

Splunk ITSI and Splunk Enterprise Platform both operate within the domain of IT service management and data analysis, competing on their ability to enhance IT operations. Splunk ITSI appears to have an upper hand in offering service-specific insights and advanced observability features, while Splunk Enterprise Platform stands out in handling vast amounts of data and scalability.
Features: Splunk ITSI provides comprehensive visibility into applications, real-time anomaly detection, and enhanced event correlation. Its service analyzers and glass tables facilitate root-cause analysis. Splunk Enterprise Platform excels in its ability to handle large data volumes from diverse sources, maintaining robust search and alert capabilities. It is particularly noted for its flexibility and customization opportunities.
Room for Improvement: Splunk ITSI needs more enriched templates, refined predictive analytics, and a simpler setup with pre-configured dashboards. Enhanced integration solutions would also benefit users. Splunk Enterprise Platform could improve its pricing model and offer more out-of-the-box dashboards to better justify its cost. Both products could enhance their documentation and customer support for a better user experience.
Ease of Deployment and Customer Service: Splunk ITSI offers versatile deployment options for both on-premises and cloud environments, providing greater flexibility. Splunk Enterprise primarily focuses on on-premises deployment. Customer service for both is generally responsive, although ITSI sometimes encounters slower response times and less knowledgeable support due to outsourcing. Improvements in support consistency and ticket response times are needed for both.
Pricing and ROI: Splunk ITSI, with its premium capabilities, is viewed as expensive, but it yields a good ROI by improving service efficiency and incident resolution. Splunk Enterprise Platform also has a high cost, viewed as a barrier for smaller businesses, but its scalability can lead to significant ROI with appropriate use-case alignment. Both solutions could enhance their perceived value by diversifying pricing models and reducing initial setup costs.
Splunk Enterprise Platform saves approximately 20 to 30 percent of my time without having to perform different actions separately.
I have seen a return on investment from using Splunk Enterprise Platform, illustrated by tracking how the daily data volume has been indexed, the estimated cost, the monthly actual report, and the annual report.
We estimate a 30 to 35 percent saving on resource costs and around 25 to 30 percent savings on inventory expenses, all credited to utilizing Splunk ITSI (IT Service Intelligence) effectively.
Risks can mean that if one failure happens, it can result in risks in hundreds of thousands of USD.
It has saved me a lot of money and a lot of time.
We contacted support and they were able to provide us with the solution which is currently working fine.
It is crucial for anyone looking to deploy Splunk Enterprise Platform to first certify for their courses, such as the Splunk Administrator and the Power User Administrator certifications, which address all troubleshooting queries.
When we encounter issues, we utilize the Splunk community, which I believe showcases a big advantage of Splunk due to its strong community support.
The technical support is excellent, and I would rate it at ten.
We typically have weekly calls with the technical staff, and whenever we encounter issues, they usually reply with solutions within one or two days.
I would rate Splunk ITSI (IT Service Intelligence) support at nine or 9.5 because it is a highly effective and handy tool.
Splunk allows for scalability, as you can start with an all-in-one instance and, as your deployment grows, split it into distributed deployment, such as separating the search head and indexers.
It is highly stable and scalable for us.
Some products can automatically scale, but Splunk requires manual configuration changes to achieve scale, which is slightly outdated compared to modern technologies.
Splunk is highly scalable, with the ability to expand efficiently.
When we create Glass Tables containing many searches, the Glass Tables sometimes fail due to memory constraints, and we receive error pages.
Splunk ITSI (IT Service Intelligence) scalability allows us to predict analytics such as service degradation and perform root cause analysis through metrics, logs, and traces.
Our L1 and L2 teams get real-time alerts and query the SPL effectively without delays that other SIEM solutions may impose.
It is highly stable and scalable for us.
It requires managing configuration files and processing operations manually, limiting its auto-scaling capabilities.
The setup, however, must be done correctly as incorrect deployment can lead to issues.
Splunk ITSI (IT Service Intelligence) fails if you do not have good hardware requirements.
I would rate the stability of Splunk ITSI (IT Service Intelligence) as a perfect ten; it is an extremely stable tool.
The deep learning capabilities need enhancing, especially on Splunk Cloud, where customers find it challenging to use deep learning tools without setting up backend computing resources.
I could also build some pre-indexed summaries so that Splunk Enterprise Platform can search much faster than raw logs.
From an architectural standpoint, data onboarding, normalization, performance, and scalability improvements would be beneficial, particularly in optimizing search speed and query execution to handle larger searches efficiently.
