# Tines vs Splunk SOAR: which do AI models recommend for SOAR, October 2026

IT AI Recommendation Index, October 2026 Edition, SOAR platforms. Nine of fourteen models named Tines first on the direct prompt; zero named Splunk SOAR. Page: https://it-ai-index.com/security/soar-platforms/tines-vs-splunk-soar/

| | First-choice share | Rank | Negative rate | Labels | Models naming it |
|---|---|---|---|---|---|
| Tines | 41% | #1 of 11 | 2% | 48 | 13 of 14 |
| Splunk SOAR | 2% | #8 of 11 | 44% | 61 | 14 of 14 |

## The direct prompt, model by model

- GPT-5.4 mini: tines first (first choices: Tines, Torq) (alternatives: Cortex XSOAR, Microsoft Sentinel, Splunk SOAR)
- Gemini 3.5 Flash: tines first (first choices: Tines) (alternatives: BlinkOps, Radiant Security, Swimlane Turbine, Torq)
- DeepSeek V4 Flash: tines first (first choices: Tines) (alternatives: Microsoft Sentinel, Rapid7 InsightConnect, Swimlane Turbine)
- Llama 4 Maverick: tines first (first choices: Tines)
- Qwen 3.7 Flash: tines first (first choices: Tines) (alternatives: Microsoft Sentinel, Swimlane Turbine)
- Kimi K2: tines first (first choices: Tines) (alternatives: Microsoft Sentinel, Rapid7 InsightConnect, Swimlane Turbine, Torq)
- GLM 4.7 FlashX: tines first (first choices: Cortex XSOAR, Tines) (alternatives: Microsoft Sentinel, Splunk SOAR, Swimlane Turbine)
- GPT-6 Luna: tines first (first choices: Tines) (alternatives: Cortex XSOAR, Microsoft Sentinel's built-in automation, Splunk SOAR)
- Muse Glimmer 30B: tines first (first choices: Swimlane Turbine, Tines, Torq) (alternatives: Cortex XSOAR, Microsoft Sentinel, Splunk SOAR)
- Claude Haiku 4.5: neither first, one named (first choices: Swimlane Turbine, Torq) (alternatives: Cortex XSOAR, FortiSOAR, Splunk SOAR, Tines)
- Mistral Small: neither first, one named (first choices: Swimlane Turbine, Torq) (alternatives: Microsoft Sentinel, Splunk SOAR, Tines)
- MiniMax M2.5: neither first, one named (first choices: Swimlane Turbine) (alternatives: FortiSOAR, Microsoft Sentinel, Splunk SOAR, Torq)
- Perplexity Sonar: neither named (first choices: D3 Security Smart SOAR) (alternatives: ManageEngine Log360, ThreatConnect)
- Grok 4.1 Fast: neither named (first choices: Swimlane Turbine) (alternatives: Microsoft Sentinel, Rapid7 InsightConnect)

## What the models said about Tines

- "Tines has a free edition, but it allows only 3 live workflows, so it's better for a proof of concept than a full company-wide deployment." (GPT-6 Luna, budget prompt, soft negative)
- "I recommend starting with Tines if you want rapid implementation and ease of use, or Cortex XSOAR if you need the most comprehensive platform" (GLM 4.7 FlashX, direct prompt, first choice)
- "Best for low-code automation: Tines, for security and operations teams that build orchestration-heavy workflows without heavy scripting." (Muse Glimmer 30B, scale prompt, first choice)
- "Tines | Analyst-friendly, low-code, strong mid-market fit, median $52K/yr | Teams wanting speed and minimal engineering overhead" (DeepSeek V4 Flash, scale prompt, first choice)

## What the models said about Splunk SOAR

- "avoid: ... Splunk SOAR: Only makes financial and operational sense if your company is already heavily standardized on Splunk" (Gemini 3.5 Flash, direct prompt, hard negative)
- "Integration with Splunk Enterprise Security (ES) is described as "hacky" and problematic" (Mistral Small, negative prompt, hard negative)
- "these are generally not recommended for mid-sized organizations" (Gemini 3.5 Flash, paraphrase prompt, hard negative)
- "Cortex XSOAR and Splunk SOAR are repeatedly positioned as top-tier enterprise platforms" (Perplexity Sonar, comparative prompt, first choice)
- "I'd usually recommend Splunk SOAR if you already have a heterogeneous security stack" (GPT-5.4 mini, paraphrase prompt, first choice)
- "Splunk SOAR leads in the number of connectors and actions" (Mistral Small, comparative prompt, first choice)

Share is the count of first choices across the direct, paraphrase, budget and scale prompts over all fourteen models, for a mid-market B2B company; rank is within the category. Comparisons are drawn for the top eight products in each category. Published under CC BY 4.0; the output is the models' output, and nothing here is a recommendation by the index.
