No more typing reviews! Try our Samantha, our new voice AI agent.

Splunk Enterprise Platform vs Splunk ITSI (IT Service Intelligence) comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 2, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
4.4
Organizations benefit from Splunk by reducing costs and downtime, enhancing productivity, and simplifying data management for effective operations.
Sentiment score
5.8
Splunk ITSI offers quick ROI with reduced resource costs and downtime, improving workflow efficiency and data visibility.
Key impact areas are generally time saved in investigations, higher analyst productivity, lowered costs of security incidents due to faster detection and response, and reduced manual reporting effort.
Managed Security Services Associate at Accenture
Instead of spending time on troubleshooting and security visibility efforts requiring many employees, Splunk Enterprise Platform has helped us reduce those needs.
Information Technology Manager at Everseen
Splunk Enterprise Platform helped reduce the time required to investigate incidents by centralizing logs and providing powerful search capabilities.
Fine at PCS Solutions
We estimate a 30 to 35 percent saving on resource costs and around 25 to 30 percent savings on inventory expenses, all credited to utilizing Splunk ITSI (IT Service Intelligence) effectively.
SIEM Splunk Engineer/Architect at Cepheid
Risks can mean that if one failure happens, it can result in risks in hundreds of thousands of USD.
Technology And Digitization Lead at JLL
It has saved me a lot of money and a lot of time.
IT Associate at Accenture
 

Customer Service

Sentiment score
6.9
Splunk Enterprise Platform is lauded for strong customer service, though some users desire faster initial responses and direct assistance.
Sentiment score
6.8
Splunk ITSI's customer service is skilled and responsive, but users desire quicker handling of high-priority cases.
We contacted support and they were able to provide us with the solution which is currently working fine.
Splunk Engineer at a recruiting/HR firm with 11-50 employees
It is crucial for anyone looking to deploy Splunk Enterprise Platform to first certify for their courses, such as the Splunk Administrator and the Power User Administrator certifications, which address all troubleshooting queries.
SOC A2 at Innodata-ISOGEN
When we encounter issues, we utilize the Splunk community, which I believe showcases a big advantage of Splunk due to its strong community support.
Security Consultant at ITSEC Asia
The technical support is excellent, and I would rate it at ten.
Senior consultant at a tech services company with 51-200 employees
We typically have weekly calls with the technical staff, and whenever we encounter issues, they usually reply with solutions within one or two days.
Senior Consultant at a consultancy with 10,001+ employees
I would rate Splunk ITSI (IT Service Intelligence) support at nine or 9.5 because it is a highly effective and handy tool.
Splunk Developer ( Training & Enablement) at DXC Technology
 

Scalability Issues

Sentiment score
7.7
Splunk Enterprise Platform is praised for its scalable architecture, seamless integration, and reliable performance, despite some cost concerns.
Sentiment score
7.7
Splunk ITSI efficiently scales in diverse environments, though infrastructure and licensing costs may affect its scalability performance.
Splunk allows for scalability, as you can start with an all-in-one instance and, as your deployment grows, split it into distributed deployment, such as separating the search head and indexers.
Security Consultant at ITSEC Asia
It is highly stable and scalable for us.
Dev Ops And Observability Admin at a tech services company with 11-50 employees
In a day we get millions of hits for the APIs.
Software Developer at a financial services firm with 10,001+ employees
Splunk is highly scalable, with the ability to expand efficiently.
Senior consultant at a tech services company with 51-200 employees
When we create Glass Tables containing many searches, the Glass Tables sometimes fail due to memory constraints, and we receive error pages.
Senior Consultant at a consultancy with 10,001+ employees
Splunk ITSI (IT Service Intelligence) scalability allows us to predict analytics such as service degradation and perform root cause analysis through metrics, logs, and traces.
Sr. Technical Manager at Vodafone
 

Stability Issues

Sentiment score
8.3
Splunk Enterprise Platform is praised for stability and reliability, efficiently managing high data volumes and minor issues in complex setups.
Sentiment score
7.7
Splunk ITSI is stable and reliable, handling large datasets effectively with minimal downtime and generally high user ratings.
Our L1 and L2 teams get real-time alerts and query the SPL effectively without delays that other SIEM solutions may impose.
Global Head Of Security Architecture Digital & Technology at Aramex
It is highly stable and scalable for us.
Dev Ops And Observability Admin at a tech services company with 11-50 employees
It requires managing configuration files and processing operations manually, limiting its auto-scaling capabilities.
Consultant at Artifield
The setup, however, must be done correctly as incorrect deployment can lead to issues.
Senior consultant at a tech services company with 51-200 employees
Splunk ITSI (IT Service Intelligence) fails if you do not have good hardware requirements.
Senior Consultant at a consultancy with 10,001+ employees
I would rate the stability of Splunk ITSI (IT Service Intelligence) as a perfect ten; it is an extremely stable tool.
Splunk Developer ( Training & Enablement) at DXC Technology
 

