Try our new research platform with insights from 80,000+ expert users

Splunk ITSI (IT Service Intelligence) vs Splunk Security Essentials comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 2, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Splunk ITSI (IT Service Int...
Ranking in IT Alerting and Incident Management
4th
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
50
Ranking in other categories
Application Performance Monitoring (APM) and Observability (10th)
Splunk Security Essentials
Ranking in IT Alerting and Incident Management
14th
Average Rating
8.0
Reviews Sentiment
8.1
Number of Reviews
2
Ranking in other categories
Data Visualization (20th), Security Incident Response (11th)
 

Mindshare comparison

As of May 2025, in the IT Alerting and Incident Management category, the mindshare of Splunk ITSI (IT Service Intelligence) is 4.0%, up from 1.4% compared to the previous year. The mindshare of Splunk Security Essentials is 0.2%, up from 0.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
IT Alerting and Incident Management
 

Featured Reviews

Sunil K R - PeerSpot reviewer
Helps improve our incident response time, and our mean time to resolve, but visibility is limited
In my previous project, I successfully led the end-to-end deployment of a Splunk migration. The process went smoothly thanks in part to Splunk's professional services team. They conducted a thorough assessment, identified all our potential pain points, and developed a tailored solution and migration plan. This comprehensive approach ensured a seamless transition. Our core deployment team consisted of 5 internal members and two specialists from Splunk. Additionally, the project included a project manager and a product owner. We also benefited from the expertise of two professional service consultants and two representatives from the customer's side. An on-site admin architect further provided valuable technical support. Throughout the deployment process, we leveraged support from various resources whenever necessary. This included assistance with configuration changes, deployments, and other related tasks. We also collaborated effectively with our teammates to ensure a smooth and successful implementation.
Srinivas Prudhivi Reddy - PeerSpot reviewer
Enables us to examine the parameters of the events found and take appropriate actions as necessary
Once we've configured our logs, for example, if we need to monitor processes and IP addresses, we ensure these logs are being ingested into our Splunk instance. The logs gathered from various endpoints are then consolidated into our Splunk platform. Once the data is collected, we can create searches and dashboards to analyze it. With these searches and dashboards, we gain insights into events and can make informed decisions based on them. We'll examine the parameters of these events and take appropriate actions as necessary.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The modeling required to setup ITSI has been very helpful in providing us a better understanding and a logical view of our services. The modeling is flexible and can be as granular or high level as our needs dictate."
"The most valuable features are the agility, being able to ingest many data sources with no limitation on capacity."
"The KPS used to automate the integration policy is the most valuable feature of Splunk ITSI."
"Having worked closely with Splunk support engineers, I've observed their high capabilities in resolving issues."
"We save substantial time on monitoring tasks because we don't have to search for what we need. Everything is packed, so you can drill down to the end values by just doing the kit. We don't spend a lot of time on this. Splunk ITSI is easy to use and not time-consuming."
"The root cause analysis is very helpful for us."
"The feature that stood out to me most from Splunk IT Service Intelligence (ITSI) was automated dashboarding or reporting. The solution lists the severity level of issues, and the response times."
"The solution has been stable."
"We are focusing on security to ensure incidents are reported efficiently. In addition to that, for reporting purposes, we are utilizing our dashboards or creating new ones. We will be using free visualization tools for this purpose."
"The network monitoring feature is particularly valuable for gathering information about users, login times, and other statistics."
 

Cons

"We had issues with support that took a long time to resolve."
"Microservices is the only area where Splunk ITSI can be improved. When things come from one EC2 instance to another, there's a lack of exposure to microservices, so we can't know what's happening. Apart from that, it's doing pretty well."
"The end-to-end visibility in Splunk ITSI is limited and has room for improvement."
"One thing ITSI could improve on is the maintenance windows. I have a huge case where I had to implement something related to the maintenance window. If you try to look up the issues in ITSI, you have to check the incidents individually, and putting hundreds of hosts in maintenance can be a hindrance."
"Splunk ITSI should include ease of integration and more templating."
"Predictive analytics, in terms of preventing incidents before they occur, still needs time to mature."
"The UI could be updated. Some elements of the KPI section aren't where you'd expect. It looks like a website from 2010 or maybe older. You can't change some things, like if it doesn't word-wrap well. For example, if you have a long list of KPIs that exceed a character limit, you need to hover over them and wait for the HTML text to pop up to see which KPI it is."
"Some of our customers occasionally require the development of the connectors when there are no native connectors so that we can develop in Python or for customer slash comments as well. If they could adjust that, it would be ideal."
"The price could be improved."
"The reporting feature needs to be more user-friendly."
 

Pricing and Cost Advice

"The pricing of Splunk is a bit high."
"Splunk pricing is high."
"It is interesting. I am not involved that much lately, but if I recall correctly, you license primarily on the volume of data that you are using in Splunk ITSI, but there is no way Splunk can ever check if that is true, so that is interesting. We are not doing it, but someone can pretend to just use 10%, and it would be super cheap. It is tricky, but it is more tricky for Splunk than for us."
"It depends on how big an organization is. If we have a lot of resources, the licensing needs to be upgraded. If we have a small environment, the licensing cost is definitely going to be less."
"Pricing has some room for improvement."
"I would prefer that the price be reduced, as it would be easier to implement it and to sell it."
"Splunk ITSI is expensive."
"Pricing was pretty good, and it is possible to just add on the features we want."
Information not available
report
Use our free recommendation engine to learn which IT Alerting and Incident Management solutions are best for your needs.
850,028 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
21%
Computer Software Company
14%
Government
11%
Manufacturing Company
7%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Splunk ITSI (IT Service Intelligence)?
Pricing can vary significantly based on the selected modules and deployment choices. Splunk ITSI tends to be more expensive compared to some open-source solutions.
What needs improvement with Splunk ITSI (IT Service Intelligence)?
Splunk ITSI could benefit from including more features that other solutions support, such as vulnerability management modules. This would help manage vulnerabilities effectively, allowing my organi...
What is your experience regarding pricing and costs for Splunk Security Essentials?
Pricing and licensing are managed by our vendor management team and are not under my purview.
What needs improvement with Splunk Security Essentials?
The reporting feature needs to be more user-friendly. It would help if it were easier to generate reports similar to other cybersecurity tools. Additionally, more automation in alert systems would ...
What is your primary use case for Splunk Security Essentials?
I use Splunk Security Essentials for monitoring as part of my organization. We use it for our security processes and to gather reports on performance, security, and bottlenecks. It's primarily util...
 

Overview

 

Sample Customers

TransUnion, Cox Automotive, Carnival Cruises, Leidos, Econocom, National Ignition Factory, Entrust Datacard, Molina Healthcare, United States Census Bureau
Information Not Available
Find out what your peers are saying about Splunk ITSI (IT Service Intelligence) vs. Splunk Security Essentials and other solutions. Updated: April 2025.
850,028 professionals have used our research since 2012.