Sign in
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Reviews from AWS customer

3 AWS reviews

External reviews

50 reviews
from and

External reviews are not included in the AWS star rating for the product.


3-star reviews ( Show all reviews )

    reviewer1248516

Has reduced alert triage time but requires skilled developers for maintenance

  • September 23, 2025
  • Review provided by PeerSpot

What is our primary use case?

We are using Swimlane for automation purposes and security orchestration.

We are using Swimlane's Playbook Automation. One of the major playbooks that we use in Swimlane is for phishing email automation, so whenever there is a phishing email delivered to a user inbox, Swimlane will automatically sandbox that.

We integrate Swimlane with third-party tools such as CrowdStrike, VirusTotal, URL Proofpoint, and all other different tools we have, so that we get various enrichment of any alerts to make sure that the analyst doesn't spend much time doing manual tasks and gets all the information from the tools in the Swimlane console itself.

We use the case management feature in Swimlane as well. This case management feature is helpful because, in security, we don't want our security incidents to be visible to end users. For example, if I am using ServiceNow, I have to impose many restrictions on the backend table to ensure that whatever incidents are created and written into that table are not available to any end users or other IT team members. We use case management for that purpose so that our security alerts are isolated and only the security team has visibility on them. Whenever we need any remediation, we integrate it with ServiceNow, so if I need to raise a remediation ticket for re-imaging the system, we can create a ticket in ServiceNow from the Swimlane console or from the case management itself with all the proper information.

What is most valuable?

We do utilize the analytics aspect in Swimlane, and we use their Hero AI module as well.

We also use customizable dashboards in Swimlane because many clients, including CISOs, whom we manage need an executive-level view of what is happening over Swimlane. We create dashboards for them that provide proper information, such as how many alerts were created, what was the mean time to triage, and mean time to respond; we cover all these as KPI metrics in the executive dashboard.

The biggest advantage of Swimlane for us is that it saves time, which in turn helps us in cost-saving.

What needs improvement?

One of the disadvantages of Swimlane is that to manage the platform, we need hardcore developers. We have recently seen new products such as Tines and Blink Ops coming into the market, where a person with a good knowledge of APIs and JSON format can manage the platform and create playbooks. Even a security analyst can create some playbooks on those platforms. However, on Swimlane, it's difficult for security analysts since they must mandatorily know Python to create the playbooks.

In terms of pricing, Swimlane is on the slightly expensive side.

Swimlane is scalable in general, but there are some limitations. It involves maintenance overhead because you need a complete engineer who knows the product in and out to scale it for the on-prem environment, while in a SaaS model, it works without many problems.

Installation can be quite complex, especially when we have to use Kubernetes, and if we need to create load balancing. In those situations, it requires a good engineer to deploy the platform.

In relation to bugs, sometimes the enrichment playbook we have does not enrich the alert, resulting in missing details, so in those scenarios, the automation team has to manually run the playbook again.

Improvements could be made in terms of quality, particularly.

For how long have I used the solution?

I have been working with Swimlane for almost seven years.

What do I think about the scalability of the solution?

Swimlane is scalable in general, but there are some limitations. It involves maintenance overhead because you need a complete engineer who knows the product in and out to scale it for the on-prem environment, while in a SaaS model, it works without many problems.

How are customer service and support?

I would rate technical support from Swimlane a seven on a scale where ten is the best.

How would you rate customer service and support?

Neutral

How was the initial setup?

Installation can be quite complex, especially when we have to use Kubernetes, and if we need to create load balancing. In those situations, it requires a good engineer to deploy the platform.

What was our ROI?

We see these savings approximately close to 30-35%.

What's my experience with pricing, setup cost, and licensing?

In terms of pricing, Swimlane is on the slightly expensive side.

Which other solutions did I evaluate?

We have recently seen new products such as Tines and Blink Ops coming into the market, where a person with a good knowledge of APIs and JSON format can manage the platform and create playbooks. Even a security analyst can create some playbooks on those platforms. However, on Swimlane, it's difficult for security analysts since they must mandatorily know Python to create the playbooks.

What other advice do I have?

I would rate Swimlane a seven out of ten as a product.


    Wasiim G.

Powerful SOAR Platform with Strong Reporting but Complex Setup

  • September 15, 2025
  • Review provided by G2

What do you like best about the product?
Swimlane SOAR provides robust reporting and case management features that make incident tracking and auditing much more streamlined. The dashboards and metrics offer valuable visibility into SOC efficiency, helping to measure response times, case resolution and analyst workload. For our POC in the context of building a SOC, these capabilities have been particularly insightful.
What do you dislike about the product?
The initial deployment and playbook design are resource-intensive and demand skilled engineering expertise. Connectors and APIs require frequent updates.Additionally, poorly tuned or over-automated playbooks risk escalating false positives into automated actions. These challenges became evident during our POC phase.
What problems is the product solving and how is that benefiting you?
Swimlane is helping us automate and orchestrate repetitive SOC tasks such as alert triage, enrichment and case tracking. Instead of hiring a team of analysts and having them spending excessive time on manual data gathering or repetitive response steps, playbooks streamline these processes and ensure consistency. The centralized case management also improves visibility across incidents, making reporting much more efficient.

