No more typing reviews! Try our Samantha, our new voice AI agent.

Everbridge IT Alerting vs Splunk Enterprise Security vs Splunk On-Call comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

IT Alerting and Incident Management Mindshare Distribution
ProductMindshare (%)
Everbridge IT Alerting5.8%
PagerDuty Operations Cloud13.1%
Opsgenie9.1%
Other72.0%
IT Alerting and Incident Management
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
Splunk Enterprise Security7.2%
Wazuh5.8%
IBM Security QRadar5.3%
Other81.7%
Security Information and Event Management (SIEM)
IT Alerting and Incident Management Mindshare Distribution
ProductMindshare (%)
Splunk On-Call3.7%
PagerDuty Operations Cloud13.1%
Opsgenie9.1%
Other74.1%
IT Alerting and Incident Management
 

Featured Reviews

reviewer1846215 - PeerSpot reviewer
Crisis Management Director at a healthcare company with 10,001+ employees
Helps in identifying potential impact and allows us to see where our assets are in relation to a risk event
I personally love VCC because I just think there needs to be more data to support it so we can be more proactive and easily assess the impact. So, I appreciate the visual aspect, but it has to have the data to support it. It has proved very useful, particularly because we have a GSOC that's not technically 24/7. We do have an 800 number that people call 24/7. If something happens, they can easily send Everbridge a notification to activate the team off hours. It is useful in that respect too. We use it in conjunction with teams, but off-hours and for additional people outside of the core team, we use Everbridge, which is useful.
Sathis-Kumar - PeerSpot reviewer
Senior Manager at Bank of America
Helps us detect cyber threats quickly and integrate multiple feeds effectively
Overall, the product is good, but when it comes to some infrastructure issues, we have to dig into more logs. There is no straightforward indication of an issue. Health check kind of dashboards are not available. More AI would help us, and more optimization, since security products run more queries. The AI module could suggest solutions, optimizing queries or workload balancing. If the product itself advises on running queries during peak times, it would be similar to what ChatGPT currently offers. We see quite a few issues on stability. Even last week, we faced something, and identifying bottlenecks is not easy. We need more SMEs, and there is no mechanism to tell us about indexer or search head issues. Self-monitoring dashboards could be beneficial. The technical support still requires more improvement. Often, primary support takes a lot of time and forwards most solutions to the engineering side. The primary support team has very limited knowledge to provide.
Venda E - PeerSpot reviewer
Cloud Option Engineer at a tech vendor with 10,001+ employees
Automated alert routing has improved incident response and now enables faster on-call collaboration
Some of the features of Splunk On-Call include automated alert routing and escalation that will ensure the right people get notified immediately. Also, on-call scheduling and rotation management. This feature makes managing shifts and coverage very easy. Another feature is real-time incident collaboration and communication. This will help bring the right team together fast. Another feature is alert de-duplication and suppression. This will reduce the noise, so only meaningful alerts reach the on-call staff. The feature I rely on the most in my daily work is automated alert routing and escalation. It ensures that critical issues go directly to the right engineer without delay, which saves time and prevents the incident from being missed. This has been the biggest contributor to improving our response times. The noise reduction feature is also very helpful. By filtering out non-critical or duplicate alerts, Splunk On-Call keeps our team focused on what actually matters and prevents alert fatigue. Splunk On-Call has helped my organization to improve response times, reduce missed alerts, and coordinate teams more efficiently during incidents. It also reduced alert fatigue and made our on-call process more reliable and predictable. Our average incident response time dropped by around 20% to 25%, mainly because alerts reached the right people faster. We also noticed fewer unnecessary escalations, and missed alerts almost completely stopped after we implemented automated routing and escalation policies.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature is automated escalation, as it eliminates a manual process which is prone to errors."
"With SaaS, we can implement in other regions without having to physically go to there."
"One key aspect of the solution is that it can send information very quickly and is connected to different nodes."
"We have been able to quantify improvements in escalation and time to resolution, as it has decreased timeframes and improved resolution by 35 - 40 percent."
"It's very customizable. For instance, if you're going on vacation this week, you go to your calendar and say, "I'm off this week, make the secondary the primary." And that's done on-the-fly. It's very responsive. It's very user-friendly."
"It has proved very useful, particularly because we have a GSOC that's not technically 24/7, and if something happens, they can easily send Everbridge a notification to activate the team off hours."
"Our performance showed us that, for major incidents, we spent over 40 minutes just making manual call-outs, and that time has been cut down to two or three minutes, so we have had tremendous gains from implementing the tool."
"Powerful conference bridging that rigorously reaches out to stakeholders, which saves time working an issue."
"It actually helps us by not having to develop all the use cases ourselves, providing an integrated product that has everything in one place."
"We are saving a lot of time by being in one place instead of several servers."
"It is user-friendly. It is more effective than other solutions. The support and help for troubleshooting and the documentation from Splunk make it very effective."
"UBA, User Behavior Analytics, is a key feature."
"Splunk Enterprise Security is a very useful application to collect all the logs and also to find out the problems."
"It allows for transparency into IT metrics for insightful business analytics."
"The technical support is among the best in the market."
"We can do things in minutes instead of days."
"Splunk On-Call has helped my organization to improve response times, reduce missed alerts, and coordinate teams more efficiently during incidents."
"The most valuable feature of the solution is helpdesk escalation."
"Its the best solution of its type out there, you should go for it."
"My VP of Operations is ecstatic about the VictorOps product."
"VictorOps has decreased the meantime to acknowledge an incident management process, our developers can be on-call faster when we are using this solution, and we can fix our incidents much quicker."
"It reduces the communication around CI/CD and production errors in about 90% of the cases and made our support tasks much easier."
"I would recommend VictorOps for global distributed support teams."
"We are very satisfied with the tool."
 

