No more typing reviews! Try our Samantha, our new voice AI agent.

Rootly vs Splunk Enterprise Platform comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Rootly
Ranking in IT Alerting and Incident Management
5th
Average Rating
8.0
Reviews Sentiment
5.6
Number of Reviews
4
Ranking in other categories
No ranking in other categories
Splunk Enterprise Platform
Ranking in IT Alerting and Incident Management
2nd
Average Rating
8.6
Reviews Sentiment
6.4
Number of Reviews
61
Ranking in other categories
Data Visualization (2nd)
 

Mindshare comparison

As of August 2026, in the IT Alerting and Incident Management category, the mindshare of Rootly is 3.1%, down from 10.0% compared to the previous year. The mindshare of Splunk Enterprise Platform is 2.7%, up from 1.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
IT Alerting and Incident Management Mindshare Distribution
ProductMindshare (%)
Splunk Enterprise Platform2.7%
Rootly3.1%
Other94.2%
IT Alerting and Incident Management
 

Featured Reviews

Luis Vasconcelos - PeerSpot reviewer
System Architect at CI&T
Centralized incident workflows have improved visibility and streamlined communication across teams
Rootly helps me handle those issues by using a predefined template to define roles inside the workflow and utilizing a basic flow, which is very short in its lifecycle. The most powerful feature of Rootly is its visibility; we can create a dashboard and integrate with Slack and Jira, for example, automating many steps in the follow-up process, which helps to centralize all communications around issues. The best features Rootly offers include communication capabilities, particularly the integration with Slack, which stands out for me because it allows for very clean and direct communication with all clients and even with the resolution area. The Slack integration helps my team by creating a specific resolution group and an automation channel inside Slack once an incident is opened in Rootly, ensuring that everyone knows when a new incident arises. It is not just a notification; we create a group where all the relevant people can help solve the issue quickly. The workflow capability of Rootly to create flows is another key feature for our operation, allowing us to establish specific rules for incidents in Jira or manage the metrics we need during the incident lifecycle, effectively automating many manual processes. Rootly has positively impacted my organization, and we have measured its impact by analyzing the number of incidents we handle over a period. With the strategic approach of putting everyone in a Slack group to resolve incidents, we have reduced the percentage of incidents created in a month by thirty percent during the first three months of using Rootly. Other positive outcomes include time savings and improvements in collaboration; the groups inside Slack enable people to communicate across different areas and work directly with client operations, creating synergy and a strong integration between teams.
Koyena Paul - PeerSpot reviewer
Managed Security Services Associate at Accenture
Centralized security monitoring has transformed our threat detection and incident response
While Splunk Enterprise Platform is widely regarded as a powerful SIEM and observability platform, users across enterprises commonly report recurring challenges including licensing and data ingestion costs. Splunk Enterprise Platform's licensing is often based on the volume of data ingested, and as our organization grows, costs can increase significantly, and our teams may need to carefully decide which logs to ingest, which can limit visibility. A suggested improvement would be more flexible licensing options, better built-in recommendations for optimizing data ingestion, and smarter data compression or tiered pricing. There is also a steep learning curve where beginners can find SPL difficult. A suggested improvement would be more AI-assisted SPL generation, interactive tutorials, and guided dashboard creation with additional pre-built templates for common SOC use cases. These are the main areas for improvement that I can see: licensing flexibility, reducing the learning curve for new users, simplifying development, improving performance for very large datasets, and providing more AI-assisted features to reduce manual effort. In terms of adding more improvements, there are frequently discussed areas including easier third-party integrations. While Splunk Enterprise Platform supports many integrations, onboarding new security tools sometimes requires custom configurations or add-ons. A suggested improvement would be more plug-and-play integrations, faster support for new vendors, and then simplified administration. Administrators often manage indexes, forwarders, user roles, and cluster health, so a suggested improvement would be easier administration dashboards and automated health checks. These are suggestions that acknowledge Splunk Enterprise Platform's strengths while highlighting areas where many enterprise users see opportunities for further improvement. The primary areas for improvement that I see are licensing flexibility, simplifying administration, expanding plug-and-play integrations, and adding more AI-driven assistance for searches and investigations. These improvements would significantly simplify our tasks and help us solve more incidents in a lesser amount of time, making it flexible even for beginners.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Rootly has positively impacted our organization because, in comparison to ObsGenie, the tool we used before Rootly, it is much more user-friendly, including the user interface and the whole approach to alerting and routing these alerts."
"Rootly has positively impacted my organization by allowing us to receive the on-call alerts successfully, whereas before Rootly, we had issues missing alerts."
"Rootly has positively impacted my organization by saving time with manually adding timelines, as they are already built in when timelines are added in Slack through integration."
"With the strategic approach of putting everyone in a Slack group to resolve incidents, we have reduced the percentage of incidents created in a month by thirty percent during the first three months of using Rootly."
"The most valuable feature of the solution is the analytics part."
"The best thing about Splunk is you can collect all the data you want, and you can play with the data and do what you want."
"Splunk Enterprise Platform has improved visibility across the environment by centralizing logs from multiple systems, reduced the time needed to detect, investigate, and respond to security incidents, streamlined troubleshooting, and helped my team respond to issues more quickly, improving operational efficiency and reducing downtime."
"Splunk Enterprise enhances data analytics with its AI capabilities."
"Splunk Enterprise Platform offers very good integration patterns and extensive support for many log sources with pre-built rule sets and pre-built integrations."
"Overall, the feature set of Splunk Enterprise Platform is comprehensive and flexible."
"The most valuable feature of Splunk Enterprise Platform is that it's a customizable solution."
"While I cannot share internal metrics, I can say that Splunk Enterprise Platform has led to faster incident triage, better visibility into security events, and reduced time spent on manual investigations due to centralized log analysis and automated correlations."
 