I would appreciate additional features in the next release of Splunk ITSI (IT Service Intelligence) such as cloud infrastructure monitoring including CICDs, Kubernetes, and similar technologies.
On-cloud upgrades are easy, but on-premises upgrades are very painful.
If Splunk ITSI (IT Service Intelligence) could handle real-time call-outs automatically—not just incident creation—this would reduce our dependency on PagerDuty and consolidate processes within Splunk ITSI (IT Service Intelligence).
The pricing model is based on ingesting data sizes, not user count, and includes a free tier for up to 500 MB of daily data.
We ingest terabytes of data, so I can say Splunk Enterprise Platform is somewhat costly.
Splunk Enterprise Platform is expensive.
Splunk ITSI tends to be more expensive compared to some open-source solutions.
I believe the pricing is based on daily volume ingestion.
The pricing reflects usage levels, and compared to others in the market, Splunk ITSI (IT Service Intelligence) provides a reasonable solution.
Splunk Enterprise Platform also has its own Phantom as a SOAR, which is much more refined and gives more accurate results than any other AI integrated SIM tool.
The anomaly detection is very good for live production data. Whenever an anomaly comes in an application, it automatically resolves and just gives the notification.
Splunk Enterprise Platform will create an incident and detect this as a credential compromise because we have a successful login from another location.
The predictive analysis can give you proactive information about potential bottlenecks that can occur on applications, desk, storage, SQL servers, databases, or other systems.
One valuable feature is the scheduled maintenance window provided by Splunk ITSI (IT Service Intelligence) because Splunk does not offer this scheduling maintenance feature in the core product, but Splunk ITSI (IT Service Intelligence) helps us with these maintenance reports.
The most beneficial aspect for me is that it is AI-enabled, providing us with very good analytics.
| Product | Mindshare (%) |
|---|---|
| Splunk ITSI (IT Service Intelligence) | 1.8% |
| Splunk Enterprise Platform | 2.6% |
| Other | 95.6% |

| Company Size | Count |
|---|---|
| Small Business | 27 |
| Midsize Enterprise | 4 |
| Large Enterprise | 27 |
| Company Size | Count |
|---|---|
| Small Business | 17 |
| Midsize Enterprise | 10 |
| Large Enterprise | 43 |
Splunk Enterprise Platform provides high flexibility and integration, featuring strong analytics, data ingestion, and real-time monitoring, catering to diverse industry needs and enhancing threat detection and data analysis.
Splunk Enterprise Platform is renowned for its powerful capabilities in log management, threat detection, and data visualization. It supports infrastructure monitoring and anomaly detection, crucial for Security Incident and Event Management operations. With its scalable architecture, users can efficiently manage data ingestion and create personalized dashboards, utilizing Splunk Processing Language for comprehensive querying and system performance assessment. This platform offers enhanced threat detection through its robust anomaly detection features and real-time monitoring capabilities, with machine learning enabling predictive analytics.
What features make Splunk Enterprise Platform stand out?In industries like finance, healthcare, and technology, Splunk Enterprise Platform is implemented to monitor infrastructure, manage logs, and enhance security protocols. Companies utilize its predictive analytics for strategic planning and operational efficiency, focusing on integration with AWS, EDR, and firewalls for comprehensive data visualization and threat management.
Splunk ITSI offers intelligent alerting, predictive analysis, customizable dashboards, and improves visibility and monitoring through Service Analyzer and Glass Tables. Event correlation enhances incident management, reducing alert fatigue, and improves mean time to resolution.
Splunk ITSI enables businesses to proactively monitor their IT environments by offering functionalities that reduce noise and provide enhanced visibility through sophisticated dashboards. Service Analyzer and Glass Tables facilitate the monitoring of KPIs, allowing for the prompt identification of potential issues. The platform's event correlation capabilities streamline incident management. Its scalability efficiently supports large data volumes, integrating diverse data resources while incorporating AI for predictive insights. Future improvements are sought in integration, documentation, and user-friendly interfaces, with an emphasis on simplifying configurations in expansive deployments.
What are the Key Features of Splunk ITSI?Industries leverage Splunk ITSI to monitor infrastructure and applications effectively, employing its Service Analyzer and KPI models. Especially in sectors requiring stringent incident management and predictive analytics, integrations like ServiceNow enable visual health assessments and automated anomaly detection, positioning ITSI as a manager of managers by enhancing IT operations with comprehensive reporting and alert correlations.
We monitor all IT Alerting and Incident Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.