Summarize the Content of the Blog
Splunk ES, ITSI, and SOAR divide the work of running a modern operation. ES detects threats and prioritizes them. ITSI shows the service impact and health context. SOAR automates the response. Each answers a different question, detect, what does it affect, what do we do, and the value compounds when they connect. Buying one without understanding the others is why teams underuse all three.
Key takeaways
These are three products with three jobs, not three versions of the same thing. ES detects, ITSI contextualizes impact, SOAR responds.
The handoffs are where the value is. ES prioritizing what reaches SOAR, and ITSI showing which service an incident threatens, are what turn three tools into one workflow.
You do not need all three to start. You need to understand how the one you have connects to the ones you might add, so you do not build a dead end.
The common failure is running them as silos: ES alerts nobody triages, ITSI dashboards nobody acts on, SOAR playbooks fed by unprioritized noise.
Three products, three questions
The clearest way to understand ES, ITSI, and SOAR is that each answers a different question about the same event.
Something happens in your environment. ES asks: is this a threat, and how urgent? ITSI asks: what business service does this affect, and is that service still healthy? SOAR asks: what do we do about it, and can we do it automatically?
Detect. Contextualize. Respond. Three questions, three products, one event moving between them. Once you see the products this way, the confusion about "which one do I need" usually resolves, because you need whichever answers the question you cannot currently answer.
What each one actually does
Splunk Enterprise Security is the detection and prioritization layer. It is the SIEM. It ingests security data, runs correlation searches, and, through risk-based alerting, accumulates risk on entities so the highest-priority findings surface first. Its output is a prioritized stream of what deserves attention. The depth of what ES does is covered in Splunk Enterprise Security Professional Services, and the prioritization mechanism in Risk-Based Alerting in Splunk ES: A Setup Guide.
Splunk ITSI is the service-impact and health layer. It models business services and computes their health, so when something happens you can see which service it threatens and whether that service is degrading. ITSI answers the question ES cannot: not "is this a threat" but "what does this threat put at risk, in business terms." The full picture is in Splunk ITSI and IT Operations Analytics: A Buyer's Guide.
Splunk SOAR is the response layer. It combines orchestration, playbook automation, and case management to act on what ES surfaces, automating the repetitive response steps and coordinating across your tools. What SOAR is worth automating, and when, is in Splunk SOAR Services: Where Automation Delivers ROI.
Three layers, three jobs. None replaces another.
The handoffs that create the value
Owning three products is not the same as getting value from three products. The value lives in the handoffs between them, and there are two that matter most.
ES to SOAR: prioritization before automation. SOAR is only as good as what feeds it. If ES sends SOAR every alert, SOAR automates noise. If ES uses risk-based alerting to send SOAR only the high-priority findings, SOAR automates signal. This handoff is why the quality of your ES tuning directly determines the value of your SOAR investment. A SOAR programme built on an untuned ES is building on sand.
ITSI to the analyst: impact context during response. When an incident is being worked, the question "how urgent is this really" is often a business question, not a security one. A threat to a test system and the same threat to the payment service demand different urgency. ITSI supplies that context: it shows which service is affected and whether it is degrading, so the response is prioritized by business impact, not just by security severity.
The full end-to-end security operations pipeline, including how observability extends this chain, is covered in From Threat Detection to Automated Response. This blog is about the conceptual division of labor; that one is about building the pipeline.
Where to start if you have one, not three

Most organizations do not deploy all three at once, and should not. The right question is not "which three do I buy" but "which question can I not currently answer, and which product answers it."
If you have ES but drown in alerts: your gap is prioritization and response. Risk-based alerting inside ES comes first, then SOAR to automate the response to what RBA surfaces.
If you have ES and SOAR but cannot prioritize by business impact: your gap is service context. ITSI answers "what does this threaten," which sharpens both triage and response.
If you have ITSI for operations and now need security response: you already understand service health; you are adding detection and response with ES and SOAR.
The principle is to add the product that answers your unanswered question, and to make sure each addition connects to what you already run rather than becoming another silo. That sequencing decision is exactly what a Splunk professional services engagement helps get right.
The silo failure to avoid
The most common way organizations waste these products is by running them as disconnected silos.
ES generates alerts nobody triages, because there is no prioritization and no response layer. ITSI produces dashboards nobody acts on, because they are not connected to a response workflow. SOAR runs playbooks fed by unprioritized noise, because ES was never tuned. Each product works in isolation and none delivers what it could, and the organization concludes that Splunk is expensive and underwhelming, when the real problem is that the handoffs were never built.
Avoiding this is less about the products and more about designing the workflow across them: what ES sends to SOAR, how ITSI context reaches the analyst, and who owns each handoff. That design is where an experienced partner earns their fee, because the products document what each can do, not how to make the three work as one.
bitsIO, a four-time Splunk Partner of the Year and Splunk Elite Partner with 50+ certifications across the team, builds these workflows across ES, ITSI, and SOAR rather than deploying each in isolation, connecting the Splunk Enterprise Security and Splunk SOAR practices into one operating model.















