No more typing reviews! Try our Samantha, our new voice AI agent.

Splunk SOAR vs VMware Carbon Black Endpoint comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 29, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
5.8
Organizations saved time and reduced workload with Torq, achieving efficiency, cost savings, and improved security workflows through automation.
Sentiment score
4.9
Splunk SOAR boosts ROI with automation, enhancing efficiency, reducing costs, improving incident response, and increasing productivity despite setup effort.
Sentiment score
5.2
Users report VMware Carbon Black Endpoint provides cost savings and malware prevention, enhancing security incident reduction across platforms.
Since we started working with Torq, I am handling much fewer alerts. It is becoming really easy for me to handle an alert.
SOC Analyst at AppsFlyer
We have seen a return on investment, targeting a $600,000 ROI for the year.
Cyber Security Engineer at a real estate/law firm with 5,001-10,000 employees
I have seen a return on investment with Torq, as the automation reduces the number of employees needed and significantly saves both time and resources.
Senior Cybersecurity Engineer at a tech vendor with 10,001+ employees
Since deploying Splunk SOAR, there has been a notable reduction in time spent on monotonous security tasks, which I estimate to be around 95%, enabling my team to focus on more strategic initiatives.
Identity and Access Management Specialist at a university with 10,001+ employees
The saved capacity allows analysts to focus on threat hunting, complex investigations, and security projects, offering the biggest financial benefit from getting more done with the same team size and resources.
Data Scientist at a tech vendor with 51-200 employees
We've seen a decrease in false positives and a significant increase in our containment.
Cyber Security Network Security Engineer at Cirrus Logic
 

Customer Service

Sentiment score
6.6
Torq's customer service is praised for responsiveness, availability, knowledgeable staff, and effective assistance, despite occasional delay issues.
Sentiment score
6.3
Splunk SOAR's support is praised for responsiveness and expertise, with high ratings and helpful documentation and community resources.
Sentiment score
6.2
VMware Carbon Black support varies in effectiveness; global support and community resources are praised, while local support needs improvement.
My impression of their technical support during the initial setup was that they were helpful, responded within a reasonable timeframe, and provided exactly what we needed.
Security Consultant at Integrity360
The speed and quality of their answers have been pretty good, as I usually get a response within 24 hours, and they follow up well.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
We can always get an answer, and the support team are experts in their own system.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
We always received a speedy response within 24 hours, and if we needed to do a live debugging session, they were always available.
Engineer at a tech vendor with 10,001+ employees
Discovering different troubleshooting methods is harder to do with Splunk SOAR than with Enterprise Security or other Splunk services.
Cyber Security Network Security Engineer at Cirrus Logic
We always have a customer support representative who will come in the picture and help us to direct any ticket or any issue that we are facing to the right team.
Manager cybersecurity at Hexion Inc.
Regarding the technical support of Broadcom, they are responsive and helpful.
Senior VP, Technology & Leading Technology Office at a outsourcing company with 1,001-5,000 employees
 

Scalability Issues

Sentiment score
6.6
Users praise Torq's scalability, adaptability, and workflow management, though initial modularization guidance is sometimes lacking.
Sentiment score
6.4
Splunk SOAR is scalable and adaptable, though some configuration challenges exist, especially with AI integration and node performance.
Sentiment score
7.1
VMware Carbon Black Endpoint is praised for scalable, flexible cloud-based solutions despite some policy complexity challenges in large environments.
Its scalability is good because it has a cloud-native architecture and it expands dynamically to handle thousands of alerts at the same time.
Software Engineer at Accenture
Our case management is super scalable.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
In terms of scalability, you can do as long as you can build it, and they can support it.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
This solution is very much scalable, so I would rate it a ten.
Citius Tech at a outsourcing company with 5,001-10,000 employees
It can be extended and adapted as necessary.
Splunk/SOAR Engineer
Regarding scalability, I find it to be a nine, as we have had no issues with scaling Splunk SOAR.
Advance Data Engineer(Cyber Security) at Novo Nordisk
The solution's scalability has had a medium impact on the IT environment.
CTO at Microsoft
 

