Try our new research platform with insights from 80,000+ expert users

Elastic Observability vs Splunk ITSI (IT Service Intelligence) comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jul 24, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.5
Elastic Observability enhances cost-effectiveness by reducing incidents, automating fixes, and visualizing cloud operations, saving time and resources.
Sentiment score
7.0
Splunk ITSI quickly delivers ROI by enhancing visibility, reducing costs, and improving performance with centralized data and efficient analytics.
Elastic Observability has saved us time as it's much easier to find relevant pieces across the system in one screen compared to our own software, and it has saved resources too since the same resources can use less time.
Technology Consultant at Hybrid software
 

Customer Service

Sentiment score
7.6
Elastic Observability customers appreciate their helpful support, quick responses, and valuable documentation, despite some challenges in complex issue resolution.
Sentiment score
6.4
Splunk ITSI support is generally good, but experiences vary by company size and issue, with occasional delays reported.
Elastic support really struggles in complex situations to resolve issues.
Assistant Vice President at QualityKiosk Technologies Pvt. Ltd.
Their excellent documentation typically helps me solve any issues I encounter.
Technology Consultant at Hybrid software
The technical support is excellent, and I would rate it at ten.
Senior consultant at a tech services company with 51-200 employees
We typically have weekly calls with the technical staff, and whenever we encounter issues, they usually reply with solutions within one or two days.
Senior Consultant at a consultancy with 10,001+ employees
 

Scalability Issues

Sentiment score
7.2
Elastic Observability is praised for scalability and ease of deployment, despite potential complexities and internal process limitations.
Sentiment score
7.6
Splunk ITSI is scalable for various deployments, though costly; supports large datasets with predictive analysis for resource optimization.
I rate the scalability of Elastic Observability as a ten, as we have never seen issues even with a lot of data coming in from more customers, provided we have the appropriate configuration.
Technology Consultant at Hybrid software
Elastic Observability seems to have a good scale-out capability.
Chief Cloud Architect at a tech services company with 11-50 employees
Elastic Observability is easy in deployment in general for small scale, but when you deploy it at a really large scale, the complexity comes with the customizations.
Assistant Vice President at QualityKiosk Technologies Pvt. Ltd.
Splunk is highly scalable, with the ability to expand efficiently.
Senior consultant at a tech services company with 51-200 employees
When we create Glass Tables containing many searches, the Glass Tables sometimes fail due to memory constraints, and we receive error pages.
Senior Consultant at a consultancy with 10,001+ employees
 

Stability Issues

Sentiment score
8.2
Elastic Observability is stable and reliable, with high user ratings, efficiently handling large data volumes with proper configuration.
Sentiment score
7.7
Splunk ITSI is stable and reliable, managing large datasets efficiently, with minor challenges mainly during updates and configuration.
There are some bugs that come with each release, but they are keen always to build major versions and minor versions on time, including the CVE vulnerabilities to fix it.
Assistant Vice President at QualityKiosk Technologies Pvt. Ltd.
It is very stable, and I would rate it ten out of ten based on my interaction with it.
Product Owner at Swisscom
I would rate the stability of Elastic Observability as a ten, as we don't experience any issues.
Technology Consultant at Hybrid software
The setup, however, must be done correctly as incorrect deployment can lead to issues.
Senior consultant at a tech services company with 51-200 employees
Splunk ITSI (IT Service Intelligence) fails if you do not have good hardware requirements.
Senior Consultant at a consultancy with 10,001+ employees
 

