Hey everyone, I've been diving into SOC platform options for a financial services context and could use some community wisdom. My team is evaluating Splunk Enterprise Security, but we have a hard requirement for SOAR (Security Orchestration, Automation, and Response) integration that feels seamless. The finance angle means we're extra sensitive about audit trails, data integrity, and compliance reporting.
I've been testing ES and its integration with Splunk SOAR (formerly Phantom). While the search and correlation is powerful, I'm trying to wrap my head around the actual workflow. For instance, if we get an alert on a suspicious transaction pattern, I want to automate the enrichment and containment steps. In a proof-of-concept, I tried setting up a simple playbook that queries an internal SQL DB for user details and then updates a ticket. The code snippet for the custom function got a bit messy:
```sql
-- Example: Joining alert IPs with our internal transaction logs
SELECT a.user_id, t.last_transaction_amt, t.account_balance
FROM alerts a
JOIN transaction_db t ON a.user_id = t.user_id
WHERE a.alert_time > DATEADD(hour, -1, GETDATE());
```
My question is: for those in finance using Splunk ES with SOAR, how robust is this integration in practice? Are you able to build automated workflows without constant custom scripting? Also, how does the cost scale when you layer SOAR on top of ES? We're comparing this to other platforms like IBM QRadar with Resilient or Exabeam, but Splunk's data handling seems superior.
Any real-world pitfalls or things you wish you knew before committing? Especially around maintaining compliance (like SOX) logs within the automated playbooks. Thanks in advance for any insights