Stability Issues

Sentiment score
7.5
Torq is praised for its high stability and reliability, with minor issues resolved quickly, ensuring consistent uptime.
Sentiment score
7.3
Splunk SOAR remains stable with proper setup, despite occasional latency, maintaining efficiency in high-alert environments.
Sentiment score
7.4
VMware Carbon Black Endpoint is stable and lightweight, with some version-specific issues and compatibility challenges with certain applications.
We have been using Torq for one and a half years, but we have experienced no downtime.
Angular developer at Flourish software
Most of the time, the system is stable as long as the components that they integrate with are stable.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
I have never faced any downtime or issues.
Senior Information Technology Security Consultant at Mideast Data Systems
We have not experienced any downtime, crashes, or performance issues.
Cyber Security Network Security Engineer at Cirrus Logic
We have not seen any impact in the work that we do with Splunk SOAR or the SIEM platform.
Manager cybersecurity at Hexion Inc.
I have not encountered any outages or glitches within my experience with Splunk SOAR.
Global Head Of Security Architecture Digital & Technology at Aramex
VMware Carbon Black Endpoint is slow for the stability rating.
CTO at Microsoft
 

Room For Improvement

Torq requires improvements in dashboard usability, AI features, error handling, integration, and UI maturity for better user experience.
Users seek more playbooks, enhanced integration, improved learning, AI, and support features in the current system.
VMware Carbon Black Endpoint needs enhancements in integration, mobile support, pricing, compatibility, and security features to meet user expectations.
Torq should offer default templates that can directly scan firewall data and automate actions.
Senior Information Technology Security Consultant at Mideast Data Systems
The AI value depends on maturity. Real value depends heavily on telemetry, integration depth, and workflow design, all of which rely on how mature customers are in their SOC department.
Security Consultant at Integrity360
It was able to capture data but was unable to differentiate between the agent hostname we are using and the hostname that resides on the back end of the Internet.
Senior Consultant at a university with 10,001+ employees
If we start ingesting those data to Splunk SOAR or SIEM with some sort of integration with threat intelligence feed, that will also improve our detection and prediction method or help us with the investigation.
Manager cybersecurity at Hexion Inc.
Torq is better than Splunk SOAR because Torq has a no-code UI where we can accomplish anything through drag and drop.
Senior Information Technology Security Consultant at Mideast Data Systems
It's basically given me a force multiplier.
Soc L1 Engineer at Softcell Technologies Limited
I think VMware Carbon Black Endpoint should improve in every area, because currently the NetGen AV, even from Microsoft and even from CrowdStrike, is better than VMware Carbon Black Endpoint.
CTO at Microsoft
 

Setup Cost

Torq offers flexible pricing based on playbooks, seen as competitive by some but expensive by others needing AI cost clarity.
Splunk SOAR is expensive but justified by its capabilities, offering long-term value despite limited flexibility for smaller businesses.
VMware Carbon Black Endpoint pricing is high yet justifiable for advanced features, with flexible large-scale enterprise options.
When they bring more and more value into the platform, it makes more sense to pay that price, but still, it is expensive.
Senior Cyber Architect at a manufacturing company with 10,001+ employees
Before deciding to implement Torq, I considered that compared to our old case management platform, Torq was a much better price and had a lot better value for what you get out of the platform, which was a key consideration for the company.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
It is an expensive solution, not an inexpensive solution, but we get through the flexibility.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
It is way below what it costs to hire some professionals to do only that type of work.
Splunk Engineer at a recruiting/HR firm with 11-50 employees
Splunk SOAR is moderately priced, neither cheap nor overly expensive.
Splunk/SOAR Engineer
I am familiar with the pricing aspect, setup cost, and licensing cost of Splunk SOAR, and it is pretty much similar to what industries are offering these days.
Manager cybersecurity at Hexion Inc.
My rating for the pricing of VMware Carbon Black Endpoint is that it is not cheap, but it is also not as inexpensive as I would prefer.
CTO at Microsoft
 

Valuable Features

Torq offers AI-driven automation, seamless integrations, and a user-friendly interface, enhancing security operations without programming skills.
Splunk SOAR enhances incident management with playbook automation, third-party integrations, and efficient processes to reduce response times.
VMware Carbon Black Endpoint excels in threat detection, real-time monitoring, and cybersecurity management with advanced features and intuitive interface.
Torq's unified platform approach to AI SOC automation and case management has significantly benefited us by integrating the case management platform with the automation, which saves time compared to managing multiple point solutions across our security stack.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
The fact that I can build whatever I want within my own imagination and skills without relying on code is the best thing about Torq.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
You can copy and paste a cURL command. If you have documentation or APIs, you usually have an example on the side. You basically have all the information on how the API call should be. You can just copy that and paste it into a step, and it will just build the step for you.
Global IT Director at OpenWeb
Creating playbooks using the Playbook Editor in Splunk SOAR is easy. The editor is designed to be user-friendly with visual drag and drop features, allowing for easy workflows without writing any code.
Splunk/SOAR Engineer
Splunk SOAR saves time in threat response, and the time to solve an incident is currently the best in the market.
Strategic Account Executive at a computer software company with 51-200 employees
Splunk SOAR has improved our MTTD and MTTR both with the consolidation with a unified platform with Splunk.
Manager cybersecurity at Hexion Inc.
I assess VMware Carbon Black Endpoint's machine learning capabilities in detecting unknown threats as fantastic.
Senior VP, Technology & Leading Technology Office at a outsourcing company with 1,001-5,000 employees
VMware Carbon Black Endpoint does facilitate endpoint protection and incident response, and it is an EDR.
CTO at Microsoft
 