Room For Improvement

Elastic Observability needs automation, AI, and customization improvements, addressing complex deployment, market presence, metrics, licensing, and usability issues.
Splunk ITSI needs better integration, user interface, predictive analytics, machine learning, real-time alerting, automated response, and user support.
For instance, if you have many error logs and want to create a rule with a custom query, such as triggering an alert for five errors in the last hour, all you need to do is open the AI bot, type this question, and it generates an Elastic query for you to use in your alert rules.
Senior Consultant at Skillfield
It lacked some capabilities when handling on-prem devices, like network observability, package flow analysis, and device performance data on the infrastructure side.
Senior Technical Sales at a tech vendor with 1,001-5,000 employees
Some areas such as AI Ops still require data scientists to understand machine learning and AI, and it doesn't have a quick win with no-brainer use cases.
Assistant Vice President at QualityKiosk Technologies Pvt. Ltd.
I would appreciate additional features in the next release of Splunk ITSI (IT Service Intelligence) such as cloud infrastructure monitoring including CICDs, Kubernetes, and similar technologies.
Director at Techpace
Splunk ITSI could benefit from including more features that other solutions support, such as vulnerability management modules.
Senior consultant at a tech services company with 51-200 employees
I believe the installation process should be more uniform, meaning it could be deployed across all components to avoid post-installation issues.
Senior Consultant at a consultancy with 10,001+ employees
 

Setup Cost

Elastic Observability provides competitive pricing, benefiting large enterprises with comprehensive licensing, but may be costly for smaller users.
Splunk ITSI is a costly but comprehensive tool, valued for its observability despite complex licensing and high pricing.
The license is reasonably priced, however, the VMs where we host the solution are extremely expensive, making the overall cost in the public cloud high.
Product Owner at Swisscom
Elastic Observability is cost-efficient and provides all features in the enterprise license without asset-based licensing.
Chief Cloud Architect at a tech services company with 11-50 employees
Observability is actually cheaper compared to logs because you're not indexing huge blobs of text and trying to parse those.
Senior Consultant at Skillfield
Splunk ITSI tends to be more expensive compared to some open-source solutions.
Senior consultant at a tech services company with 51-200 employees
I believe the pricing is based on daily volume ingestion.
Senior Consultant at a consultancy with 10,001+ employees
 

Valuable Features

Elastic Observability excels with flexible integration, powerful search, scalability, real-time insights, affordability, and robust support, enhancing efficiency.
Splunk IT Service Intelligence enhances incident management with agile data handling, advanced analytics, and effective troubleshooting features for quick issue resolution.
The most valuable feature is the integrated platform that allows customers to start from observability and expand into other areas like security, EDR solutions, etc.
Chief Cloud Architect at a tech services company with 11-50 employees
the most valued feature of Elastic is its log analytics capabilities.
Senior Technical Sales at a tech vendor with 1,001-5,000 employees
All the features that we use, such as monitoring, dashboarding, reporting, the possibility of alerting, and the way we index the data, are important.
Product Owner at Swisscom
The predictive analysis can give you proactive information about potential bottlenecks that can occur on applications, desk, storage, SQL servers, databases, or other systems.
Director at Techpace
One valuable feature is the scheduled maintenance window provided by Splunk ITSI (IT Service Intelligence) because Splunk does not offer this scheduling maintenance feature in the core product, but Splunk ITSI (IT Service Intelligence) helps us with these maintenance reports.
Senior Consultant at a consultancy with 10,001+ employees
Splunk ITSI allows for integration with threat intelligence, enabling my organization to correlate more than two events for generating alerts.
Senior consultant at a tech services company with 51-200 employees
 

Categories and Ranking

Elastic Observability
Ranking in Application Performance Monitoring (APM) and Observability
6th
Average Rating
8.0
Reviews Sentiment
6.8
Number of Reviews
29
Ranking in other categories
IT Infrastructure Monitoring (9th), Log Management (14th), Container Monitoring (4th), Cloud Monitoring Software (7th)
Splunk ITSI (IT Service Int...
Ranking in Application Performance Monitoring (APM) and Observability
12th
Average Rating
8.2
Reviews Sentiment
6.9
Number of Reviews
52
Ranking in other categories
IT Alerting and Incident Management (3rd)
 

Mindshare comparison

As of January 2026, in the Application Performance Monitoring (APM) and Observability category, the mindshare of Elastic Observability is 2.6%, down from 6.2% compared to the previous year. The mindshare of Splunk ITSI (IT Service Intelligence) is 0.7%, down from 0.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Performance Monitoring (APM) and Observability Market Share Distribution
ProductMarket Share (%)
Elastic Observability2.6%
Splunk ITSI (IT Service Intelligence)0.7%
Other96.7%
Application Performance Monitoring (APM) and Observability
 

