No more typing reviews! Try our Samantha, our new voice AI agent.

Rootly vs Splunk Enterprise Platform comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
3.7
Rootly enhances productivity and standardizes incident management despite uncertainties regarding measurable ROI and specific efficiency metrics.
Sentiment score
4.4
Splunk Enterprise Platform saves time and reduces costs by centralizing logs, enhancing security, and improving operational efficiency.
Key impact areas are generally time saved in investigations, higher analyst productivity, lowered costs of security incidents due to faster detection and response, and reduced manual reporting effort.
Managed Security Services Associate at Accenture
Splunk Enterprise Platform has provided tremendous value.
Splunk Engineer
For us, the main value lies in error handling and identifying bugs.
Administrator at a government with 201-500 employees
 

Customer Service

Sentiment score
6.5
Rootly's customer service is praised for quick, proactive engagement and useful Slack support, leading to high user satisfaction.
Sentiment score
6.7
Splunk's customer service is praised for responsiveness and helpfulness, with beneficial community support, despite some variability in expertise.
Rootly's customer support is great; every time we have had to use it, they have gotten in touch with us really quickly and connected us to the relevant teams to fix our problems or potentially suggest a feature for the future.
Lead Dev Ops Engineer at a financial services firm with 51-200 employees
The customer support is quite good; I can write to Rootly specialists in Slack, and that is very useful.
Devops engineer at a tech vendor with 51-200 employees
We contacted support and they were able to provide us with the solution which is currently working fine.
Splunk Engineer at a recruiting/HR firm with 11-50 employees
I would rate the customer support a ten.
Splunk architect at a consultancy with 10,001+ employees
I would rate the customer support a ten.
engineer at a tech services company with 11-50 employees
 

Scalability Issues

Sentiment score
6.1
Rootly enhances scalability by seamlessly integrating with growth, simplifying component addition, alert management, and user expansion for teams.
Sentiment score
7.7
Splunk Enterprise Platform is praised for its scalability, efficiently handling large data volumes while supporting vertical and horizontal scaling.
If we ever need to add a new alert, we just put it into the code, run the pipeline, and we are done.
Lead Dev Ops Engineer at a financial services firm with 51-200 employees
Rootly's scalability is great; it goes under the hood and my colleagues and I as users do not think about it generally.
Devops engineer at a tech vendor with 51-200 employees
Splunk allows for scalability, as you can start with an all-in-one instance and, as your deployment grows, split it into distributed deployment, such as separating the search head and indexers.
Security Consultant at ITSEC Asia
It is highly stable and scalable for us.
Dev Ops And Observability Admin at a tech services company with 11-50 employees
In a day we get millions of hits for the APIs.
Software Developer at a financial services firm with 10,001+ employees
 

Stability Issues

Sentiment score
8.7
Rootly is praised for its stability, with users consistently highlighting its reliability and lack of issues or complications.
Sentiment score
8.3
Splunk Enterprise Platform is highly stable and reliable, excelling in large data handling and minimal downtime for daily operations.
Our L1 and L2 teams get real-time alerts and query the SPL effectively without delays that other SIEM solutions may impose.
Global Head Of Security Architecture Digital & Technology at Aramex
It is highly stable and scalable for us.
Dev Ops And Observability Admin at a tech services company with 11-50 employees
It requires managing configuration files and processing operations manually, limiting its auto-scaling capabilities.
Consultant at Artifield
 

Room For Improvement

Rootly aims to improve integration, notifications, and customization with AI while listening to user feedback for future enhancements.
Splunk Enterprise users seek improved UI efficiency, cost reduction, enhanced AI, better data management, and increased accessibility and automation.
We had one incident when we lost alerting generally because Rootly crashed, and we did not like it.
Devops engineer at a tech vendor with 51-200 employees
The integration process could be easier, perhaps with the addition of AI to facilitate smoother integrations with other applications, especially since those who manage integrations often need technical knowledge about web services and single sign-on processes, which can be challenging for non-technical users.
System Architect at CI&T
Enhancing search functionality to make it easier to locate historical incidents and action items would be beneficial.
Specilist at a tech vendor with 10,001+ employees
The deep learning capabilities need enhancing, especially on Splunk Cloud, where customers find it challenging to use deep learning tools without setting up backend computing resources.
Consultant at Artifield
I could also build some pre-indexed summaries so that Splunk Enterprise Platform can search much faster than raw logs.
security engineer at a tech vendor with 501-1,000 employees
From an architectural standpoint, data onboarding, normalization, performance, and scalability improvements would be beneficial, particularly in optimizing search speed and query execution to handle larger searches efficiently.
Global Head Of Security Architecture Digital & Technology at Aramex
 

