SOC tools: what actually matters

Summary
Looking for expert guidance?
Curious about this topic? Got a question or a project in mind?

In most post-mortems, the alert was there. It had fired, it had a timestamp, it was sitting in a queue. Nobody read it.

That is the real issue with SOC tools. Not feature checklists, but whether a signal reaches the right person with enough context to act on. And one confusion keeps surfacing: plenty of products sold as security operations center tools are nothing of the sort. They watch availability, not intent. That distinction changes everything once a budget is on the table.

Key takeaways

  • A SOC tool hunts for malicious intent. An IT monitoring tool measures whether a system is healthy. Both matter, neither replaces the other.
  • Three SIEMs dominate the accessible market: Splunk, QRadar and Wazuh, each on a completely different commercial model.
  • False positives are still the number one obstacle detection teams report.
  • Past the 200-day mark, the average cost of a breach climbs by close to 30%.
  • Centreon, Zabbix and NinjaOne do not belong in a detection architecture, but they feed a SOC with context it would otherwise lack.
  • Shared visualisation, video walls and hypervision, is the last thing funded and the first thing missed in a crisis.

The paradox: more tools, less visibility

There is a stubborn belief that SOC maturity can be counted in deployed components. The data says the opposite.

State of the SOC: Unify Now or Pay Later, produced by Omdia for Microsoft, found that security teams juggle double-digit numbers of consoles and that close to half of all alerts are never investigated (source: Omdia / Microsoft, February 2026). The SANS Institute lands in the same place: 73% of organisations name false positives as their biggest detection obstacle (source: SANS 2025 Detection and Response Survey).

So the bottleneck is not technical. It is cognitive. Every extra console means another context to rebuild, another query language, another naming convention. Under pressure, that switching cost hurts far more than any missing feature.

The real SOC tools: three SIEMs, three philosophies

A SIEM does not tell anyone whether a system is healthy. It collects logs and surfaces sequences no single tool would ever catch on its own.

Splunk

Splunk grew up as a data analytics platform and became a SIEM through its Enterprise Security layer. Its query language makes it a formidable investigation tool, capable of digging deep into historical data. The catch is well known: pricing has historically tracked ingested volume, so every new log source turns into a budget conversation. The product now sits inside Cisco.

IBM QRadar

QRadar is built around the offense. The engine rolls several correlated events into a single incident, which mechanically cuts the noise reaching the analyst.

One point needs settling before any project starts. Palo Alto Networks closed its acquisition of IBM’s QRadar SaaS assets on 31 August 2024, then announced end of sale from 14 April 2025, with a migration path to Cortex XSIAM. The on-premises version is untouched: IBM still provides support, fixes and connector updates. Anyone weighing up QRadar needs to nail down the deployment model first.

Wazuh

Wazuh came out of the OSSEC ecosystem and pairs SIEM functions with endpoint protection: file integrity monitoring, host-based intrusion detection, compliance dashboards. No licence fee. The cost simply moves to in-house engineering, which makes it a strong starting point for teams with real technical depth and a trap for anyone relying on two generalists.

The SolarWinds case

SolarWinds deserves its own note, because the name covers two very different things. The Observability suite is IT monitoring. Security Event Manager, on the other hand, is a genuine SIEM, shipped as an on-premises virtual appliance and licensed by the number of log-emitting sources rather than by volume. That model is its strongest selling point against platforms that charge by the terabyte.

IT monitoring platforms: useful, but not detection tools

Here is the blind spot. A monitoring platform tracks availability and performance: a service going down, an abnormal load, a process stuck in a restart loop. Those are sometimes the tracks an attacker leaves without meaning to, but none of these products was built to recognise an adversary’s playbook.

Centreon occupies a particular spot in the French market. A domestic vendor, distributed pollers, an open source core extended by commercial editions. Its ability to model business services turns a technical incident into an impact an executive can actually understand. Invaluable in a crisis room, useless for detection.

Zabbix delivers impressive coverage for zero software spend, in exchange for demanding configuration work. WhatsUp Gold is aimed at small network teams: auto-discovery, visual mapping. It answers the “what is plugged in where” question fast, and plenty of organisations struggle to answer that mid-incident.

NinjaOne sits in another category again, endpoint management: inventory, patching, remote control. Its value to a SOC lies in remediation. France’s national cybersecurity agency reports that nearly 29% of vulnerabilities exploited in 2025 were exploited on the day of disclosure or earlier (source: ANSSI, Panorama de la cybermenace 2025). Patch deployment speed has become a security control in its own right.

