Staff Security Engineer at a engineering company with 10,001+ employees
Real User
Top 20
2023-07-20T00:30:00Z
Jul 20, 2023
The most valuable feature is the API connector, depending on how it's formatted and who made the actual app offering for it. The REST API is my favorite component. It's very easy to use. The filters are also really valuable. Those are the two primary features but I enjoy using the rest of it.
Sr. Principal Info Sec Analyst at Veritas Technologies LLC
Real User
Top 10
2023-06-09T20:06:00Z
Jun 9, 2023
When you design a playbook, you can integrate multiple log sources and define rules... After that, the platform automatically compiles all these activities and, based on the results, the analyst only has to indicate whether the result is a true or false positive. That reduces the time and effort involved.
Director of Security Engineering and Operations at a legal firm with 1,001-5,000 employees
Real User
Top 5
2023-05-12T16:14:00Z
May 12, 2023
I like the way Splunk interacts with various systems via the API. The ability to integrate Splunk with our ticketing system has been an immense help because we can maintain our workflow while blending Splunk with our support desk and other ways that we track work.
The solution allows us to customize playbooks and incorporate custom code, allowing us to drag and drop elements while still writing code to build the integrations we need.
The most valuable feature of Splunk Phantom that stands out is it has a great SOAR. The automation and orchestration module is highly mature. A lot of use cases are on user entity and behavioral analytics (UEBA), which is artificial intelligence and machine learning-based (AIML).
Splunk SOAR offers features like automation and orchestration of manual tasks, speeding up work, detection and response to advanced and emerging threats.
Go from overwhelmed to in-control
Automate manual tasks. Address every alert, every day. Establish repeatable procedures that allow security analysts to stop being reactive and focus on mission-critical objectives to protect your business.
Force multiply your team
Orchestrate and automate repetitive tasks, investigation and response to...
Splunk SOAR's quick response to incidents is the most valuable part.
It helps increase efficiency and productivity.
The ability to automate Splunk SOAR and customize the playbook use cases is the most valuable feature and is very exciting for me.
The most valuable feature of Splunk SOAR is the automated playbooks, which saves analysts time.
The most valuable feature is the API connector, depending on how it's formatted and who made the actual app offering for it. The REST API is my favorite component. It's very easy to use. The filters are also really valuable. Those are the two primary features but I enjoy using the rest of it.
The product’s integration with other Splunk products is valuable.
When you design a playbook, you can integrate multiple log sources and define rules... After that, the platform automatically compiles all these activities and, based on the results, the analyst only has to indicate whether the result is a true or false positive. That reduces the time and effort involved.
I like the way Splunk interacts with various systems via the API. The ability to integrate Splunk with our ticketing system has been an immense help because we can maintain our workflow while blending Splunk with our support desk and other ways that we track work.
The solution’s dashboard is really good and customizable. It also has a good UI.
My understanding is the initial setup isn't too hard.
The solution allows us to customize playbooks and incorporate custom code, allowing us to drag and drop elements while still writing code to build the integrations we need.
The customizable playbook is the most valuable aspect of the solution.
Technical support is helpful.
The most valuable feature of Splunk Phantom that stands out is it has a great SOAR. The automation and orchestration module is highly mature. A lot of use cases are on user entity and behavioral analytics (UEBA), which is artificial intelligence and machine learning-based (AIML).
I have found all the security automation platform features of Splunk Phantom to be good. The Automation playbook development is highly useful.
I like the integration capabilities of Phantom. It has a lot of integrations with other products.
Its searching methodologies are also good. It is also easy to understand and easy to create playbooks.
The customization continues to be excellent.
So far, the interface is very easy to use.
Very flexible integration with other tools
The most valuable feature is the risk-based access control.