Cons

"The initial setup was very complex. We did not have a very good experience with our initial deployment. Most of this was due to customizations in our ServiceNow instance."
"The ability to not have to worry about the IT alerting and calendar resources. I would like it to be simpler in the sense of a different cost structure."
"It could use more enhancement type integrations, but no improvements to functionality are needed."
"One thing that could be improved would be to enable the mobile app to more easily display published calendars via the Member Portal. Currently, it is quite difficult."
"The integration with other solutions needs improvement... Due to issues with the libraries provided by Everbridge, we have not been able to integrate IT Alerting with our incident management tool."
"There is some room to improve the initial-rollout functions which are a little bit painful."
"I swapped two people's weeks, and at least from what I saw, I had to do each day individually."
"With their templates, you can only have a maximum of three phases: new, updated, and resolved. It's not always that easy when we open up a call, that we identify who we need, page out, and we're good. A lot of time it requires multiple page-outs. Being restricted to those three phases, there's no way to say, "I want this variable to be persistent, and this one to not be." ...I would like to see a bit more flexibility and tighter control over the templates and the variables you can create."
"Splunk Enterprise Security can be improved with better triage capability and less dependency on running SPL searches, which would allow analysts who may not have much experience in writing SPL searches to still use the tool and run investigations."
"​On the technical side, it would be nice to see aspects of the recent acquisition of Phantom make it into the core Splunk Enterprise, not just become a part of the premium Enterprise Security.​"
"We'd like Splunk to reduce false positives."
"The threat management part is still lagging. There are some gaps in threat management. Other vendors have built-in threat management systems, but Splunk lacks the threat management component in its portal. The UEBA and everything else is perfect, but it lacks a unified threat intelligence and management part."
"It is a good product, but the Achilles heel for a lot of organizations is the cost model for it because it gets expensive. That's because the model is based on how much data it processes a day, which can be prohibitive, especially if you have a lot of data. A lot of customers may not be ready for the sticker shock on how to fully leverage the product. I realized that the reason for that is that when it was originally designed, it was kind of like a big data modeling application. If they want to have a bigger customer base, they can come out with subsets of their product that are focused on specific things and have different pricing models. It may help with the cost."
"A problem that we had recently had was we licensed it based on how much data you upload to them every day."
"We're planning to incorporate UBA and SOAR. It would be good to have everything in one place."
"I would like more assistance with use cases and help with teaching us how to use it once it's installed."
"One area for improvement would be enhancing the mobile app experience."
"Many years ago, when VictorOps was a standalone company, when it was not part of Splunk, their support was more dedicated for us."
"User management has to be improved and more user types need to be added as there is currently only Admin or User."
"The third-party configuration tool could be easier to use."
"Should have more YouTube webinars."
"At that stage, all our needs are fulfilled, but at the beginning, we had some feature requests and they were deployed during their roadmap."
"There could be improvements with communicating an incident or alert."
"We chose to move away from the HP product as far as our monitoring goes and dealing with system-generated alerts, simply because it took too much time and effort to manage the APM platform."
 

