic, tactical, operational, and technical threat intelligence, with each type providing a different insight into the threat landscape, contributing to a well-rounded cyber security strategy. It has helped create a more secure environment, improving scalability and work efficiency by 38.5%. It has also helped defend against multiple cyber attacks, making it a truly beneficial solution.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"In terms of deployment, there were no issues. It was pretty seamless."
"The product provides 100% automation for certain processes."
"When you design a playbook, you can integrate multiple log sources and define rules... After that, the platform automatically compiles all these activities and, based on the results, the analyst only has to indicate whether the result is a true or false positive. That reduces the time and effort involved."
"The benefits were immediate when we started using Mission Control Splunk SOAR over a year ago; it has made it easier for our analysts to work on alerts using playbooks and forward them."
"Fortunately, the system helps to parse through these alerts and determine which ones are important and need further investigation."
"The most valuable feature of the solution is the playbook automation just because it allows us to reduce the manual actions that SOC has to handle."
"The most valuable features of Splunk SOAR are the easy integration with other solutions, including other Splunk solutions. The most important playbooks we need on the market come already on the Frontend. However, nowadays, Splunk changed its name, it's not Frontend anymore, it's Splunk Store. This is a very strong point."
"It helps increase efficiency and productivity."
"ThreatConnect Threat Intelligence Platform (TIP) is a robust platform that helps with advanced AI-driven intelligence, and it assists whenever there is a problem, serving as a single-stop solution."
"The most valuable features are ease of use and the ability to customize it."
"ThreatConnect has a highly user-friendly interface."
"I like their customer support."
"ThreatConnect Threat Intelligence Platform (TIP) has positively impacted our organization by significantly reducing response times and improving detection accuracy by ensuring only high-confidence, context-rich indicators are pushed to security controls."
"The product automatically generated a threat score based on the maliciousness of an IP."
"It's a solid platform and is stable enough. It is not complicated and is easy to use."
"We have been able to see a return on investment as our clients believe in us more."
 

Cons

"I'm not an expert on Splunk SOAR, but I'm sure our team members know what areas could be improved."
"The application does not work properly and does not pass the log-based configuration. I feel that some kind of review should happen in the application. This review should validate things so that we can get the right information. Splunk does not tell us where the IP address is associated with."
"The tool's response is slower because it has to search through a huge dataset, which can be improved for latency."
"While support is available, the resources around Splunk SOAR are more homegrown by other users, and discovering different troubleshooting methods is harder to do with Splunk SOAR than with Enterprise Security or other Splunk services."
"The Splunk SOAR platform was not designed specifically for case management which is why this area needs improvement."
"It would be nice if we could put it on other search heads, not just Enterprise Security."
"What we have seen is if the workflow gets halted or if we want to halt a workflow, it cannot be resumed."
"Providing Splunk app developers and playbook developers Python Stub files so that way when they create custom code through their IDE, they can have IntelliCode suggestions."
"It would be good to have more feeds and more integrated sources for enrichment."
"They should make it a little bit easier to generate events and share them with the community"
"I would like to see improvements in the time zone support of their customer service, considering users are from different time zones."
"ThreatConnect Threat Intelligence Platform (TIP) could be better in terms of cost, as the basic needs of the software are emphasized."
"Support is an area with which nobody is ever fully satisfied, so it can be improved."
"I couldn’t get any training videos online when I was working with the tool."
"Integration is an area that could use some improvement."
"Sometimes, when using the solution, it slows down, affecting our ability to mitigate threats."
 

Pricing and Cost Advice

"Splunk SOAR is an expensive solution for an organization of our size."
"It's very overpriced because it is based on the number of users. There is no bulk licensing."
"The licensing cost is reasonable."
"In my opinion, the price is high, but if you want good products, you have to be willing to pay for them."
"Splunk SOAR is moderately priced, neither cheap nor overly expensive."
"Splunk SOAR is more expensive compared to other options for SOAR."
"We renewed it this year. This year was the first time there was a dramatic increase in the price. It was kind of non-negotiable. It was just a high increase. We had internal communications, and it was definitely a surprise to us. In a short time frame, we renewed it this year. Prices are going up everywhere, but they are not always justifiable, at least not to our eyes. The pricing this year was definitely a big shock."
"The cost is high and the licensing is on an annual basis."
"I rate the product price as six on a scale of one to ten, where one is extremely expensive, and ten means it is cheap."
"The price of this product is in the mid-range, not too expensive, nor inexpensive."
"The tool is expensive."
"The price could be better."
report
Use our free recommendation engine to learn which Security Orchestration Automation and Response (SOAR) solutions are best for your needs.
879,422 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
12%
Manufacturing Company
10%
Computer Software Company
10%
University
7%
Financial Services Firm
17%
Computer Software Company
7%
Comms Service Provider
6%
Educational Organization
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business12
Midsize Enterprise7
Large Enterprise31
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise23
Large Enterprise4
 

Questions from the Community

What do you like most about Splunk Phantom?
Splunk SOAR's quick response to incidents is the most valuable part.
What is your experience regarding pricing and costs for Splunk Phantom?
I am familiar with the pricing aspect, setup cost, and licensing cost of Splunk SOAR, and it is pretty much similar to what industries are offering these days. We never had any issue when we had to...
What needs improvement with Splunk Phantom?
The visibility of Splunk SOAR's playbook viewer is rather unclear to me; I wonder what the visibility is for. There are indeed some problems with integrating Splunk SOAR with other Splunk products ...
What is your experience regarding pricing and costs for ThreatConnect Threat Intelligence Platform (TIP)?
The experience with pricing, setup cost, and licensing was seamless. Assistance was provided with everything on time, but the pricing could be improved as it is somewhat pricey compared to other so...
What needs improvement with ThreatConnect Threat Intelligence Platform (TIP)?
ThreatConnect Threat Intelligence Platform (TIP) could be better in terms of cost, as the basic needs of the software are emphasized. It provides good solutions, but if similar offerings were avail...
What is your primary use case for ThreatConnect Threat Intelligence Platform (TIP)?
The main use case is threat detection, and it helps day-to-day with threat detection, response, and the cyber security automation feature, which is exceptionally effective. ThreatConnect Threat Int...
 

Also Known As

Phantom
No data available
 

Interactive Demo

Demo not available
 

Overview

 

Sample Customers

Recorded Future, Blackstone
Customer Case Studies & Use Cases
Find out what your peers are saying about Splunk SOAR vs. ThreatConnect Threat Intelligence Platform (TIP) and other solutions. Updated: December 2025.
879,422 professionals have used our research since 2012.