No more typing reviews! Try our Samantha, our new voice AI agent.

Splunk ITSI (IT Service Intelligence) vs Splunk Security Essentials comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 2, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Splunk ITSI (IT Service Int...
Ranking in IT Alerting and Incident Management
4th
Average Rating
8.4
Reviews Sentiment
6.6
Number of Reviews
64
Ranking in other categories
Application Performance Monitoring (APM) and Observability (9th)
Splunk Security Essentials
Ranking in IT Alerting and Incident Management
13th
Average Rating
8.6
Reviews Sentiment
4.8
Number of Reviews
6
Ranking in other categories
Data Visualization (12th), Security Incident Response (9th)
 

Mindshare comparison

As of October 2026, in the IT Alerting and Incident Management category, the mindshare of Splunk ITSI (IT Service Intelligence) is 2.0%, down from 2.5% compared to the previous year. The mindshare of Splunk Security Essentials is 1.8%, up from 0.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
IT Alerting and Incident Management Mindshare Distribution
ProductMindshare (%)
Splunk ITSI (IT Service Intelligence)2.0%
Splunk Security Essentials1.8%
Other96.2%
IT Alerting and Incident Management
 

Featured Reviews

DS
Senior Consultant at a consultancy with 10,001+ employees
Service health has been monitored and visual insights support proactive telecom operations
The installation process is the first aspect I dislike about Splunk ITSI (IT Service Intelligence). If you do not configure it correctly, you will encounter issues in the search head. Because we use a distributed environment where each component has its own specific roles, installation is critical and requires careful attention. Splunk ITSI (IT Service Intelligence) is built with many applications. It is a compressed file, and when you extract the Splunk ITSI (IT Service Intelligence) app, you receive approximately 19 apps. Some applications, add-ons, and packages must be installed on specific components. If you do not configure an application correctly, it will not work. Sometimes we encounter issues during installation because of this complexity. I believe the installation process should be more uniform, meaning it could be deployed across all components to avoid post-installation issues. Sometimes after installation, you receive errors, and users cannot access Splunk ITSI (IT Service Intelligence). We have experienced this type of issue due to installation errors. I believe there is currently room for improvement regarding scalability. When we create Glass Tables containing many searches, the Glass Tables sometimes fail due to memory constraints, and we receive error pages. Splunk ITSI (IT Service Intelligence) should have a lightweight version to address these concerns. I would rate current scalability as medium.
reviewer2836941 - PeerSpot reviewer
Assistant Manager at a tech services company with 1-10 employees
Centralized monitoring has given our SOC real-time visibility into security and application activity
When I first implemented Splunk Security Essentials in this environment, it took a week for each log source to onboard and to create use cases and implement the data model, CIM, etc., for production readiness. Training is mandatory, and we need at least the Splunk Security Essentials User certification because it is a very critical resource in the organization, as we are handling security logs. In my organization, Splunk Security Essentials is used not only by the SOC but also for monitoring logs across different teams, as it is important for handling both security and application logs, given its capability to manage unstructured logs. Splunk Security Essentials has dramatically impacted my organization, as without it, we were blind to what is happening from both a security and application perspective, and it provides vital visibility into the organization's operations.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution's scalability is fine."
"It's scalable and expands well."
"Splunk ITSI can be easily integrated with the incident management platform. You can automate workflows and certain actions can be taken."
"Having a structure on how to resolve incidents is the most valuable aspect."
"The most valuable feature is event correlation, which ensures that only one ticket is generated per issue, eliminating duplicates and reducing noise from multiple alerts."
"The predictive analysis feature is quite useful, as it helps identify potential issues before they impact services and allows for proactive action."
"We liked the built-in calculation of health scores."
"Customers have noted the solution helps streamline incident management."
"I would have to rate Splunk Security Essentials a 10 out of 10 because it's free and there's tons of usable content."
"The network monitoring feature is particularly valuable for gathering information about users, login times, and other statistics."
"We are focusing on security to ensure incidents are reported efficiently. In addition to that, for reporting purposes, we are utilizing our dashboards or creating new ones. We will be using free visualization tools for this purpose."
"They have a good catalog of plans to use to resist the attacks."
"Splunk Security Essentials has dramatically impacted my organization, as without it, we were blind to what is happening from both a security and application perspective, and it provides vital visibility into the organization's operations."
"Splunk Security Essentials has impacted my organization in that we have been getting the results that we wanted."
 

