

Find out in this report how the two IT Alerting and Incident Management solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI.
Key impact areas are generally time saved in investigations, higher analyst productivity, lowered costs of security incidents due to faster detection and response, and reduced manual reporting effort.
Splunk Enterprise Platform has provided tremendous value.
For us, the main value lies in error handling and identifying bugs.
Rootly's customer support is great; every time we have had to use it, they have gotten in touch with us really quickly and connected us to the relevant teams to fix our problems or potentially suggest a feature for the future.
The customer support is quite good; I can write to Rootly specialists in Slack, and that is very useful.
We contacted support and they were able to provide us with the solution which is currently working fine.
I would rate the customer support a ten.
I would rate the customer support a ten.
If we ever need to add a new alert, we just put it into the code, run the pipeline, and we are done.
Rootly's scalability is great; it goes under the hood and my colleagues and I as users do not think about it generally.
Splunk allows for scalability, as you can start with an all-in-one instance and, as your deployment grows, split it into distributed deployment, such as separating the search head and indexers.
It is highly stable and scalable for us.
In a day we get millions of hits for the APIs.
Our L1 and L2 teams get real-time alerts and query the SPL effectively without delays that other SIEM solutions may impose.
It is highly stable and scalable for us.
It requires managing configuration files and processing operations manually, limiting its auto-scaling capabilities.
We had one incident when we lost alerting generally because Rootly crashed, and we did not like it.
The integration process could be easier, perhaps with the addition of AI to facilitate smoother integrations with other applications, especially since those who manage integrations often need technical knowledge about web services and single sign-on processes, which can be challenging for non-technical users.
Enhancing search functionality to make it easier to locate historical incidents and action items would be beneficial.
The deep learning capabilities need enhancing, especially on Splunk Cloud, where customers find it challenging to use deep learning tools without setting up backend computing resources.
I could also build some pre-indexed summaries so that Splunk Enterprise Platform can search much faster than raw logs.
From an architectural standpoint, data onboarding, normalization, performance, and scalability improvements would be beneficial, particularly in optimizing search speed and query execution to handle larger searches efficiently.
Generally, it is great and the price is great, and that is the reason we chose Rootly.
Rootly scheduled a call with us and was very quick to give us a POC license to trial out the full product.
The pricing model is based on ingesting data sizes, not user count, and includes a free tier for up to 500 MB of daily data.
We ingest terabytes of data, so I can say Splunk Enterprise Platform is somewhat costly.
The platform's ability to consolidate siloed tools into a single pane of glass provides immense value justifying the premium cost if the architecture is tightly managed.
With the strategic approach of putting everyone in a Slack group to resolve incidents, we have reduced the percentage of incidents created in a month by thirty percent during the first three months of using Rootly.
Rather than manually tweaking schedules to try to hack a way to shadow existing engineers, Rootly gave us a shadow feature which allowed us to say person X, please shadow person Y, using these times and these days, very customizable.
The precise rules and entities help me route alerts very specifically to the exact persons who are in charge and to rotate this person using on-call policies.
Splunk Enterprise Platform also has its own Phantom as a SOAR, which is much more refined and gives more accurate results than any other AI integrated SIM tool.
The anomaly detection is very good for live production data. Whenever an anomaly comes in an application, it automatically resolves and just gives the notification.
Splunk Enterprise Platform will create an incident and detect this as a credential compromise because we have a successful login from another location.
| Product | Mindshare (%) |
|---|---|
| Splunk Enterprise Platform | 2.7% |
| Rootly | 2.8% |
| Other | 94.5% |

| Company Size | Count |
|---|---|
| Small Business | 3 |
| Large Enterprise | 4 |
| Company Size | Count |
|---|---|
| Small Business | 39 |
| Midsize Enterprise | 11 |
| Large Enterprise | 67 |
Rootly is an essential tool for effectively addressing and managing incidents within any system or organization. With quick and reliable incident alerts, comprehensive incident management capabilities, and efficient problem-solving features, Rootly helps users to identify, prioritize, and resolve incidents, resulting in improved system reliability and reduced downtime. The solution is highly regarded for its reliability, excellent customer support, and overall value to users.
Splunk Enterprise Platform provides high flexibility and integration, featuring strong analytics, data ingestion, and real-time monitoring, catering to diverse industry needs and enhancing threat detection and data analysis.
Splunk Enterprise Platform is renowned for its powerful capabilities in log management, threat detection, and data visualization. It supports infrastructure monitoring and anomaly detection, crucial for Security Incident and Event Management operations. With its scalable architecture, users can efficiently manage data ingestion and create personalized dashboards, utilizing Splunk Processing Language for comprehensive querying and system performance assessment. This platform offers enhanced threat detection through its robust anomaly detection features and real-time monitoring capabilities, with machine learning enabling predictive analytics.
What features make Splunk Enterprise Platform stand out?In industries like finance, healthcare, and technology, Splunk Enterprise Platform is implemented to monitor infrastructure, manage logs, and enhance security protocols. Companies utilize its predictive analytics for strategic planning and operational efficiency, focusing on integration with AWS, EDR, and firewalls for comprehensive data visualization and threat management.
We monitor all IT Alerting and Incident Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.