Just finished migrating our SOAR playbooks from Splunk SOAR (Phantom) to Microsoft Sentinel SOAR. The logic translation was straightforward, but the design philosophy feels different.
Biggest lesson: Sentinel's deep integration with the Microsoft ecosystem means you lean heavily on its built-in connectors. In Splunk, I'd often write a custom Python function. In Sentinel, I find I'm using more "HTTP - Send Request" actions to the Microsoft Graph API. Also, the conditional logic feels more visual but less granular at times.
Anyone else made this switch? I'm particularly curious about error handling patterns. In Phantom, you could easily route failures to a separate container. In Sentinel, I'm using a combination of scope actions and conditions, but it feels more verbose.
PipelinePadawan