AI Buyer Insights:

● Citigroup, a VestmarkONE customer evaluated BlackRock Aladdin Wealth

● Swedbank, a Temenos T24 customer evaluated Oracle Flexcube

● Wayfair, a Korber HighJump WMS customer just evaluated Manhattan WMS

● Michelin, an e2open customer evaluated Oracle Transportation Management

● Cantor Fitzgerald, a Kyriba Treasury customer evaluated GTreasury

● Moog, an UKG AutoTime customer evaluated Workday Time and Attendance

● Westpac NZ, an Infosys Finacle customer evaluated nCino Bank OS

● Citigroup, a VestmarkONE customer evaluated BlackRock Aladdin Wealth

● Swedbank, a Temenos T24 customer evaluated Oracle Flexcube

● Wayfair, a Korber HighJump WMS customer just evaluated Manhattan WMS

● Michelin, an e2open customer evaluated Oracle Transportation Management

● Cantor Fitzgerald, a Kyriba Treasury customer evaluated GTreasury

● Moog, an UKG AutoTime customer evaluated Workday Time and Attendance

● Westpac NZ, an Infosys Finacle customer evaluated nCino Bank OS

List of Splunk Phantom Customers

loading spinner icon

Apply Filters For Customers

Logo Customer Industry Empl. Revenue Country Vendor Application Category When SI Insight
Alaska Airlines Transportation 35951 $14.2B United States Splunk Splunk Phantom Security Orchestration, Automation, and Response (SOAR) 2017 n/a
In 2017, Alaska Airlines implemented Splunk Phantom as part of a program to operationalize automated incident response within the Security Orchestration, Automation, and Response (SOAR) category. The implementation was led from ITS Performance Operations by a Solution Architect and Developer Lead and aligned with teams supporting Aircraft Maintenance and Engineering and a newly developed IT Asset Management system. Splunk Phantom was configured to deliver core SOAR capabilities, including playbook driven automation, orchestration of incident workflows, automated alert triage, and case management for security events. The deployment emphasized runbook authoring and automation connectors to accelerate repetitive response tasks and to feed incident context into IT operations workflows. The deployment was integrated into a CLIP closed loop integration with other security tooling explicitly including Kenna and AIOps monitoring, supporting both cloud hosted applications and on prem implementations. The SOAR implementation operated alongside Cherwell Service Management and the IT Asset Management lifecycle components in the broader IT ecosystem to ensure security signals could be correlated with asset and documentation data. Operational governance was structured under the ITS Performance Operations practice, with a lead team of three onsite application developers and five offshore support developers, and ongoing stewardship by a practice lead. Rollout focused on embedding automated security orchestration into existing operational processes for incident handling, with runbook ownership and developer led change control managed by the performance operations team.
CareFirst BlueCross BlueShield Insurance 9000 $12.4B United States Splunk Splunk Phantom Security Orchestration, Automation, and Response (SOAR) 2022 n/a
In 2022, CareFirst BlueCross BlueShield implemented Splunk Phantom as part of its Security Orchestration, Automation, and Response (SOAR) toolset inside a 24/7/365 CSIRT SOC environment. Splunk Phantom was operated alongside Splunk Enterprise, Splunk ES, and Splunk ITSI to centralize automated incident handling and orchestration across cloud and on premises telemetry sources. Implementation work focused on developing and configuring playbooks, automated triage routines, and incident rule orchestration. The team executed a Splunk Phantom proof of value testing out of the box use cases and then built custom playbooks to automate indicator extraction, enrichment, and containment tasks, leveraging existing Jenkins CI pipelines for Azure cloud deployment automation and a Python utility developed to evaluate FireEye extracted URLs and attachments. Phantom and its playbooks were integrated operationally with an ecosystem of security controls and telemetry, including Microsoft Sentinel, Azure Security Center Defender for Cloud, endpoint protection platforms such as CrowdStrike and Defender, SIEMs including Sumo Logic and Splunk Enterprise, vulnerability scanners like Rapid7 Nexpose, DLP and email security platforms such as Proofpoint and Mimecast, Tanium for endpoint evidence collection, and ticketing workflows into ServiceNow. The implementation spanned Azure and AWS operational coverage, and worked in concert with SASE deployments for secure access across distributed offices and remote users. Governance and process work included configuring incident rules, data connectors, workbooks and playbooks in Microsoft Sentinel, creating level 1 playbook procedures for SOC analysts, and applying NIST incident categorization and MITRE ATT&CK and Cyber Kill Chain frameworks to classify incidents and prioritize response. Identity protection alerts were routed into detection workflows and automated playbooks were used to suppress noisy alerts and support CSPM and secure score efforts, aligning orchestration, runbook automation, and SOC workflow restructuring with existing security operation practices.
Dell Manufacturing 108000 $95.6B United States Splunk Splunk Phantom Security Orchestration, Automation, and Response (SOAR) 2019 n/a
In 2019, Dell implemented Splunk Phantom as a Security Orchestration, Automation, and Response (SOAR) application to support its internal SOC and automation initiatives in the United States. The deployment focused on delivering playbook-driven SOAR capabilities, positioning Splunk Phantom to orchestrate and automate incident response workflows within Dell’s cybersecurity operations. Splunk Phantom was configured to execute SOAR playbooks and automate incident triage and response sequencing, leveraging the application’s orchestration and automation capabilities to standardize repetitive SOC tasks. Functional emphasis included playbook authoring and orchestration, automated enrichment and response action sequencing, and mapping security events to predefined response workflows consistent with Security Orchestration, Automation, and Response (SOAR) operational patterns. Operational coverage targeted Dell’s internal Security Operations Center in the United States, aligning SOC procedures and incident response runbooks with automated playbook governance. Governance and process changes emphasized playbook lifecycle management, approvals for automated actions, and centralized orchestration to institutionalize consistent incident handling across the security organization.
ExxonMobil Oil, Gas and Chemicals 57900 $323.9B United States Splunk Splunk Phantom Security Orchestration, Automation, and Response (SOAR) 2021 n/a
In 2021, ExxonMobil implemented Splunk Phantom as part of its Security Orchestration, Automation, and Response (SOAR) tooling to operationalize incident response and SOC playbooks. Splunk Phantom was configured to orchestrate automated workflows and to centralize actionable threat intelligence for SOC operations, threat hunting, and incident response functions. The deployment focused on developing detection rules, automated playbooks, and response playbooks within Splunk Phantom, while aligning detection content with the MITRE ATT&CK Framework. Engineers created custom dashboards and detection rules in Splunk, and authored automation using Python, PowerShell, and Bash to parse logs, manage endpoint actions, and trigger Phantom playbooks for high-priority incidents. Integrations were explicitly implemented between Splunk Phantom and enterprise CTI sources such as Anomali ThreatStream and Recorded Future, and with the Splunk SIEM to source alerts and telemetry. The SOAR implementation also interfaced with SentinelOne for endpoint context, iBoss Proxy for web access monitoring, Nexpose and InsightVM for vulnerability data from Azure and AWS environments, Palo Alto Prisma Cloud for cloud posture signals, Nozomi Networks for ICS and OT device telemetry, and investigation tools including Maltego to enrich incidents. Governance and operationalization included codifying Priority Intelligence Requirements to drive automated playbooks, institutionalizing threat hunting workflows in the SOC, and integrating periodic risk assessments aligned to ISO 27001. Splunk Phantom was used to streamline SOC operations and reduce response times for high-priority incidents, while enabling incident response teams to operationalize CTI and repeatable playbooks across IT, cloud, and ICS/OT environments.
Mitsui Bussan Secure Directions Professional Services 264 $30M Japan Splunk Splunk Phantom Security Orchestration, Automation, and Response (SOAR) 2022 n/a
In 2022, Mitsui Bussan Secure Directions implemented Splunk Phantom as its Security Orchestration, Automation, and Response (SOAR) platform to automate security operations and threat hunting workflows for its clients in Japan. The deployment prioritized operationalizing repeatable playbooks to accelerate incident response and standardize SOC processes across managed security engagements. Splunk Phantom was configured to run playbook-driven automation for email filtering triage, threat hunting orchestration, case management, and investigation workflows, reflecting module usage cited in Splunk SOAR customer references. The implementation leveraged the platform’s orchestration engine and automated tasking to reduce manual analyst steps and codify detection to response sequences. Operational coverage focused on the organization’s security operations center and threat hunting teams, extending capabilities into client-facing managed services across Japan. The rollout centralized investigation context within Splunk Phantom’s case management fabric while automating routine SOC tasks and analyst handoffs. Governance changes included formalizing response playbooks and operational procedures to ensure consistent execution of automated workflows. Reported outcomes from Splunk SOAR customer materials include faster response times, greater agility in investigations, improved threat hunting speed, and increased SOC efficiency, and Splunk Phantom is the product now marketed as Splunk SOAR.
Banking and Financial Services 56366 $23.1B United States Splunk Splunk Phantom Security Orchestration, Automation, and Response (SOAR) 2022 n/a
Professional Services 1000 $120M United Kingdom Splunk Splunk Phantom Security Orchestration, Automation, and Response (SOAR) 2021 n/a
Showing 1 to 7 of 7 entries