Cons

"There are a few areas where Rootly can be improved."
"Regarding Rootly's AI capabilities, we had one incident when we lost alerting generally because Rootly crashed, and we did not like it."
"The integration process could be easier, perhaps with the addition of AI to facilitate smoother integrations with other applications, especially since those who manage integrations often need technical knowledge about web services and single sign-on processes, which can be challenging for non-technical users."
"There is very much improvement needed from Splunk vendor support side because they need to check what people are raising in the requests."
"The only problem I have with Splunk Enterprise Platform is that sometimes when I update a review, it takes time to receive confirmation emails."
"There is room for improvement in terms of scalability."
"The licensing model is based on data ingestion volume and can become expensive as organizations grow."
"When concerning the cost of Splunk Enterprise Platform, the license cost can be a factor."
"The Splunk Enterprise Platform has room for improvement, particularly in automating the permissions process during app promotions. Currently, permissions are manually set when different teams request an application move to production, which is time-consuming. Automating this process would streamline operations by automatically assigning the appropriate permissions and roles to specific services or teams, reducing the need to review each request ticket manually."
"Sometimes, queries don't give proper results, and the indexes go down."
"For Splunk Enterprise Platform improvement, I think it would be beneficial to focus on particular areas such as system performance, cost management, and detection accuracy."
 

Pricing and Cost Advice

Information not available
"The solution is expensive, so I rate its pricing a four out of ten."
"On a scale from one to ten, where one is cheap, and ten is expensive, I rate the solution's pricing around seven or eight out of ten."
"The solution's pricing increases with the amount of data used. This pricing model is acceptable because it aligns with the security features provided. It ensures that the price reflects the level of security and the amount of data we're managing."
"The solution’s pricing is moderate."
"I have heard from my managers that Splunk Enterprise Platform is an expensive solution."
"The product is expensive, and the cost depends on the amount of data ingestion."
"I rate the product's pricing a ten on a scale of one to ten, where one is cheap, and ten is expensive. It is a very pricey tool."
"The tool is expensive."
report
Use our free recommendation engine to learn which IT Alerting and Incident Management solutions are best for your needs.
909,725 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Performing Arts
28%
Comms Service Provider
7%
Financial Services Firm
7%
Transportation Company
7%
Financial Services Firm
16%
Construction Company
10%
Outsourcing Company
8%
Manufacturing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business34
Midsize Enterprise8
Large Enterprise43
 

Questions from the Community

What is your experience regarding pricing and costs for Rootly?
Regarding my experience with pricing, setup cost, and licensing, we got a license for one year. Generally, it is great and the price is great, and that is the reason we chose Rootly. The only thing...
What needs improvement with Rootly?
There are a few areas where Rootly can be improved. More customization options for postmortem templates and reports would be helpful. Enhancing search functionality to make it easier to locate hist...
What is your primary use case for Rootly?
I use Rootly every day to manage the end-to-end incident lifecycle. When a critical incident is reported, I create or join an incident on Rootly, assign the appropriate severity, and engage the req...
What needs improvement with Splunk Enterprise Platform?
With respect to the use cases, we were able to create many use cases as well as fine-tune them, so thirty percent of the alerts were fine-tuned, and we have improved our detection logic and also th...
What is your primary use case for Splunk Enterprise Platform?
Splunk Enterprise Platform serves as our SIEM tool where we receive alerts and we primarily depend on it. As a centralized logging and monitoring system, we use Splunk based upon different data typ...
What advice do you have for others considering Splunk Enterprise Platform?
With respect to the use cases, we were able to create many use cases as well as fine-tune them, so thirty percent of the alerts were fine-tuned, and we have improved our detection logic and also th...
 

Overview

 

Sample Customers

* **Atlassian** * **Cisco** * **Databricks** * **DigitalOcean** * **Google Cloud** * **IBM** * **JetBlue** * **LinkedIn** * **Lyft** * **Microsoft** * **MongoDB** * **Netflix** * **Pinterest** * **Qualcomm** * **Red Hat** * **Salesforce** * **Spotify** * **Square** * **T-Mobile** * **Twitter** * **Uber** * **VMware** * **WeWork** * **Workday** * **Xerox** * **Zoom**
Information Not Available
Find out what your peers are saying about Rootly vs. Splunk Enterprise Platform and other solutions. Updated: August 2026.
909,725 professionals have used our research since 2012.