Featured Reviews

Mohammed-Abdelalim - PeerSpot reviewer
Assistant Vice President at QualityKiosk Technologies Pvt. Ltd.
Has provided powerful customization for unique monitoring needs but needs more out-of-the-box capabilities
In my opinion, the best features of Elastic Observability are their flexibility to integrate with other existing systems and the ability to build a unified monitoring tool that can integrate with existing ones and end-to-end user journeys which require a lot of customizations. The greatest feature in Elastic is the ability to customize. This is similar to my comments about customizable dashboards in Elastic because it's visible to the analyst. However, it's very great. Customizing these dashboards can meet the customer's specific use cases and specific stories that they have in their environment, their special environment that doesn't look like other environments. The dashboarding in Elastic is highly customizable to the level of logos. If the customer wants his company logo in the dashboard, it can be done.
DS
Senior Consultant at a consultancy with 10,001+ employees
Service health has been monitored and visual insights support proactive telecom operations
The installation process is the first aspect I dislike about Splunk ITSI (IT Service Intelligence). If you do not configure it correctly, you will encounter issues in the search head. Because we use a distributed environment where each component has its own specific roles, installation is critical and requires careful attention. Splunk ITSI (IT Service Intelligence) is built with many applications. It is a compressed file, and when you extract the Splunk ITSI (IT Service Intelligence) app, you receive approximately 19 apps. Some applications, add-ons, and packages must be installed on specific components. If you do not configure an application correctly, it will not work. Sometimes we encounter issues during installation because of this complexity. I believe the installation process should be more uniform, meaning it could be deployed across all components to avoid post-installation issues. Sometimes after installation, you receive errors, and users cannot access Splunk ITSI (IT Service Intelligence). We have experienced this type of issue due to installation errors. I believe there is currently room for improvement regarding scalability. When we create Glass Tables containing many searches, the Glass Tables sometimes fail due to memory constraints, and we receive error pages. Splunk ITSI (IT Service Intelligence) should have a lightweight version to address these concerns. I would rate current scalability as medium.
report
Use our free recommendation engine to learn which Application Performance Monitoring (APM) and Observability solutions are best for your needs.
881,346 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
16%
Computer Software Company
14%
Manufacturing Company
8%
Government
6%
Financial Services Firm
18%
Manufacturing Company
10%
Computer Software Company
7%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise4
Large Enterprise16
By reviewers
Company SizeCount
Small Business11
Midsize Enterprise9
Large Enterprise33
 

Questions from the Community

What do you like most about Elastic Observability?
Elastic Observability significantly improves incident response time by providing quick access to logs and data across various sources. For instance, searching for specific keywords in logs spanning...
What is your experience regarding pricing and costs for Elastic Observability?
The problem is their licensing model, which is a bit confusing. Many customers struggle to understand their total cost of ownership because Elastic licensing is not dependent on easy, quantifiable ...
What needs improvement with Elastic Observability?
After careful consideration about areas for improvement in Elastic Observability, aspects such as pricing, customization, implementation, and scalability could be improved. As a user of the system,...
What is your experience regarding pricing and costs for Splunk ITSI (IT Service Intelligence)?
Pricing can vary significantly based on the selected modules and deployment choices. Splunk ITSI tends to be more expensive compared to some open-source solutions.
What needs improvement with Splunk ITSI (IT Service Intelligence)?
Splunk ITSI (IT Service Intelligence) can be improved in terms of the service management function, which is the only drawback, and there are some limitations in terms of event correlation, specific...
 

Overview

 

Sample Customers

PSCU, Entel, VITAS, Mimecast, Barrett Steel, Butterfield Bank
TransUnion, Cox Automotive, Carnival Cruises, Leidos, Econocom, National Ignition Factory, Entrust Datacard, Molina Healthcare, United States Census Bureau
Find out what your peers are saying about Elastic Observability vs. Splunk ITSI (IT Service Intelligence) and other solutions. Updated: December 2025.
881,346 professionals have used our research since 2012.