Pricing and Cost Advice

"It saves us a lot of time."
"It's a seven out of ten for us in terms of pricing. We've just gone through a process of looking at other solutions."
"Their call structure is based on how many people are IT alert people and who is on the calendar, and the cost will be driven by those numbers versus if you are using it for the non-IT alert. As you look at the competition and other vendors, make sure you truly understand your cost structure with them."
"They are one of the top three most expensive products. I also understand if you are going to use them for IT alerting, it is worth it. They are competitively priced, but the IT alerting is the differentiator. The way that they market it and push it out. That is their premier function."
"As far as I'm aware, there are no costs beyond the standard licensing fees."
"Everbridge is not an inexpensive tool, but as the adage says, you get what you pay for."
"The annual cost is $125,000 USD. That is for everything. It includes the 11,000 mass notifications. Technically, we have 500 licenses for IT Alerting."
"Everbridge IT Alerting is a cost-efficient solution."
"Splunk Enterprise Security incurs a significant cost because of the amount of data we send, but we are fine with the value we're getting for that price."
"The pricing modules could be improved."
"Unlike other security tools, Splunk provides a fixed amount of gigabytes per day, and we are required to pay for any additional usage beyond that limit, in addition to our monthly cost."
"It is expensive. That is why many customers have moved to IBM QRadar. The price is definitely a challenge for customers."
"Luckily, we come under a large federal agency, and before the pandemic, they signed a large enterprise license agreement. It worked out great and to our advantage because we are a small organization. We got a 300 gig license, and we just did not have the buying power to be able to get products cheaply. Because we all partnered together under the agency umbrella, we were able to get Splunk Enterprise Security, UBA, and ITSI for cheap. This was good considering the fact that some of these premium apps require a minimum number of users, and we do not have the number of people needed to even justify buying it."
"The pricing of Splunk Enterprise Security is high."
"It is quite expensive."
"From what I have seen so far, Splunk has multiple cost models. The one that we are using is pretty good when it comes to ingesting data into the environment. It has worked out pretty well."
"The price of the solution could be less expensive."
report
Use our free recommendation engine to learn which IT Alerting and Incident Management solutions are best for your needs.
885,728 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Performing Arts
10%
Manufacturing Company
8%
Healthcare Company
6%
Financial Services Firm
12%
Computer Software Company
9%
Manufacturing Company
9%
Government
6%
Performing Arts
13%
Construction Company
10%
Manufacturing Company
9%
Financial Services Firm
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business3
Large Enterprise22
By reviewers
Company SizeCount
Small Business112
Midsize Enterprise50
Large Enterprise267
By reviewers
Company SizeCount
Small Business1
Midsize Enterprise1
Large Enterprise9
 

Questions from the Community

What needs improvement with Everbridge IT Alerting?
The solution's non-targeted communication with external parties could be enhanced.
What advice do you have for others considering Everbridge IT Alerting?
We are using Everbridge IT Alerting for incident and crisis modules. The tool is powerful in itself, but as with any ...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is a...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingest...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitor...
What is your experience regarding pricing and costs for VictorOps?
My experience with Splunk On-Call pricing and licensing has been straightforward. The setup cost was minimal since it...
What needs improvement with VictorOps?
One area for improvement would be enhancing the mobile app experience. While it works well, smoother navigation and f...
What is your primary use case for VictorOps?
I have been using Splunk On-Call for the last three years. My main use case for Splunk On-Call is incident alerting a...
 

Also Known As

No data available
No data available
VictorOps
 

Overview

 

Sample Customers

Choice Hotels, Alexion, Navy Federal Credit Union, EastWest Bank, IBM, Core Logic, Paypal, Charter Communications, Lowes, Express Scripts, Finastra, Worldpay
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
NVIDIA, Cisco, NBC, Rackspace, Intuit, DirectTV, NASCAR, Arrow Electronics, Alliance Health, NetApp, Edmunds, New York Times, Return Path, Sony Playstation, CA Technologies, Sphero, Symantic, HBO, Weatherford, Blackboard, Epic Games
Find out what your peers are saying about PagerDuty, Splunk, Atlassian and others in IT Alerting and Incident Management. Updated: March 2026.
885,728 professionals have used our research since 2012.