18
Ditched SIEM for SOAR last quarter and it saved our team 20 hours a week
We were drowning in alerts from Splunk at my last job in Denver. Triage alone took 3 people most of the day. We switched to a basic SOAR setup with automated playbooks for common stuff like phishing and brute force attempts. Now our SOC analyst handles what used to take a whole shift in like 2 hours. It's not perfect but the difference in response time is night and day. Has anyone else made that switch and seen similar results?
2 comments
Log in to join the discussion
Log In2 Comments
umasullivan1mo ago
SOAR just adds more complexity to an already messy stack.
8
mason20926d ago
Honestly, I saw a talk recently where a guy showed how his team spent months building playbooks in their SOAR tool, and then a single API change from a vendor broke half of them. That's exactly the kind of complexity creep that makes you wonder if the automation is even worth the upkeep. Ngl, it felt like they were just wrapping their old problems in a new shiny interface.
5