Fortune 500 Retailer Replaces Splunk in Under Three Weeks

Industry: Retail |
Region: Global |
Product: Torq AI SOC Platform |

Case Study Contents

Get a Personalized Demo

See how Torq harnesses AI in your SOC to detect, prioritize, and respond to threats faster.

Request a Demo

Years of Legacy SOAR Logic, Three Weeks to Get Out

When a Fortune 500 retailer approached Torq, the ask was direct: “We don’t want to renew Splunk in three weeks.” Challenge accepted.

After nearly four years on Splunk SOAR, the retailer had accumulated 40 playbooks, layered on top of 1,000+ lines of Python workarounds and hidden code blocks. The system had become fragile and difficult to maintain. Every new use case required custom code. Every troubleshooting required an SME. Renewal was three weeks away. There was no version of this where the team carried the legacy SOAR into another four-year contract.

“Our SOAR had become a backlog with a renewal date. Every playbook was a Python script someone had to babysit, and the team was burning out trying to keep it standing.”

Senior Director of Security Operations, Fortune 500 Retailer


A Two-Phase Migration Inside a Three-Week Window

The Torq AI SOC Platform is built to handle both halves of a SOAR migration: fast, like-for-like replacement of legacy automation, and the strategic upleveling that follows.

Phase 1: Like-for-Like Replacement in Days
Socrates Agentic Builder is built to make SOAR migrations a sprint, not a marathon. Security
teams describe what they need in natural language, and Socrates plans, builds, tests, and deploys the workflows. What used to require dedicated SMEs writing custom Python is now declarative, accessible to the entire SOC team, and built in days instead of months.

Phase 2: Upleveling to a Strategic AI SOC
The Torq AI SOC Platform goes beyond a like-for-like SOAR replacement. Once parity is reached, teams have the architecture to deploy capabilities legacy SOAR couldn’t deliver — agentic investigation, autonomous case resolution, transparent reasoning, native case management, and Torq HyperAgents™ that work end-to-end across the threat lifecycle.

Torq is NOT a SOAR. Torq is an AI SOC platform that uses agentic AI and automation to eliminate the weaknesses of legacy SOAR, rendering it obsolete. Torq expands SOC capacity, accelerates throughput, and delivers on end-to-end SecOps threat lifecycle management at scale.


Agentic Builder Made the Migration a Sprint, Not a Marathon

The Torq AI SOC Platform combines deterministic automation with agentic AI on a single platform, built for end-to-end SecOps from day one. Here’s what carried the retailer from legacy SOAR to a working AI SOC inside three weeks:

Socrates, the AI SOC Orchestrator
With Socrates, the team built workflows using natural language, describing what they needed while Socrates planned, built, tested, and deployed them. Work that used to require dedicated SMEs writing custom Python became declarative and accessible to the whole SOC, and four years of accumulated SOAR logic moved over in days instead of months.

Torq HyperAgents™
The retailer put autonomous AI Agents to work across the full threat lifecycle: triage, investigation, response, and case closure, under explicit guardrails the team set. Once the team hit like-for-like parity, HyperAgents took on work the legacy platform never could, including enriched Google Threat Intelligence, autonomous closure of low-risk verdicts, defanged URL detection, and email metadata parsing.

Native Case Management
The team ran on Torq’s built-in case management, with full chain-of-custody, investigation timelines, and human-and-AI collaboration in a single layer, no separate ticketing tool to maintain.

Complete transparency at every step
Every agentic decision was logged, every action auditable, and every verdict overridable. What the team saw in Torq was the moment-by-moment context of the SOC, at the moment a decision was made, or an action was taken, giving a regulated retailer the evidence trail an audit requires instead of a black box.

End-to-end execution
The retailer ran triage, investigation, response, and case closure on one platform, with consistent context throughout: not a triage tool with a chatbot on top. Because the same grounded context followed each case from first alert to closure, nothing got lost in handoffs, and every downstream action traced back to the reasoning that started it.

“Torq took years of accumulated SOAR logic and migrated it in days — then gave us back the rest of the three weeks to mature what we couldn’t build before.”

Senior Director of Security Operations, Fortune 500 Retailer


A Strategic AI SOC Upgrade, Delivered On Schedule

In three weeks, the retailer stood up a unified AI SOC platform with agentic AI, native case management, and end-to-end execution — built for what the SOC needs to do next.

40 playbooks consolidated to 15 workflows
The team eliminated years of accumulated logic, redundant playbooks, and embedded Python workarounds, including dormant playbooks they couldn’t safely retire on the legacy platform.

84% reduction in Python
Custom scripts were replaced with declarative, natural-language-built workflows accessible to the entire SOC team, not just dedicated SMEs.

Use cases live in days
Phishing triage, threat intel IOC ingestion and blocking, and domain typosquatting monitoring are all running in production — with native integrations across the retailer’s stack, including Elastic Security, CrowdStrike, ServiceNow, Google Threat Intelligence, and Recorded Future.

Advanced HyperAgents in production
After quickly reaching like-for-like parity, the team deployed Torq HyperAgents to deliver capabilities the legacy platform couldn’t: enriched Google Threat Intelligence, autonomous closure of low-risk verdicts, defanged URL detection, email metadata parsing, and comms and coordination.

Torq Case Management for the win
Using Quick Response within Torq’s native Case Management, the team built a new interactive form that human and AI analysts use to send templated notification emails to issue reporters — directly from within a Torq Case, with built-in communications compliance guardrails.

Expansion already in flight
Elastic Security alerts now flow directly into Torq’s native case management, extending the AI SOC Platform across the full 32-person incident response team.

“What started as a SOAR migration turned into a reset of how we think about security operations. We came out of three weeks with a platform we can build on — not one we have to maintain.”

Senior Director of Security Operations, Fortune 500 Retailer

For teams running legacy SOAR, the path out is a strategic moment. This retailer used three weeks of urgency to leave behind four years of accumulated technical debt and adopt an AI SOC Platform built for what the SOC needs to do next: agentic AI across the threat lifecycle, native case management, and an architecture that compounds value over time. The result was a SOC transformation — delivered on a timeline any executive board would be glad to see.