The main benefit seen during the POC has been a reduction in analyst workload and faster incident handling, while also providing metrics and dashboards to track overall SOC performance. For us, in the context of building a SOC, Swimlane is providing both operational efficiency and governance-level visibility via Reporting.


    Sairam S

Leverage security automation with easy setup and integration while refining version control for optimal performance

  • March 18, 2025
  • Review provided by PeerSpot

What is our primary use case?

We have been using Swimlane for security automation within our company. All the ingestions, automations, and everything within our department goes through Swimlane.

What is most valuable?

Swimlane is easy to start with, as it requires minimal prior knowledge to get started. It is flexible, providing room for users to set up specific incident response flows. Additionally, its integration capabilities allow connections to various platforms, enhancing its usability. Swimlane has helped reduce analyst time, contributing to operational efficiency.

What needs improvement?

There is a need for enhanced version control in Swimlane. Currently, our version does not support it, making it tough to move changes between environments during significant updates. Furthermore, despite being advertised as a no-code tool, it remains code-reliant, demanding users to build solutions through coding.

For how long have I used the solution?

We have been using Swimlane for the past three years.

What do I think about the stability of the solution?

I would rate the stability of Swimlane as a seven. We encountered issues requiring multiple restarts, which suggests that stability could be optimized further.

What do I think about the scalability of the solution?

Swimlane is very scalable, and I would rate it a nine. We did not encounter issues even when managing thousands of alerts, as scalability is only limited by our instance's server capacity.

How are customer service and support?

Swimlane's technical support is very good. They are attentive, responsive, and work to resolve issues efficiently.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We previously used Splunk SOAR, but switched to Swimlane due to cost considerations. Swimlane was more cost-effective.

How was the initial setup?

The initial setup of Swimlane is easy to learn but requires customers to design their solutions. Deployment of Swimlane took us three to four months, which involved migrating existing playbooks.

What about the implementation team?

Around ten people from Swimlane and five from our team were involved in the implementation.

What was our ROI?


What's my experience with pricing, setup cost, and licensing?


Which other solutions did I evaluate?

I wasn't part of the initial evaluation process. Still, we had some evaluations of other SOAR solutions within our company after migrating to Swimlane.

What other advice do I have?

I would recommend Swimlane for those proficient with code and prepared for the maintenance efforts required. On a scale of one to ten, I rate Swimlane a seven.


    Dihia

The product provides a single portal to manage logs, but it is unstable, and the plug-ins have bugs

  • July 12, 2023
  • Review from a verified AWS customer

What is our primary use case?

I use the solution for receiving alerts and case creation. It is used as a ticketing system.

What is most valuable?

It provides us with a single portal for our logs from different solutions.

What needs improvement?

We faced a lot of issues with the product’s stability. Sometimes we find bugs in the plug-ins. We experience some latency when we have a huge amount of data.

For how long have I used the solution?

I have been using the solution for six to eight months.

What do I think about the stability of the solution?

I rate the tool’s stability a five or six out of ten.

What do I think about the scalability of the solution?

I rate the tool’s scalability a seven out of ten. When we add some users, the platform becomes unstable. In my organization, 20 people use the solution.

How are customer service and support?

The response time depends on the support person. The resolution of our issues depends upon the problem and the support person.

How would you rate customer service and support?

Positive

How was the initial setup?

The product is deployed on the cloud.

What other advice do I have?

Overall, I rate the product a seven out of ten.


    Computer Software

Swimlane Experiences

  • October 12, 2018
  • Review provided by G2

What do you like best about the product?
Very Intuitive interface, Provides centeralized information, reports to SecOps teams, specializing the security incidents, it’s cross platform, it automates realtime security incidents reporting and triage.
What do you dislike about the product?
The information on thedashboards is sometimes overwhelming.
What problems is the product solving and how is that benefiting you?
The worlflow tools are very in-depth and helps in customize the incident reporting for different types of applications.


    Computer Software

Great

  • June 14, 2018
  • Review provided by G2

What do you like best about the product?
Automated instant and immediate responses
What do you dislike about the product?
Some alerts are still unresolved, unseen, or unknown
What problems is the product solving and how is that benefiting you?
Stronger threat responses and realizations - security analyses have become so much more sufficient with this company's services.


showing 1 - 6