Try our new research platform with insights from 80,000+ expert users

Splunk ITSI (IT Service Intelligence) vs Splunk Security Essentials comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 2, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Splunk ITSI (IT Service Int...
Ranking in IT Alerting and Incident Management
3rd
Average Rating
8.2
Reviews Sentiment
7.0
Number of Reviews
51
Ranking in other categories
Application Performance Monitoring (APM) and Observability (12th)
Splunk Security Essentials
Ranking in IT Alerting and Incident Management
14th
Average Rating
8.6
Reviews Sentiment
5.9
Number of Reviews
4
Ranking in other categories
Data Visualization (16th), Security Incident Response (11th)
 

Mindshare comparison

As of January 2026, in the IT Alerting and Incident Management category, the mindshare of Splunk ITSI (IT Service Intelligence) is 2.2%, down from 3.2% compared to the previous year. The mindshare of Splunk Security Essentials is 1.4%, up from 0.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
IT Alerting and Incident Management Market Share Distribution
ProductMarket Share (%)
Splunk ITSI (IT Service Intelligence)2.2%
Splunk Security Essentials1.4%
Other96.4%
IT Alerting and Incident Management
 

Featured Reviews

Ahmed Naguib - PeerSpot reviewer
Director at Techpace
Identifying complex diagnostics and alert management improvements needed
The best features of Splunk ITSI (IT Service Intelligence) are the APM, the Application Performance Monitoring, and the diagnostic capabilities. It is state-of-the-art. The intelligent alerting in Splunk ITSI (IT Service Intelligence) is very good. The predictive analysis can give you proactive information about potential bottlenecks that can occur on applications, desk, storage, SQL servers, databases, or other systems. It is very effective. The customizable dashboards in Splunk ITSI (IT Service Intelligence) facilitate our customers because they are highly adaptable. We have multiple types of dashboards, depending on who will be utilizing them, such as engineering, middle management, IT heads, or NOC teams that will be monitoring systems. The metrics I rely on for monitoring in Splunk ITSI (IT Service Intelligence) depend on what kind of asset or CI we are monitoring. For applications, we have the number of concurrent transactions, response time from the database, and write time on the desk. There are multiple parameters and metrics that we utilize in the monitoring part within ITSI.
BM
Information Security Architect at UMMS
Offers a wide range of advanced detection capabilities for identifying suspicious activities
We already talked about Enterprise Security on May 28th.I'm using Splunk Enterprise. We do use SOAR Mission Control, but not AppDynamics or Phantom. We have another freemium app for infrastructure monitoring called ITSI, IT Essentials Work. We also have the ITSI module for virtualization. I would have to rate Splunk Security Essentials a 10 out of 10 because it's free and there's tons of usable content.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I like ITSI's glass tables. They're easy to navigate by clicking through them. The interface isn't that much different from other products I've used. It provides all the information we need in one place."
"The root cause analysis is very helpful for us."
"The most valuable feature is event correlation, which ensures that only one ticket is generated per issue, eliminating duplicates and reducing noise from multiple alerts."
"The most valuable aspect lies in its utilization of predictive analytics to anticipate and prevent incidents within a window of twenty to thirty minutes."
"The feature that stood out to me most from Splunk IT Service Intelligence (ITSI) was automated dashboarding or reporting. The solution lists the severity level of issues, and the response times."
"Splunk ITSI can be easily integrated with the incident management platform. You can automate workflows and certain actions can be taken."
"Splunk ITSI helps us secure our environment by allowing us to create automatons that run when alerts are triggered."
"ITSI's KPI and correlation search aspects are powerful, and the service creation suits the project well. It allows for good segregation of the monitoring solution, and up-to-date quick-time monitoring. We're notified quickly when something goes wrong."
"We are focusing on security to ensure incidents are reported efficiently. In addition to that, for reporting purposes, we are utilizing our dashboards or creating new ones. We will be using free visualization tools for this purpose."
"They have a good catalog of plans to use to resist the attacks."
"I would have to rate Splunk Security Essentials a 10 out of 10 because it's free and there's tons of usable content."
"The network monitoring feature is particularly valuable for gathering information about users, login times, and other statistics."
 

Cons

"We also faced challenges relating to UI development."
"ITSI could benefit from a security model that would allow operations team members to get involved in model building, KPI implementation, and model maintenance, while maintaining appropriate segregation of duties."
"Microservices is the only area where Splunk ITSI can be improved. When things come from one EC2 instance to another, there's a lack of exposure to microservices, so we can't know what's happening. Apart from that, it's doing pretty well."
"Splunk ITSI (IT Service Intelligence) can be improved in terms of the service management function, which is the only drawback, and there are some limitations in terms of event correlation, specifically when correlating between different CIs."
"When we check the service analyzer, and we have custom inputs, there are issues."
"I believe the refresh time should be faster."
"When configuring a dashboard, we can write search criteria. Based on the search criteria, the dashboard shows all the alerts, including the alert time, creation time, and a summary description of the alert. When you add an extra column, such as the user that triggered the alert, the next time he refreshes the dashboard, he wants to know that the alert is acknowledged. We want to improve that comment feature."
"While Splunk has existing add-ons, they are unreliable and do not provide accurate results."
"The reporting feature needs to be more user-friendly."
"They could add more AI content or AI and machine learning."
"The price could be improved."
 

Pricing and Cost Advice

"I know that it is expensive, but I do not think there is another solution that can do similar things for that price."
"It would have been good if the product cost was much lower."
"Pricing has some room for improvement."
"I wouldn't say there's been an issue with the solution's pricing because we went through the AWS marketplace and negotiated directly with Splunk."
"Splunk ITSI is expensive compared to other tools."
"It depends on how big an organization is. If we have a lot of resources, the licensing needs to be upgraded. If we have a small environment, the licensing cost is definitely going to be less."
"Splunk ITSI is expensive."
"Splunk ITSI is a premium application and comes with a premium price tag."
Information not available
report
Use our free recommendation engine to learn which IT Alerting and Incident Management solutions are best for your needs.
880,255 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
17%
Manufacturing Company
10%
Computer Software Company
8%
Government
7%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business11
Midsize Enterprise9
Large Enterprise32
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Splunk ITSI (IT Service Intelligence)?
Pricing can vary significantly based on the selected modules and deployment choices. Splunk ITSI tends to be more expensive compared to some open-source solutions.
What needs improvement with Splunk ITSI (IT Service Intelligence)?
Splunk ITSI (IT Service Intelligence) can be improved in terms of the service management function, which is the only drawback, and there are some limitations in terms of event correlation, specific...
What is your experience regarding pricing and costs for Splunk Security Essentials?
Our SecOps manager and CISO were more familiar with Splunk, and the price was right. That was probably the primary driver, and we did evaluation as well with strict criteria and Gartner ratings.
What needs improvement with Splunk Security Essentials?
I have not used Splunk Security Essentials' customizable dashboards. I have not taken advantage of the pre-built security use cases in Splunk.
What is your primary use case for Splunk Security Essentials?
We use Splunk Security Essentials. We have projects, though not many projects per year. The solution is used to resist cyber attacks. They have a good catalog of plans to use to resist the attacks.
 

Overview

 

Sample Customers

TransUnion, Cox Automotive, Carnival Cruises, Leidos, Econocom, National Ignition Factory, Entrust Datacard, Molina Healthcare, United States Census Bureau
Information Not Available
Find out what your peers are saying about Splunk ITSI (IT Service Intelligence) vs. Splunk Security Essentials and other solutions. Updated: December 2025.
880,255 professionals have used our research since 2012.