Room For Improvement

Splunk Enterprise faces criticism for high costs, complexity, and suggests improvements in AI, integration, pricing, and support.
Splunk ITSI faces complexity and cost issues, needing better documentation, integrations, monitoring, predictive analytics, and improved usability features.
The deep learning capabilities need enhancing, especially on Splunk Cloud, where customers find it challenging to use deep learning tools without setting up backend computing resources.
Consultant at Artifield
I could also build some pre-indexed summaries so that Splunk Enterprise Platform can search much faster than raw logs.
security engineer at a tech vendor with 501-1,000 employees
From an architectural standpoint, data onboarding, normalization, performance, and scalability improvements would be beneficial, particularly in optimizing search speed and query execution to handle larger searches efficiently.
Global Head Of Security Architecture Digital & Technology at Aramex
I would appreciate additional features in the next release of Splunk ITSI (IT Service Intelligence) such as cloud infrastructure monitoring including CICDs, Kubernetes, and similar technologies.
Director at Techpace
On-cloud upgrades are easy, but on-premises upgrades are very painful.
Technology And Digitization Lead at JLL
If Splunk ITSI (IT Service Intelligence) could handle real-time call-outs automatically—not just incident creation—this would reduce our dependency on PagerDuty and consolidate processes within Splunk ITSI (IT Service Intelligence).
Monitoring Dev Ops Engineer at Centrica
 

Setup Cost

Splunk Enterprise is costly due to data volumes but offers significant value with advanced features for large enterprises.
Splunk ITSI is considered pricey, linked to data volume, but valued for its features and support; affordability varies.
The pricing model is based on ingesting data sizes, not user count, and includes a free tier for up to 500 MB of daily data.
Consultant at Artifield
We ingest terabytes of data, so I can say Splunk Enterprise Platform is somewhat costly.
Dev Ops And Observability Admin at a tech services company with 11-50 employees
The platform's ability to consolidate siloed tools into a single pane of glass provides immense value justifying the premium cost if the architecture is tightly managed.
Managed Security Services Associate at Accenture
Splunk ITSI tends to be more expensive compared to some open-source solutions.
Senior consultant at a tech services company with 51-200 employees
I believe the pricing is based on daily volume ingestion.
Senior Consultant at a consultancy with 10,001+ employees
The pricing reflects usage levels, and compared to others in the market, Splunk ITSI (IT Service Intelligence) provides a reasonable solution.
Works at a tech services company with 1,001-5,000 employees
 

Valuable Features

Splunk Enterprise offers robust risk-based alerting, real-time monitoring, and integration with AI-enhanced features for efficient incident management.
Splunk ITSI is valued for intelligent alerting, predictive analytics, and integration capabilities, enhancing visibility and reducing incident noise.
Splunk Enterprise Platform also has its own Phantom as a SOAR, which is much more refined and gives more accurate results than any other AI integrated SIM tool.
SOC A2 at Innodata-ISOGEN
The anomaly detection is very good for live production data. Whenever an anomaly comes in an application, it automatically resolves and just gives the notification.
Technical Lead at a financial services firm with 10,001+ employees
Splunk Enterprise Platform will create an incident and detect this as a credential compromise because we have a successful login from another location.
Cybersecurity Team Leader at EMAK For Computer Manufacturing (ECM)
The predictive analysis can give you proactive information about potential bottlenecks that can occur on applications, desk, storage, SQL servers, databases, or other systems.
Director at Techpace
One valuable feature is the scheduled maintenance window provided by Splunk ITSI (IT Service Intelligence) because Splunk does not offer this scheduling maintenance feature in the core product, but Splunk ITSI (IT Service Intelligence) helps us with these maintenance reports.
Senior Consultant at a consultancy with 10,001+ employees
The most beneficial aspect for me is that it is AI-enabled, providing us with very good analytics.
Technology And Digitization Lead at JLL
 

Categories and Ranking

Splunk Enterprise Platform
Ranking in IT Alerting and Incident Management
2nd
Average Rating
8.6
Reviews Sentiment
6.4
Number of Reviews
61
Ranking in other categories
Data Visualization (2nd)
Splunk ITSI (IT Service Int...
Ranking in IT Alerting and Incident Management
4th
Average Rating
8.4
Reviews Sentiment
6.6
Number of Reviews
64
Ranking in other categories
Application Performance Monitoring (APM) and Observability (10th)
 

Mindshare comparison

As of August 2026, in the IT Alerting and Incident Management category, the mindshare of Splunk Enterprise Platform is 2.7%, up from 1.6% compared to the previous year. The mindshare of Splunk ITSI (IT Service Intelligence) is 2.0%, down from 2.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
IT Alerting and Incident Management Mindshare Distribution
ProductMindshare (%)
Splunk Enterprise Platform2.7%
Splunk ITSI (IT Service Intelligence)2.0%
Other95.3%
IT Alerting and Incident Management
 