Buyer Intent: Companies Evaluating Splunk Phantom

ARTW Buyer Intent uncovers actionable customer signals, identifying software buyers actively evaluating Splunk Phantom. Gain ongoing access to real-time prospects and uncover hidden opportunities.

Discover Software Buyers actively Evaluating Enterprise Applications

Logo Company Industry Employees Revenue Country Evaluated
No data found
FAQ - APPS RUN THE WORLD Splunk Phantom Coverage

Splunk Phantom is a Security Orchestration, Automation, and Response (SOAR) solution from Splunk.

Companies worldwide use Splunk Phantom, from small firms to large enterprises across 21+ industries.

Organizations such as ExxonMobil, Dell, PNC BANK, Alaska Airlines and CareFirst BlueCross BlueShield are recorded users of Splunk Phantom for Security Orchestration, Automation, and Response (SOAR).

Companies using Splunk Phantom are most concentrated in Oil, Gas and Chemicals, Manufacturing and Banking and Financial Services, with adoption spanning over 21 industries.

Companies using Splunk Phantom are most concentrated in United States, with adoption tracked across 195 countries worldwide. This global distribution highlights the popularity of Splunk Phantom across Americas, EMEA, and APAC.

Companies using Splunk Phantom range from small businesses with 0-100 employees - 0%, to mid-sized firms with 101-1,000 employees - 28.57%, large organizations with 1,001-10,000 employees - 14.29%, and global enterprises with 10,000+ employees - 57.14%.

Customers of Splunk Phantom include firms across all revenue levels — from $0-100M, to $101M-$1B, $1B-$10B, and $10B+ global corporations.

Contact APPS RUN THE WORLD to access the full verified Splunk Phantom customer database with detailed Firmographics such as industry, geography, revenue, and employee breakdowns as well as key decision makers in charge of Security Orchestration, Automation, and Response (SOAR).