iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Splunk announced a definitive agreement to acquire Phantom Cyber Corporation on February 27, 2018, for approximately $350 million, subject to adjustment and payable in cash and stock. Phantom supplied security orchestration, automation and response (SOAR) technology, giving Splunk a way to automate incident response alongside its security and IT analytics.
What Splunk announced
Splunk’s February 27, 2018 announcement described an agreement to acquire Phantom Cyber, the company behind an enterprise security-orchestration platform. The stated consideration was approximately $350 million, subject to adjustment, with payment in a combination of cash and stock. The announcement framed the transaction as a way to extend Splunk’s security platform beyond detecting and analyzing events into coordinating and automating response actions.
Splunk expected the deal to add Phantom’s employees and technology to its security business. Splunk president and CEO Doug Merritt said: “Phantom’s employees and technology significantly expand and strengthen Splunk’s vision for the security nerve center and for business revolution through IT.”
Why Splunk wanted Phantom
Adding SOAR to analytics
Phantom’s product was enterprise SOAR software. SOAR systems connect security tools, apply repeatable playbooks and automate response steps that might otherwise require analysts to move between multiple consoles. Splunk already provided large-scale data collection and analytics; Phantom added an orchestration layer for acting on findings.
#1 Best Overall
Reducing manual incident-response work
Phantom co-founder and CEO Oliver Friedrichs described the company’s goal this way: “Sourabh Satish and I founded Phantom to give SOC analysts a powerful advantage over their adversaries, a way to automatically and quickly resolve threats.” In practical terms, the acquisition was intended to help security operations centers investigate and respond faster by automating routine actions while leaving analysts in control of significant decisions.
Extending the security and IT portfolio
Splunk’s acquisition history described Phantom as an addition to its security-orchestration and automation capabilities for security and IT customers. The strategic fit was therefore broader than a standalone endpoint or threat-intelligence purchase: Phantom’s workflows could coordinate actions across the tools already used by an organization.
Rank #2
Why the deal is described as both $350 million and $303.8 million
The two commonly cited figures use different measurement bases and should not be treated as a correction of one another.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problems| Figure | What it measures | Source and timing |
|---|---|---|
| Approximately $350 million | Announced transaction consideration, subject to adjustment, payable in cash and stock | Splunk announcement, February 27, 2018 |
| $303.8 million | Fair value of consideration transferred recorded for accounting purposes | Splunk FY2021 annual report |
| $291.5 million | Cash component included in the reported fair value of consideration transferred | Splunk FY2021 annual report |
| $12.3 million | Fair value of replacement equity awards attributed to pre-acquisition service | Splunk FY2021 annual report |
The annual-report figure is a post-close accounting measurement. It reflects the fair value Splunk assigned to the consideration transferred, including the cash and replacement-award components reported in the filing. It is not a later announcement that the original $350 million headline was wrong.
When did Splunk acquire Phantom?
Splunk’s FY2021 annual report records the acquisition of 100% of Phantom Cyber on April 6, 2018. Splunk’s dedicated acquisition-history page gives April 9, 2018. Because the audited annual-report acquisition note is the more precise accounting source for the transaction date, April 6 is the date to use when a single date is required; the three-day discrepancy should be acknowledged when comparing Splunk pages.
Splunk’s first-quarter fiscal 2019 results also confirmed that the transaction had closed and connected the purchase to the company’s security-platform strategy.
What happened to Phantom’s product?
Splunk later changed the product name from Splunk Phantom to Splunk SOAR and announced a cloud-deployment option. Those announcements establish the historical rebranding and the existence of that dated cloud announcement; they do not by themselves establish Splunk SOAR’s packaging, licensing, availability or deployment choices in September 2026. Organizations evaluating the product today should check Splunk’s current official product documentation and commercial terms.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
What the acquisition did—and did not—buy
- It did buy: Phantom’s SOAR technology, personnel and workflow-oriented incident-response capabilities.
- It was intended to add: automated coordination between Splunk’s analytics and the security tools used by customers.
- It did not mean: that Splunk was acquiring a consumer cybersecurity gadget or a physical product; the transaction centered on enterprise software.
- It does not establish: current product pricing, editions, service limits or supported deployment models nearly a decade later.
Bottom line on the 2018 transaction
Splunk’s Phantom purchase was a strategic SOAR acquisition announced at approximately $350 million in cash and stock, subject to adjustment. Splunk’s later financial reporting recorded $303.8 million as the fair value of consideration transferred—$291.5 million in cash and $12.3 million in replacement equity awards tied to pre-acquisition service. The different totals reflect different reporting bases. The business rationale was consistent: combine Splunk’s security analytics with Phantom’s orchestration and automation to help security and IT teams respond to incidents more efficiently.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