Setup Cost

Rootly offers competitive pricing and easy setup, appealing to enterprises, though user addition processes could improve.
Splunk Enterprise Platform's pricing can be costly, but scalable features and flexible pricing models help manage expenses.
Generally, it is great and the price is great, and that is the reason we chose Rootly.
Devops engineer at a tech vendor with 51-200 employees
Rootly scheduled a call with us and was very quick to give us a POC license to trial out the full product.
Lead Dev Ops Engineer at a financial services firm with 51-200 employees
The pricing model is based on ingesting data sizes, not user count, and includes a free tier for up to 500 MB of daily data.
Consultant at Artifield
We ingest terabytes of data, so I can say Splunk Enterprise Platform is somewhat costly.
Dev Ops And Observability Admin at a tech services company with 11-50 employees
The platform's ability to consolidate siloed tools into a single pane of glass provides immense value justifying the premium cost if the architecture is tightly managed.
Managed Security Services Associate at Accenture
 

Valuable Features

Rootly's Slack integration streamlines communication, enhances workflow, improves resolution rates, and boosts operational efficiency with top tool integrations.
Splunk Enterprise offers customizable dashboards, real-time alerts, data integration, and machine learning tools for efficient log management and threat detection.
With the strategic approach of putting everyone in a Slack group to resolve incidents, we have reduced the percentage of incidents created in a month by thirty percent during the first three months of using Rootly.
System Architect at CI&T
Rather than manually tweaking schedules to try to hack a way to shadow existing engineers, Rootly gave us a shadow feature which allowed us to say person X, please shadow person Y, using these times and these days, very customizable.
Lead Dev Ops Engineer at a financial services firm with 51-200 employees
The precise rules and entities help me route alerts very specifically to the exact persons who are in charge and to rotate this person using on-call policies.
Devops engineer at a tech vendor with 51-200 employees
Splunk Enterprise Platform also has its own Phantom as a SOAR, which is much more refined and gives more accurate results than any other AI integrated SIM tool.
SOC A2 at Innodata-ISOGEN
The anomaly detection is very good for live production data. Whenever an anomaly comes in an application, it automatically resolves and just gives the notification.
Technical Lead at a financial services firm with 10,001+ employees
Splunk Enterprise Platform will create an incident and detect this as a credential compromise because we have a successful login from another location.
Cybersecurity Team Leader at EMAK For Computer Manufacturing (ECM)
 

Categories and Ranking

Rootly
Ranking in IT Alerting and Incident Management
11th
Average Rating
8.0
Reviews Sentiment
5.9
Number of Reviews
4
Ranking in other categories
No ranking in other categories
Splunk Enterprise Platform
Ranking in IT Alerting and Incident Management
2nd
Average Rating
8.6
Reviews Sentiment
6.2
Number of Reviews
95
Ranking in other categories
Data Visualization (2nd)
 

Mindshare comparison

As of October 2026, in the IT Alerting and Incident Management category, the mindshare of Rootly is 2.8%, down from 9.6% compared to the previous year. The mindshare of Splunk Enterprise Platform is 2.7%, up from 1.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
IT Alerting and Incident Management Mindshare Distribution
ProductMindshare (%)
Splunk Enterprise Platform2.7%
Rootly2.8%
Other94.5%
IT Alerting and Incident Management
 