Categories and Ranking

Torq
Sponsored
Average Rating
8.6
Reviews Sentiment
6.5
Number of Reviews
18
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (4th), AI-SOC (1st), AI-Powered Security Automation (1st)
Splunk SOAR
Average Rating
8.2
Reviews Sentiment
6.4
Number of Reviews
69
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (1st)
VMware Carbon Black Endpoint
Average Rating
7.8
Reviews Sentiment
6.6
Number of Reviews
65
Ranking in other categories
Endpoint Protection Platform (EPP) (28th), Security Incident Response (3rd), Endpoint Detection and Response (EDR) (27th), Ransomware Protection (8th)
 

Mindshare comparison

Security Orchestration Automation and Response (SOAR) Mindshare Distribution
ProductMindshare (%)
Splunk SOAR7.0%
Microsoft Sentinel9.1%
Palo Alto Networks Cortex XSOAR8.8%
Other75.1%
Security Orchestration Automation and Response (SOAR)
Endpoint Protection Platform (EPP) Mindshare Distribution
ProductMindshare (%)
VMware Carbon Black Endpoint2.0%
Microsoft Defender for Endpoint6.5%
CrowdStrike Falcon5.7%
Other85.8%
Endpoint Protection Platform (EPP)
 

Featured Reviews

AD
Solutions Architect at ProArch
Automation has streamlined multi-tenant SOC workflows and improves alert handling efficiency
Although the reporting within Torq is not that great, we did ask for many features regarding reporting in Torq, but due to some platform constraints, they could not make the whole dataset available for us to be used in reporting. Except for that, we used some basic reporting. When I used Torq, it was indeed in the early stages of AI capabilities. Only a few customers were allowed to use it, and we were among them. It functioned well as long as we summarized the data properly. If you input garbage, you would get garbage out. Thus, we had to do significant fine-tuning regarding what data context we provided to the AI orchestrator to get meaningful results. In terms of Torq's unified platform approach to AI SOC automation and case management compared to managing multiple point solutions across my security stack, I find it case-centric. The unified view in case management is good since it provides clarity, although there are limitations regarding how many items in case management can be modified at once. Bulk operations are very limited, potentially due to their back-end database or data retrieval processes that can be improved. Regarding improvements for Torq, when we were onboarded, there were aspects we were uncertain about, such as the number of cases that could be generated, what data we could bring in, how many clients we could onboard, and similar concerns. Initially, we also lacked clarity about the number of playbooks or workflows we could build. Different triggers like system triggers, case-based triggers, and others can be employed without restrictions, but when it comes to on-demand and scheduled jobs, there is a limitation based on the subscription and pricing tier that notably caps the number of workflows we can create. No bulk editing across cases was one issue, along with limited filtering related to single grouping constraints. Additionally, the out-of-the-box case templates provided require substantial modifications before they become usable. There is also a feature in the cases for notes that cannot be searched. They are only visible through the UI, which is another area for improvement. The workflow and execution-based charges seem misleading as this was not discussed initially. I am not sure if new customers are made aware of this. It seems that workflows revolving around cases hinder functionality outside of case management, as we have many use cases needing on-demand triggers and schedules for functions like reporting or polling devices. Creating additional workflows to achieve basic functionalities raises costs significantly, which disadvantages customers. While they facilitate optimization and scaling, the support received tends to be very basic. Improvements can be made in that area as well.
Vikash Kushwaha - PeerSpot reviewer
Full-Stack Software Engineer at mindpathtech
Automated playbooks have transformed incident response and now protect critical services
The biggest advantage I see from my personal experience as an integrator with Splunk SOAR is that it integrates with most of the security features among the Defenders, Microsoft Defender, firewalls, CloudWatch, and AWS security agents, as well as EC2 machines, firewalls, EDR, IAM, email security, and antivirus. It automates the security process over phishing emails and any other brute force attacks. It helps quite a lot because if 100 phishing emails were sent to a domain, a developer can only reach one, two, or five, but for hundreds of others, it actually supports better automated playbooks and provides major security. Splunk SOAR introduced some new and innovative capabilities or approaches that transformed the way my SOC operates. Splunk SOAR provides playbooks for automatic security features, such as for firewalls, phishing mails, and utilizing Defenders or virtual tools. A playbook maintains its algorithms or processes, so if any kind of security issue arises, the playbook automatically runs and handles actions such as IP blocking or resolving brute force attacks, notifying the admin about suspicious users. After implementing Splunk SOAR, the training process for my SOC team to use playbooks takes a long time during the whole integration part, as it retrieves all credentials from us, whether for an EC2 machine or any antivirus. It takes about one to two months for the team to fully sustain and know the processes of the playbooks and security, particularly for three or four individuals in the cyber security or DevOps team. Splunk SOAR significantly reduces the time spent on monotonous security tasks. In banking, insurance, or healthcare, automated services for addressing phishing emails and security threats are common. Having a manual workforce of two or three individuals can only handle five or ten security threats while Splunk SOAR automates the entire process across apps and machines, making it easier and notifying the admin about the threats. If someone tries to breach, Splunk SOAR immediately processes incoming requests, validating them and blocking any unsecured requests, which reduces a lot of time and effort. With the help of the playbook viewer, I assess the visibility provided by Splunk SOAR as very positive, especially for security purposes. If someone is attacked by 100 users, it blocks all the users, while individual developers such as myself can only handle two or three at a time. The automated process of Splunk SOAR handles all the processes concurrently, making it a game-changing solution. It helps reduce mean time to resolve (MTTR). It takes around 10 to 20 minutes to resolve one incident through the whole process and notify the admin of the issue. If there are multiple incidents, calculating the time taken for each, it generally requires around 40 to 50 minutes to resolve five incidents.
PM
CTO at Microsoft
Improved incident investigation has supported response while core protection still needs progress
VMware Carbon Black Endpoint does not have easy integration, as there are many complexities with the Ribitava API, which is very deep. I rate this solution overall as a five or six on a scale from one to ten. I have integrated VMware Carbon Black Endpoint with other tools that are helpful. I think this solution should be targeted at small clients, because adoption will grow more with small businesses tomorrow.
report
Use our free recommendation engine to learn which Security Orchestration Automation and Response (SOAR) solutions are best for your needs.
911,994 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Outsourcing Company
11%
Comms Service Provider
10%
Construction Company
9%
Financial Services Firm
11%
Manufacturing Company
10%
Outsourcing Company
9%
Construction Company
8%
Financial Services Firm
9%
Construction Company
9%
Outsourcing Company
9%
Manufacturing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise5
Large Enterprise11
By reviewers
Company SizeCount
Small Business21
Midsize Enterprise10
Large Enterprise48
By reviewers
Company SizeCount
Small Business31
Midsize Enterprise9
Large Enterprise33
 

