No more typing reviews! Try our Samantha, our new voice AI agent.

Splunk ITSI (IT Service Intelligence) vs Splunk Security Essentials comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 2, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Splunk ITSI (IT Service Int...
Ranking in IT Alerting and Incident Management
4th
Average Rating
8.4
Reviews Sentiment
6.6
Number of Reviews
64
Ranking in other categories
Application Performance Monitoring (APM) and Observability (10th)
Splunk Security Essentials
Ranking in IT Alerting and Incident Management
14th
Average Rating
8.6
Reviews Sentiment
4.8
Number of Reviews
6
Ranking in other categories
Data Visualization (14th), Security Incident Response (10th)
 

Mindshare comparison

As of August 2026, in the IT Alerting and Incident Management category, the mindshare of Splunk ITSI (IT Service Intelligence) is 2.0%, down from 2.4% compared to the previous year. The mindshare of Splunk Security Essentials is 1.8%, up from 0.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
IT Alerting and Incident Management Mindshare Distribution
ProductMindshare (%)
Splunk ITSI (IT Service Intelligence)2.0%
Splunk Security Essentials1.8%
Other96.2%
IT Alerting and Incident Management
 

Featured Reviews

DS
Senior Consultant at a consultancy with 10,001+ employees
Service health has been monitored and visual insights support proactive telecom operations
The installation process is the first aspect I dislike about Splunk ITSI (IT Service Intelligence). If you do not configure it correctly, you will encounter issues in the search head. Because we use a distributed environment where each component has its own specific roles, installation is critical and requires careful attention. Splunk ITSI (IT Service Intelligence) is built with many applications. It is a compressed file, and when you extract the Splunk ITSI (IT Service Intelligence) app, you receive approximately 19 apps. Some applications, add-ons, and packages must be installed on specific components. If you do not configure an application correctly, it will not work. Sometimes we encounter issues during installation because of this complexity. I believe the installation process should be more uniform, meaning it could be deployed across all components to avoid post-installation issues. Sometimes after installation, you receive errors, and users cannot access Splunk ITSI (IT Service Intelligence). We have experienced this type of issue due to installation errors. I believe there is currently room for improvement regarding scalability. When we create Glass Tables containing many searches, the Glass Tables sometimes fail due to memory constraints, and we receive error pages. Splunk ITSI (IT Service Intelligence) should have a lightweight version to address these concerns. I would rate current scalability as medium.
reviewer2836941 - PeerSpot reviewer
Assistant Manager at a tech services company with 1-10 employees
Centralized monitoring has given our SOC real-time visibility into security and application activity
When I first implemented Splunk Security Essentials in this environment, it took a week for each log source to onboard and to create use cases and implement the data model, CIM, etc., for production readiness. Training is mandatory, and we need at least the Splunk Security Essentials User certification because it is a very critical resource in the organization, as we are handling security logs. In my organization, Splunk Security Essentials is used not only by the SOC but also for monitoring logs across different teams, as it is important for handling both security and application logs, given its capability to manage unstructured logs. Splunk Security Essentials has dramatically impacted my organization, as without it, we were blind to what is happening from both a security and application perspective, and it provides vital visibility into the organization's operations.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Splunk is not only a great product but also, as a company it really supports its users with the customer support program and all of the documentation they have available, all of the conventions that are arranged, meet the experts, case studies, use cases, and the YouTube channel."
"We save substantial time on monitoring tasks because we don't have to search for what we need. Everything is packed, so you can drill down to the end values by just doing the kit. We don't spend a lot of time on this. Splunk ITSI is easy to use and not time-consuming."
"Splunk ITSI offers a valuable visualization tree that allows us to map and analyze dependencies and co-dependency within our environment."
"The most valuable feature is the Glass Tables. It gives you a nice, good overview of your KPIs. It's really slick and clean."
"One particularly useful feature of Splunk ITSI is the ability to create custom services."
"The feature that stood out to me most from Splunk IT Service Intelligence (ITSI) was automated dashboarding or reporting. The solution lists the severity level of issues, and the response times."
"The search function is the most valuable. It includes regular expressions and wild card searches. We'll write searches using field and case-sensitive services and use all of these search types to write an alert condition. Splunk ITSI has another feature called Glass Table that offers a visual representation."
"Customers have noted the solution helps streamline incident management."
"The network monitoring feature is particularly valuable for gathering information about users, login times, and other statistics."
"Splunk Security Essentials has dramatically impacted my organization, as without it, we were blind to what is happening from both a security and application perspective, and it provides vital visibility into the organization's operations."
"Splunk Security Essentials has impacted my organization in that we have been getting the results that we wanted."
"I would have to rate Splunk Security Essentials a 10 out of 10 because it's free and there's tons of usable content."
"We are focusing on security to ensure incidents are reported efficiently. In addition to that, for reporting purposes, we are utilizing our dashboards or creating new ones. We will be using free visualization tools for this purpose."
"They have a good catalog of plans to use to resist the attacks."
 