Featured Reviews

Koyena Paul - PeerSpot reviewer
Managed Security Services Associate at Accenture
Centralized security monitoring has transformed our threat detection and incident response
While Splunk Enterprise Platform is widely regarded as a powerful SIEM and observability platform, users across enterprises commonly report recurring challenges including licensing and data ingestion costs. Splunk Enterprise Platform's licensing is often based on the volume of data ingested, and as our organization grows, costs can increase significantly, and our teams may need to carefully decide which logs to ingest, which can limit visibility. A suggested improvement would be more flexible licensing options, better built-in recommendations for optimizing data ingestion, and smarter data compression or tiered pricing. There is also a steep learning curve where beginners can find SPL difficult. A suggested improvement would be more AI-assisted SPL generation, interactive tutorials, and guided dashboard creation with additional pre-built templates for common SOC use cases. These are the main areas for improvement that I can see: licensing flexibility, reducing the learning curve for new users, simplifying development, improving performance for very large datasets, and providing more AI-assisted features to reduce manual effort. In terms of adding more improvements, there are frequently discussed areas including easier third-party integrations. While Splunk Enterprise Platform supports many integrations, onboarding new security tools sometimes requires custom configurations or add-ons. A suggested improvement would be more plug-and-play integrations, faster support for new vendors, and then simplified administration. Administrators often manage indexes, forwarders, user roles, and cluster health, so a suggested improvement would be easier administration dashboards and automated health checks. These are suggestions that acknowledge Splunk Enterprise Platform's strengths while highlighting areas where many enterprise users see opportunities for further improvement. The primary areas for improvement that I see are licensing flexibility, simplifying administration, expanding plug-and-play integrations, and adding more AI-driven assistance for searches and investigations. These improvements would significantly simplify our tasks and help us solve more incidents in a lesser amount of time, making it flexible even for beginners.
DS
Senior Consultant at a consultancy with 10,001+ employees
Service health has been monitored and visual insights support proactive telecom operations
The installation process is the first aspect I dislike about Splunk ITSI (IT Service Intelligence). If you do not configure it correctly, you will encounter issues in the search head. Because we use a distributed environment where each component has its own specific roles, installation is critical and requires careful attention. Splunk ITSI (IT Service Intelligence) is built with many applications. It is a compressed file, and when you extract the Splunk ITSI (IT Service Intelligence) app, you receive approximately 19 apps. Some applications, add-ons, and packages must be installed on specific components. If you do not configure an application correctly, it will not work. Sometimes we encounter issues during installation because of this complexity. I believe the installation process should be more uniform, meaning it could be deployed across all components to avoid post-installation issues. Sometimes after installation, you receive errors, and users cannot access Splunk ITSI (IT Service Intelligence). We have experienced this type of issue due to installation errors. I believe there is currently room for improvement regarding scalability. When we create Glass Tables containing many searches, the Glass Tables sometimes fail due to memory constraints, and we receive error pages. Splunk ITSI (IT Service Intelligence) should have a lightweight version to address these concerns. I would rate current scalability as medium.
report
Use our free recommendation engine to learn which IT Alerting and Incident Management solutions are best for your needs.
908,834 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Construction Company
10%
Outsourcing Company
8%
Comms Service Provider
7%
Financial Services Firm
16%
Manufacturing Company
10%
Outsourcing Company
9%
Construction Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business34
Midsize Enterprise8
Large Enterprise43
By reviewers
Company SizeCount
Small Business17
Midsize Enterprise8
Large Enterprise46
 

Questions from the Community

What needs improvement with Splunk Enterprise Platform?
With respect to the use cases, we were able to create many use cases as well as fine-tune them, so thirty percent of the alerts were fine-tuned, and we have improved our detection logic and also th...
What is your primary use case for Splunk Enterprise Platform?
Splunk Enterprise Platform serves as our SIEM tool where we receive alerts and we primarily depend on it. As a centralized logging and monitoring system, we use Splunk based upon different data typ...
What advice do you have for others considering Splunk Enterprise Platform?
With respect to the use cases, we were able to create many use cases as well as fine-tune them, so thirty percent of the alerts were fine-tuned, and we have improved our detection logic and also th...
What is your experience regarding pricing and costs for Splunk ITSI (IT Service Intelligence)?
From a pricing perspective, it is not that bad because we get it from a distributor and do not purchase it directly from Splunk. We get it from a distributor who gives the pricing to a partner and ...
What needs improvement with Splunk ITSI (IT Service Intelligence)?
In terms of improvements for Splunk ITSI (IT Service Intelligence), I would suggest adding more out-of-the-box plugins and adapters, especially as there is a high demand for observability and dashb...
What is your primary use case for Splunk ITSI (IT Service Intelligence)?
I use Splunk ITSI (IT Service Intelligence) as a manager of the managers, a tool sitting on top of all the other observability tools. It gets the alerts feed from all the sources such as Splunk Ent...
 

Overview

 

Sample Customers

Information Not Available
TransUnion, Cox Automotive, Carnival Cruises, Leidos, Econocom, National Ignition Factory, Entrust Datacard, Molina Healthcare, United States Census Bureau
Find out what your peers are saying about Splunk Enterprise Platform vs. Splunk ITSI (IT Service Intelligence) and other solutions. Updated: June 2026.
908,834 professionals have used our research since 2012.