Questions from the Community

What needs improvement with Torq?
There are some bugs in Torq, of course. They can be present in data transformation, some UI debugging, and other area...
What is your primary use case for Torq?
My main use case for Torq is the automation of cyber security processes through a SOAR platform and APIs. A main exam...
What advice do you have for others considering Torq?
Regarding someone thinking about using Torq, I recommend looking into their provided academy to start working with th...
What is your experience regarding pricing and costs for Splunk Phantom?
For pricing, I would rate Splunk SOAR a seven where one is high price and ten is low price.
What needs improvement with Splunk Phantom?
Splunk SOAR could be improved by making playbook development easier for new users and providing better troubleshootin...
What is your primary use case for Splunk Phantom?
My main use case for Splunk SOAR is automating repetitive SOC tasks and speeding up incident response, and I mainly u...
What to choose: an endpoint antivirus, an EDR solution or both?
I can recommend Carbon Black, an award-winning next-gen anti-virus (NGAV) and endpoint detection and response (EDR) s...
What's the difference between Carbon Black CB Response and Carbon Black CB Defense?
Carbon Black offers two different levels of Endpoint Detection and Response. One is the VM Carbon Black Cloud Endpoin...
What is your experience regarding pricing and costs for Carbon Black CB Defense?
My rating for the pricing of VMware Carbon Black Endpoint is that it is not cheap, but it is also not as inexpensive ...
 

Also Known As

No data available
Phantom
Carbon Black CB Defense, Bit9, Confer
 

Overview

 

Sample Customers

Information Not Available
Recorded Future, Blackstone
Netflix, Progress Residential, Indeed, Hologic, Gentle Giant, Samsung Research America
Find out what your peers are saying about Splunk, Palo Alto Networks, Microsoft and others in Security Orchestration Automation and Response (SOAR). Updated: August 2026.
911,994 professionals have used our research since 2012.