I use Splunk IT Service Intelligence (ITSI) for SIEM.
Security Architect at a tech vendor with 10,001+ employees
Feature-rich, good reporting, and easy to install
Pros and Cons
- "In my opinion, Splunk IT Service Intelligence (ITSI) is better than QRadar. With the help of Splunk, we can get results."
- "The dashboard queries should be improved. More queries should be suggested in order to produce better dashboards."
What is our primary use case?
What is most valuable?
Splunk IT Service Intelligence (ITSI) is a very good tool.
Splunk IT Service Intelligence (ITSI) is superior to QRadar in my opinion. We can get results with the help of Splunk.
Splunk outperforms IBM QRadar in terms of functionality.
What needs improvement?
The dashboard queries should be improved. More queries should be suggested in order to produce better dashboards.
For how long have I used the solution?
I have been working with Splunk IT Service Intelligence (ITSI) for one year.
Buyer's Guide
Splunk ITSI (IT Service Intelligence)
March 2025

Learn what your peers think about Splunk ITSI (IT Service Intelligence). Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
845,406 professionals have used our research since 2012.
What do I think about the stability of the solution?
Splunk IT Service Intelligence (ITSI) is a stable solution.
How are customer service and support?
I have never contacted technical support.
Which solution did I use previously and why did I switch?
I have worked with IBM QRadar, Splunk, and Sentinel.
People say that IBM QRadar is easier to implement as well as to query things.
How was the initial setup?
The initial setup is straightforward. It is very easy to implement.
What's my experience with pricing, setup cost, and licensing?
Splunk pricing is high.
Which other solutions did I evaluate?
I was exploring LogRhythm, and multiple SIEM solutions, because we wanted to purchase a SIEM tool.
What other advice do I have?
Definitely, I would recommend this solution to others who are interested in using it. Splunk should be used because it provides a better solution in terms of SIEM as well as reporting. If you want to use that tool for reporting purposes, it is a fantastic tool. You only need to create a query to get started.
I would rate Splunk IT Service Intelligence (ITSI) an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Splunk Consultant at Yssy
Stable with good customization potential and easily scalable
Pros and Cons
- "The flexibility to develop and consolidate many solutions into one platform is great."
- "Some of our customers occasionally require the development of the connectors when there are no native connectors so that we can develop in Python or for customer slash comments as well. If they could adjust that, it would be ideal."
What is our primary use case?
We are a solution provider with many technologies. We use Splunk to customize solutions with Splunk. For example, we try to give our customers a great visualization experience. And sometimes we develop on the Splunk platform, like JavaScript, to provide the customers a better visualization. We also implement ITSI. In-house we can implement Enterprise Security.
What is most valuable?
We can customize the visualization. For example, if the customer wants to have a better visualization experience, we can develop it on the front-end of the platform in order to provide a better user experience.
The flexibility to develop and consolidate many solutions into one platform is great. We've portrayed many parts of the solution in order to provide complete solutions. We can develop various parts that customers desire into Splunk platform due to the fact that it is so flexible and does allow for customization and specific tweaks.
What needs improvement?
Some of our customers occasionally require the development of the connectors when there are no native connectors so that we can develop in Python or for customer slash comments as well. If they could adjust that, it would be ideal.
For how long have I used the solution?
We've been using the solution for a while. We implement it for clients.
What do I think about the stability of the solution?
The solution is great in terms of stability. It doesn't have bugs and it's not glitchy. It doesn't crash or freeze. It's rather reliable.
What do I think about the scalability of the solution?
The scalability is great. We can scale horizontally, meaning we can deploy a small solution, and if, according to the needs, it needs to expand, it can horizontally do so.
We implement Splunk to our clients, and they all vary in size. We've implemented it to banks and in places where there are more than 500 users on Splunk. Some of the implementations were sizable.
How was the initial setup?
Typically, implementation is complex initially. Splunk is easy to set up when you are looking at the basics. When you're looking for advanced configurations or advanced development it's never easy but it's possible.
What other advice do I have?
We are a Splunk reseller. We're consultants. We use Splunk to develop a solution for our customers and therefore use multiple deployment models.
Overall, on a scale from one to ten, I would rate this solution at a ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free Splunk ITSI (IT Service Intelligence) Report and get advice and tips from experienced pros
sharing their opinions.
Updated: March 2025
Product Categories
IT Alerting and Incident Management Application Performance Monitoring (APM) and ObservabilityPopular Comparisons
Splunk Cloud Platform
Buyer's Guide
Download our free Splunk ITSI (IT Service Intelligence) Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- How do you decide about the alert severity in your Security Operations Center (SOC)?
- What is an incident response playbook and how is it used in SOAR?
- What is the difference between mitigation and remediation in incident response?
- What tools and solutions do you use for automated incident response in an enterprise in 2022?
- What measures should a business have in place to enable an effective incident response for data breaches?
- Why a Security Operations Center (SOC) is important?
- When evaluating Incident Management Software, what aspect do you think is the most important to look for?
- What are some Incident management best practices to keep in mind?
- GoDaddy has been hacked again. What can be done better?
- Why is IT Alerting and Incident Management important for companies?