Try our new research platform with insights from 80,000+ expert users

Splunk SOAR vs Tines comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 8, 2024
 

Categories and Ranking

Splunk SOAR
Ranking in Security Orchestration Automation and Response (SOAR)
3rd
Average Rating
8.2
Reviews Sentiment
6.8
Number of Reviews
43
Ranking in other categories
No ranking in other categories
Tines
Ranking in Security Orchestration Automation and Response (SOAR)
12th
Average Rating
9.0
Reviews Sentiment
7.5
Number of Reviews
3
Ranking in other categories
Vulnerability Management (32nd), Threat Intelligence Platforms (20th), Endpoint Detection and Response (EDR) (42nd)
 

Mindshare comparison

As of December 2024, in the Security Orchestration Automation and Response (SOAR) category, the mindshare of Splunk SOAR is 8.6%, down from 9.8% compared to the previous year. The mindshare of Tines is 5.3%, up from 3.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Orchestration Automation and Response (SOAR)
 

Featured Reviews

Ryan Plas - PeerSpot reviewer
Offers playbook automation that helps reduce the manual and tedious work for users
When it comes to Splunk SOAR's ability to provide end-to-end visibility into our company's cloud-native environment, I would say that we are not using the cloud portions of it. I don't know if that's super relevant to what we are doing in our organization. I am 100 percent sure that Splunk SOAR helped reduce your mean time to resolve, but I don't have any metrics on hand but I know it has dramatically decreased. The tool has helped with the business resilience part. I think having it as a platform has been a solid portion of the product that we offer to people. Spunk SOAR has definitely saved my time in alert triage. When some of the tedious enrichment and lookup stuff happens, the analyst doesn't have to deal with such areas, and they can just jump in and see relevant data all in one pane of glass, which has been super helpful for speeding things up. The unified platform helps consolidate networking, security, and IT observability tools. The consolidation of tools impacts our organization as it just helps focus the SOC analyst on a single unified place to find information. It helps keep things streamlined and regular so they know where to look for certain stuff they want. It really helps people with training. It is a really easy tool to onboard people into because everything is right there in the product itself. The product is really great. I would love to see more SOAR innovation going into the tool, especially the on-premises version since it is what we use in our company. I feel the tool needs to encourage continuous improvements, but as a product itself, my company is really happy with the solution. I rate the tool an eight out of ten.
Del Tice - PeerSpot reviewer
Automate daily tasks, phishing emails, ticket creation and IOC investigations
Support is pretty top-notch. If they identify an issue, they notify their customers. For instance, they monitor the tenants, and if a problem occurs, they send an email to inform you. They provide a lot of their support through Slack channels. Each customer has a dedicated channel where you can post questions or mention issues you’re facing. You’ll usually receive a response quickly. Recently, they’ve integrated AI into this process, so you often get useful suggestions within a minute. If needed, you can also request a human to take a look. Their response time is generally quick, although it might be slower at night since they aren’t available 24/7.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Splunk integrates with so many products. It provides us with good information for us to be able to do our jobs."
"In Splunk SOAR, I find the playbooks valuable. We get to create multiple playbooks, and within each playbook, there is a different type of investigation attached to it, which helps out an analyst or new analysts coming on board."
"So far, the interface is very easy to use."
"When you design a playbook, you can integrate multiple log sources and define rules... After that, the platform automatically compiles all these activities and, based on the results, the analyst only has to indicate whether the result is a true or false positive. That reduces the time and effort involved."
"The most valuable feature is the API connector, depending on how it's formatted and who made the actual app offering for it. The REST API is my favorite component. It's very easy to use. The filters are also really valuable. Those are the two primary features but I enjoy using the rest of it."
"The automation part of the product is great."
"Technical support is helpful."
"I like the way Splunk interacts with various systems via the API. The ability to integrate Splunk with our ticketing system has been an immense help because we can maintain our workflow while blending Splunk with our support desk and other ways that we track work."
"The tool was vendor-neutral."
"The best thing is that it's no code, so it doesn't require coding knowledge."
"One of the most valuable features is that it’s a low-code solution."
 

Cons

"The UI can be more customizable for the clients."
"Splunk SOAR can improve IoT/OT security-related case studies or your use cases. Their integration with identity and access management (IAM) solutions is a bit shaky. They don't have good integration with a lot of IAM solutions. They do have good capability in terms of user access management internally, but even with privileged user access, they have a good module. However, if they have to integrate with solutions, such as CyberArk or IBM IAM solutions they are lacking, the visibility of user access is not that much."
"Splunk SOAR should improve its ease of upgrade, which is a pain point for us right now."
"The Splunk SOAR platform was not designed specifically for case management which is why this area needs improvement."
"They can improve on what they are currently doing. They can provide more playbooks or at least template playbooks that are in their repository."
"The cost of Splunk SOAR has room for improvement."
"In my opinion, the focus should be on improving its simplicity, specifically the interface, and configuration."
"Improving the integration ecosystem can raise the quality of the bottom tier of the integrations so that they can work better out of the box."
"They started implementing some AI, and their AI is isolated."
"Tines was a little bit more expensive than Torq."
"Maybe Tines can add more features and demonstrations, like videos on how to use the features within the tool."
 

Pricing and Cost Advice

"I found the price of Splunk SOAR to be good."
"We renewed it this year. This year was the first time there was a dramatic increase in the price. It was kind of non-negotiable. It was just a high increase. We had internal communications, and it was definitely a surprise to us. In a short time frame, we renewed it this year. Prices are going up everywhere, but they are not always justifiable, at least not to our eyes. The pricing this year was definitely a big shock."
"The tool is not cheap."
"Splunk is a fast enterprise tool, but it costs too much. At the same time, it's worth what we pay, in my opinion. We can efficiently perform all the functions and tie together the data. It's the perfect tool for our needs."
"I don't know the exact price, but for my region, it is very expensive."
"In my opinion, the price is high, but if you want good products, you have to be willing to pay for them."
"It's very overpriced because it is based on the number of users. There is no bulk licensing."
"The licensing cost is reasonable."
Information not available
report
Use our free recommendation engine to learn which Security Orchestration Automation and Response (SOAR) solutions are best for your needs.
823,875 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
14%
Manufacturing Company
11%
Government
10%
Computer Software Company
15%
Financial Services Firm
13%
Government
8%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What do you like most about Splunk Phantom?
Splunk SOAR's quick response to incidents is the most valuable part.
What is your experience regarding pricing and costs for Splunk Phantom?
I rate Splunk SOAR two out of 10 for affordability. Splunk is a fast enterprise tool, but it costs too much. At the same time, it's worth what we pay, in my opinion. We can efficiently perform all ...
What needs improvement with Splunk Phantom?
The dashboard could be improved and some other features. SOAR should integrate network capabilities, allowing us to also monitor the WLAN network. Splunk is also expensive and difficult for beginne...
What needs improvement with Tines?
Maybe Tines can add more features and demonstrations, like videos on how to use the features within the tool. For example, when you click on a feature, it could show a video link explaining how to ...
What is your primary use case for Tines?
We use it for automations on the enterprise security aspect.
What advice do you have for others considering Tines?
If someone needs tasks performed daily that can be automated between different systems, and if there's a cybersecurity or SOC analyst team, they can also use it by creating various API calls, setti...
 

Comparisons

 

Also Known As

Phantom
No data available
 

Learn More

 

Overview

 

Sample Customers

Recorded Future, Blackstone
Information Not Available
Find out what your peers are saying about Splunk SOAR vs. Tines and other solutions. Updated: December 2024.
823,875 professionals have used our research since 2012.