Cons

"ITSI currently lacks the capability for automated response, mitigation, and remediation."
"Customer support is adequate, but it could be faster, especially with P1 issues, and having more instructional videos available would help."
"They should make it easier to use. Many people are new to it. It is hard and has a steep learning curve."
"The user interface visualization could be improved."
"We have problems doing upgrades and operating alternate new versions."
"We also faced challenges relating to UI development — being able to get the UI the way we wanted it to look performance-wise. Some of the customization levels of the UI just weren't there."
"If they can somehow integrate it with AI in the near future, it will definitely be a game changer."
"After upgrading Splunk ITSI from version 4.11 to 4.13, the analyzer stopped finding values for KPS and services."
"The reporting feature needs to be more user-friendly."
"The price could be improved."
"If I could change one thing about Splunk Security Essentials, it would be pricing. I believe they are still very costly as compared to the competition."
"It takes a lot of time to install Splunk Security Essentials. It's not very difficult, but it requires time."
"The biggest friction points I have with Splunk Security Essentials are the high license costs and user behavior that causes performance issues due to inappropriate wildcard searches."
"They could add more AI content or AI and machine learning."
 

Pricing and Cost Advice

"Splunk pricing is high."
"It would have been good if the product cost was much lower."
"Splunk is pretty expensive, but it gives you a decent insight into the data. It is easy to learn, and ITSI has a great interface. You can run those queries and pass the data. I"
"Splunk ITSI is expensive."
"I would prefer that the price be reduced, as it would be easier to implement it and to sell it."
"Pricing has some room for improvement."
"Splunk ITSI is a pay-per-use service that is priced fairly based on the amount of data we use."
"The cost of the modules is a bit high for non-global companies, making it difficult for them to afford Splunk ITSI."
Information not available
report
Use our free recommendation engine to learn which IT Alerting and Incident Management solutions are best for your needs.
915,341 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
14%
Financial Services Firm
13%
Manufacturing Company
12%
Construction Company
6%
Construction Company
18%
Financial Services Firm
11%
Comms Service Provider
9%
Healthcare Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business17
Midsize Enterprise8
Large Enterprise46
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Splunk ITSI (IT Service Intelligence)?
From a pricing perspective, it is not that bad because we get it from a distributor and do not purchase it directly from Splunk. We get it from a distributor who gives the pricing to a partner and ...
What needs improvement with Splunk ITSI (IT Service Intelligence)?
Training the database could make Splunk ITSI (IT Service Intelligence) even better for my work. I sometimes feel a lag with Splunk ITSI (IT Service Intelligence). I gave it a nine out of ten.
What is your primary use case for Splunk ITSI (IT Service Intelligence)?
I have been using Splunk ITSI (IT Service Intelligence) for the last two to three years for my data handling. I do IT implementation with strong technical skills. I sometimes use Splunk ITSI (IT Se...
What is your experience regarding pricing and costs for Splunk Security Essentials?
Our SecOps manager and CISO were more familiar with Splunk, and the price was right. That was probably the primary driver, and we did evaluation as well with strict criteria and Gartner ratings.
What needs improvement with Splunk Security Essentials?
The biggest friction points I have with Splunk Security Essentials are the high license costs and user behavior that causes performance issues due to inappropriate wildcard searches. Additionally, ...
What is your primary use case for Splunk Security Essentials?
My main use case for Splunk Security Essentials is for Enterprise Security, specifically the ES app. Splunk Security Essentials is my primary tool for threat detection and monitoring because as a S...
 

Overview

 

Sample Customers

TransUnion, Cox Automotive, Carnival Cruises, Leidos, Econocom, National Ignition Factory, Entrust Datacard, Molina Healthcare, United States Census Bureau
Information Not Available
Find out what your peers are saying about Splunk ITSI (IT Service Intelligence) vs. Splunk Security Essentials and other solutions. Updated: September 2026.
915,341 professionals have used our research since 2012.