Summary table

ToolActual categoryRole in relation to the SOC
Splunk ESSIEMDetection and investigation
IBM QRadarSIEMDetection, offense-based correlation
WazuhOpen source SIEM and XDRDetection, compliance
SolarWinds SEMOn-premises SIEMDetection, per-source licensing
CentreonIT monitoringContext source, business services
ZabbixIT monitoringInfrastructure context source
WhatsUp GoldNetwork monitoringMapping, inventory
NinjaOneEndpoint managementRemediation, patching

What a SIEM cannot see

No SIEM stands alone. Three complements come into play, depending on scope.

EDR covers the endpoints, and that is where most alerts start life: endpoint telemetry is the first trigger for investigation according to 85% of analysts surveyed by the SANS Institute (source: SANS 2025 SOC Survey). That dominance also says something about how thin the coverage is everywhere else.

NDR picks up the assets that will never accept an agent. On an industrial site, PLCs, sensors and legacy hardware run into the dozens. Those are exactly the systems Triton went after in 2017, when attackers targeted the safety instrumented systems of a Saudi petrochemical plant. A bug in the malicious code tripped the plant into shutdown, which is how the intrusion came to light at all.

SOAR takes on the repetitive work. IBM reports that organisations making extensive use of AI and automation shorten the breach lifecycle by 80 days and save 1.9 million dollars on average (source: IBM, Cost of a Data Breach Report 2025).

The part almost everyone forgets

An analyst works on their own screens. A team works on a shared view. The moment a CISO, a network lead and an executive have to make a call together, that gap becomes painful.

The video wall sets the hierarchy: perimeter status, live incidents, workload across the team. More importantly, it lets an operator push their screen straight to the shared display. Everyone is suddenly looking at the same thing at the same moment.

Once a SIEM and a monitoring platform coexist, hypervision adds a layer of synthesis on top of the specialist tools. Motilde integrates these platforms without vendor bias, so existing investments stay in play. The benefit is obvious wherever a SOC and a NOC sit side by side: reading both views together often separates an outage from an attack in minutes.

Then there is the human side. The SANS Institute finds that 70% of analysts with five years of experience or less leave their role within three years. Yet spotting an anomaly depends on knowing intimately what normal looks like on this network, in this building. That knowledge walks out the door with the people, and control room ergonomics is one of the few retention levers a security leader can actually pull.

Three recurring mistakes

Buying before knowing what to look for. Ten to fifteen priority detection scenarios are enough to steer the selection. Do it the other way round and the result is a SIEM stuffed with logs and short on detections. The SANS Institute notes that 42% of SOCs dump everything into their SIEM with no analysis plan behind it.

Mistaking monitoring for detection. A flawlessly deployed Centreon or Zabbix will never stand in for a SIEM. It feeds one.

Treating the room as a finishing touch. Control room design belongs in the same conversation as licensing, not in whatever budget survives at the end.

FAQ

What is the difference between an IT monitoring tool and a SIEM?

IT monitoring, whether Centreon, Zabbix or WhatsUp Gold, measures availability and performance. A SIEM, whether Splunk, QRadar or Wazuh, looks for sequences that point to malicious intent. An unexplained load spike interests both teams, but only the SIEM can tie it back to a suspicious login three hours earlier.

Which security operations center tools are essential at the start?

A SIEM to correlate, an EDR for endpoints, and a case management tool so investigations leave a trace. NDR becomes necessary as soon as the perimeter includes agentless assets. SOAR earns its keep once alert volume outgrows what people can process by hand.

Can a SOC run on open source tools?

Technically, yes. Wazuh covers much of the SIEM and endpoint ground, Zabbix handles infrastructure monitoring, and Centreon’s open source core fills the gap on business services. The cost does not vanish, it moves to in-house engineering.

Is QRadar still a sensible choice?

On premises, yes: IBM continues to support and update it. The SaaS version was sold to Palo Alto Networks in 2024 and withdrawn from sale in 2025, with a migration path to Cortex XSIAM. The deployment model has to be decided before anything else.

How can a team tell whether its current tooling works?

Four numbers are enough: time to detect, time to contain, false positive rate, and the share of alerts closed without investigation. That last one is the most honest.

Conclusion

SOC tools are not chosen one at a time. They form a chain, and the first decision is to separate what detects from what merely observes.

What comes next plays out on ground that is still largely open. ANSSI recorded 196 incidents involving data exfiltration in 2025, up from 130 the year before, and flags the arrival of attacks with physical consequences. Operations centres will increasingly need security, network and process data in one place, in front of one team. That is Motilde’s territory, from the technical architecture through to the design of the room itself.

Our offices
France – Paris
Spain – Barcelona
Slovakia – Žilina
Our network
(Outside the EU)
AFRICA
Kenya
Tanzania
Uganda
Nigeria
South Africa
Angola
French-speaking Africa

MIDDLE EAST
Dubai
Abu Dhabi
Saudi Arabia
Join our team

Copyright © 2026. MOTILDE. All rights reserved.