Splunk can be both a SIEM and a SOAR platform, depending on the Splunk product you mean. Reviewed on ****, Splunk says Splunk SOAR integrates with more than 300 third-party tools and supports more than 2,800 automated actions.
The product names make the distinction:
- Splunk Enterprise Security Essentials is primarily a SIEM.
- Splunk SOAR is a dedicated SOAR product.
- Splunk Enterprise Security Premier combines SIEM, SOAR, UEBA and other security operations capabilities in one platform.
Splunk SIEM vs SOAR at a Glance
| Splunk product | Category | Primary purpose |
|---|---|---|
| Splunk Enterprise Security Essentials | SIEM | Collect, analyze and correlate security data to detect and investigate threats |
| Splunk Enterprise Security Premier | SIEM, SOAR and UEBA | Combine threat detection, investigation and automated response |
| Splunk SOAR | SOAR | Automate response workflows with playbooks, integrations and response actions |
| Splunk Enterprise or Splunk Cloud Platform | Data and analytics platform | Ingest, search, analyze and visualize machine data |
Why Splunk Enterprise Security Is a SIEM
Splunk Enterprise Security is a SIEM because it collects and analyzes security data from sources such as endpoints, applications, cloud services, identity systems and network devices.
Splunk Enterprise Security Essentials is Splunk's SIEM offering. It supports security data analysis, threat detection, risk-based alerting, threat intelligence, alert triage and case management.
Splunk Enterprise Security uses the Splunk data platform to:
- Ingest security logs and telemetry
- Correlate events across users, devices and applications
- Detect suspicious behavior
- Add threat intelligence to alerts
- Prioritize high-risk activity
- Support investigations and incident management
Why Splunk SOAR Is a SOAR Platform
Splunk SOAR is a SOAR platform because it connects security tools and automates repeatable incident-response tasks. SOAR stands for Security Orchestration, Automation and Response.
Splunk SOAR is Splunk's dedicated SOAR product. It uses playbooks, integrations and automated actions to coordinate responses across security and IT tools.
Typical Splunk SOAR actions include:
- Enriching an alert with threat intelligence
- Checking whether an IP address or domain is malicious
- Disabling a compromised user account
- Blocking an IP address on a firewall
- Isolating an endpoint
- Creating or updating a case
- Notifying analysts or other teams
Splunk says Splunk SOAR integrates with more than 300 third-party tools and supports more than 2,800 automated actions.
What Is the Difference Between Splunk SIEM and Splunk SOAR?
The difference is straightforward:
- A SIEM finds and investigates threats.
- A SOAR platform automates and coordinates the response.
For example, Splunk Enterprise Security might detect an unusual login followed by suspicious activity and create a high-risk alert. Splunk SOAR could then enrich the alert, check identity data, open a case and disable the account through an approved playbook.
| Capability | SIEM | SOAR |
|---|---|---|
| Collect security logs | Yes | Usually consumes alerts and data from other tools |
| Correlate events | Yes | Limited, and not its primary function |
| Detect threats | Yes | Not its primary function |
| Investigate incidents | Yes | Supports investigation workflows |
| Automate response actions | Limited or integrated | Yes |
| Connect security tools | Through data integrations | Through orchestration and action integrations |
| Use playbooks | Sometimes | Core capability |
Is Splunk Enterprise Itself a SIEM?
Splunk Enterprise is not automatically a complete SIEM or SOAR platform. It is a general data and analytics platform. Organizations can use it as the foundation for security monitoring, while Splunk Enterprise Security adds the SIEM functionality.
Splunk SOAR is a separate SOAR capability, although it can integrate with Splunk Enterprise Security. Splunk's current product structure also includes SOAR within Enterprise Security Premier.
Which Splunk Product Should You Choose?
Choose Splunk Enterprise Security Essentials if you need:
- Security information and event management
- Centralized log and telemetry analysis
- Threat detection
- Risk-based alerting
- Security investigations
- Compliance and security monitoring
Choose Splunk SOAR if you need:
- Automated response tasks
- Coordination across multiple security tools
- Incident-response playbooks
- Less manual analyst work
- Standardized response procedures
Choose Splunk Enterprise Security Premier if you want one security operations platform that combines SIEM, SOAR, UEBA and threat detection and response workflows.
Bottom Line
The answer depends on the product. Splunk Enterprise Security Essentials is the SIEM, Splunk SOAR is the SOAR product, and Enterprise Security Premier combines both capabilities. Splunk Enterprise and Splunk Cloud Platform provide the underlying data and analytics foundation, but they are not automatically complete SIEM or SOAR products.