Featured Reviews

MT
Lead Dev Ops Engineer at a financial services firm with 51-200 employees
On-call workflows have become reliable and onboarding new engineers runs smoothly
The best feature that Rootly offers, which I really appreciated when we onboarded Rootly, is the shadowing feature. I evaluated quite a few tools but Rootly was the only one at the time that had this, and this allowed us to onboard new engineers into the on-call rota smoothly, which was a really cool feature. Regarding how the shadowing feature helped with onboarding new engineers, rather than manually tweaking schedules to try to hack a way to shadow existing engineers, Rootly gave us a shadow feature which allowed us to say person X, please shadow person Y, using these times and these days, very customizable, and it allowed us to onboard people in a much more graceful manner.
Koyena Paul - PeerSpot reviewer
Managed Security Services Associate at Accenture
Centralized security monitoring has transformed our threat detection and incident response
While Splunk Enterprise Platform is widely regarded as a powerful SIEM and observability platform, users across enterprises commonly report recurring challenges including licensing and data ingestion costs. Splunk Enterprise Platform's licensing is often based on the volume of data ingested, and as our organization grows, costs can increase significantly, and our teams may need to carefully decide which logs to ingest, which can limit visibility. A suggested improvement would be more flexible licensing options, better built-in recommendations for optimizing data ingestion, and smarter data compression or tiered pricing. There is also a steep learning curve where beginners can find SPL difficult. A suggested improvement would be more AI-assisted SPL generation, interactive tutorials, and guided dashboard creation with additional pre-built templates for common SOC use cases. These are the main areas for improvement that I can see: licensing flexibility, reducing the learning curve for new users, simplifying development, improving performance for very large datasets, and providing more AI-assisted features to reduce manual effort. In terms of adding more improvements, there are frequently discussed areas including easier third-party integrations. While Splunk Enterprise Platform supports many integrations, onboarding new security tools sometimes requires custom configurations or add-ons. A suggested improvement would be more plug-and-play integrations, faster support for new vendors, and then simplified administration. Administrators often manage indexes, forwarders, user roles, and cluster health, so a suggested improvement would be easier administration dashboards and automated health checks. These are suggestions that acknowledge Splunk Enterprise Platform's strengths while highlighting areas where many enterprise users see opportunities for further improvement. The primary areas for improvement that I see are licensing flexibility, simplifying administration, expanding plug-and-play integrations, and adding more AI-driven assistance for searches and investigations. These improvements would significantly simplify our tasks and help us solve more incidents in a lesser amount of time, making it flexible even for beginners.
report
Use our free recommendation engine to learn which IT Alerting and Incident Management solutions are best for your needs.
915,341 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Performing Arts
27%
Manufacturing Company
7%
Comms Service Provider
6%
Financial Services Firm
6%
Financial Services Firm
14%
Outsourcing Company
13%
Construction Company
9%
Healthcare Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business3
Large Enterprise4
By reviewers
Company SizeCount
Small Business39
Midsize Enterprise11
Large Enterprise67
 

Questions from the Community

What is your experience regarding pricing and costs for Rootly?
Regarding my experience with pricing, setup cost, and licensing, we got a license for one year. Generally, it is great and the price is great, and that is the reason we chose Rootly. The only thing...
What needs improvement with Rootly?
There are a few areas where Rootly can be improved. More customization options for postmortem templates and reports would be helpful. Enhancing search functionality to make it easier to locate hist...
What is your primary use case for Rootly?
I use Rootly every day to manage the end-to-end incident lifecycle. When a critical incident is reported, I create or join an incident on Rootly, assign the appropriate severity, and engage the req...
What needs improvement with Splunk Enterprise Platform?
I do not have any suggestions on how Splunk Enterprise Platform can be improved because I am happy with it. If I had to think of one area where Splunk Enterprise Platform could be better or easier ...
What is your primary use case for Splunk Enterprise Platform?
My main use case for Splunk Enterprise Platform is to monitor the video on demand success rate for our video platform. A specific example of how I use Splunk Enterprise Platform for monitoring the ...
What advice do you have for others considering Splunk Enterprise Platform?
My advice to others looking into using Splunk Enterprise Platform is to research the product and utilize all the support that Splunk provides. I have rated this review a ten out of ten.
 

Overview

 

Sample Customers

* **Atlassian** * **Cisco** * **Databricks** * **DigitalOcean** * **Google Cloud** * **IBM** * **JetBlue** * **LinkedIn** * **Lyft** * **Microsoft** * **MongoDB** * **Netflix** * **Pinterest** * **Qualcomm** * **Red Hat** * **Salesforce** * **Spotify** * **Square** * **T-Mobile** * **Twitter** * **Uber** * **VMware** * **WeWork** * **Workday** * **Xerox** * **Zoom**
Information Not Available
Find out what your peers are saying about Rootly vs. Splunk Enterprise Platform and other solutions. Updated: September 2026.
915,341 professionals have used our research since 2012.