Cons

"Splunk ITSI's UI needs to be more interactive and user-friendly."
"One area where Splunk ITSI (IT Service Intelligence) has room for improvement is the high cost associated with it."
"When we check the service analyzer, and we have custom inputs, there are issues."
"ITSI currently lacks the capability for automated response, mitigation, and remediation."
"Predictive analytics, in terms of preventing incidents before they occur, still needs time to mature."
"The dashboard queries should be improved. More queries should be suggested in order to produce better dashboards."
"The license cost is expensive."
"We're using predictive analytics, and there are three or four algorithms. It would be helpful if this process were more standardized and scalable."
"The reporting feature needs to be more user-friendly."
"The price could be improved."
"The biggest friction points I have with Splunk Security Essentials are the high license costs and user behavior that causes performance issues due to inappropriate wildcard searches."
"If I could change one thing about Splunk Security Essentials, it would be pricing. I believe they are still very costly as compared to the competition."
"They could add more AI content or AI and machine learning."
"It takes a lot of time to install Splunk Security Essentials. It's not very difficult, but it requires time."
 

Pricing and Cost Advice

"The pricing of Splunk is a bit high."
"Splunk ITSI is expensive."
"It depends on how big an organization is. If we have a lot of resources, the licensing needs to be upgraded. If we have a small environment, the licensing cost is definitely going to be less."
"Splunk ITSI is expensive."
"It would have been good if the product cost was much lower."
"It is interesting. I am not involved that much lately, but if I recall correctly, you license primarily on the volume of data that you are using in Splunk ITSI, but there is no way Splunk can ever check if that is true, so that is interesting. We are not doing it, but someone can pretend to just use 10%, and it would be super cheap. It is tricky, but it is more tricky for Splunk than for us."
"Splunk ITSI is an expensive tool, and we need to purchase the utility license."
"Splunk is pretty expensive, but it gives you a decent insight into the data. It is easy to learn, and ITSI has a great interface. You can run those queries and pass the data. I"
Information not available
report
Use our free recommendation engine to learn which IT Alerting and Incident Management solutions are best for your needs.
909,725 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
16%
Manufacturing Company
10%
Outsourcing Company
9%
Construction Company
7%
Construction Company
18%
Comms Service Provider
11%
Financial Services Firm
11%
Healthcare Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business17
Midsize Enterprise8
Large Enterprise46
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Splunk ITSI (IT Service Intelligence)?
From a pricing perspective, it is not that bad because we get it from a distributor and do not purchase it directly from Splunk. We get it from a distributor who gives the pricing to a partner and ...
What needs improvement with Splunk ITSI (IT Service Intelligence)?
In terms of improvements for Splunk ITSI (IT Service Intelligence), I would suggest adding more out-of-the-box plugins and adapters, especially as there is a high demand for observability and dashb...
What is your primary use case for Splunk ITSI (IT Service Intelligence)?
I use Splunk ITSI (IT Service Intelligence) as a manager of the managers, a tool sitting on top of all the other observability tools. It gets the alerts feed from all the sources such as Splunk Ent...
What is your experience regarding pricing and costs for Splunk Security Essentials?
Our SecOps manager and CISO were more familiar with Splunk, and the price was right. That was probably the primary driver, and we did evaluation as well with strict criteria and Gartner ratings.
What needs improvement with Splunk Security Essentials?
The biggest friction points I have with Splunk Security Essentials are the high license costs and user behavior that causes performance issues due to inappropriate wildcard searches. Additionally, ...
What is your primary use case for Splunk Security Essentials?
My main use case for Splunk Security Essentials is for Enterprise Security, specifically the ES app. Splunk Security Essentials is my primary tool for threat detection and monitoring because as a S...
 

Overview

 

Sample Customers

TransUnion, Cox Automotive, Carnival Cruises, Leidos, Econocom, National Ignition Factory, Entrust Datacard, Molina Healthcare, United States Census Bureau
Information Not Available
Find out what your peers are saying about Splunk ITSI (IT Service Intelligence) vs. Splunk Security Essentials and other solutions. Updated: August 2026.
909,725 professionals have used our research since 2012.