Try our new research platform with insights from 80,000+ expert users

Splunk ITSI (IT Service Intelligence) vs Unit 42 Managed Detection and Response comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Splunk ITSI (IT Service Int...
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
50
Ranking in other categories
Application Performance Monitoring (APM) and Observability (11th), IT Alerting and Incident Management (4th)
Unit 42 Managed Detection a...
Average Rating
0.0
Reviews Sentiment
7.8
Number of Reviews
1
Ranking in other categories
Managed Security Services Providers (MSSP) (60th), Managed Detection and Response (MDR) (42nd)
 

Mindshare comparison

Splunk ITSI (IT Service Intelligence) and Unit 42 Managed Detection and Response aren’t in the same category and serve different purposes. Splunk ITSI (IT Service Intelligence) is designed for IT Alerting and Incident Management and holds a mindshare of 2.9%, up 1.8% compared to last year.
Unit 42 Managed Detection and Response, on the other hand, focuses on Managed Security Services Providers (MSSP), holds 1.5% mindshare, up 0.1% since last year.
IT Alerting and Incident Management
Managed Security Services Providers (MSSP)
 

Featured Reviews

Srinivasulu Soolluru - PeerSpot reviewer
It speeds up incident response by automating alerts and ticket creation
When configuring a dashboard, we can write search criteria. Based on the search criteria, the dashboard shows all the alerts, including the alert time, creation time, and a summary description of the alert. When you add an extra column, such as the user that triggered the alert, the next time he refreshes the dashboard, he wants to know that the alert is acknowledged. We want to improve that comment feature. In the Service Analyzer, we monitor the network infrastructure services and have a KPI for each service. When the value exceeds the threshold value, we can add the colors. For example, we can set it to green when the threshold value is within the limit. If it is red, then the value has passed the threshold. We want more colors in the service analyzer to display all these features.
MohammedSirajuddin - PeerSpot reviewer
Flexible and reduces IT operations but requires local data sovereignty and competitive pricing
I prefer having local data sovereignty. It would be advantageous for Palo Alto to have local data centers across different countries to adhere to this requirement. I also have a concern regarding pricing, which is perceived as high compared to competitors. Improvements should focus on response times and reducing the time taken to reach solutions.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"ITSI includes a feature called a glass table."
"The most valuable feature is the Glass Tables. It gives you a nice, good overview of your KPIs. It's really slick and clean."
"I particularly appreciate two features of Splunk ITSI: data forwarding and the marketplace."
"ITSI's KPI and correlation search aspects are powerful, and the service creation suits the project well. It allows for good segregation of the monitoring solution, and up-to-date quick-time monitoring. We're notified quickly when something goes wrong."
"The service analyzer view and automatic creation of incidents are valuable."
"Having a structure on how to resolve incidents is the most valuable aspect."
"We save substantial time on monitoring tasks because we don't have to search for what we need. Everything is packed, so you can drill down to the end values by just doing the kit. We don't spend a lot of time on this. Splunk ITSI is easy to use and not time-consuming."
"The solution has been stable."
"Unit 42 MDR provides us with managed detection and response functionalities, eliminating the need for capital expenditure since it is an operational expenditure-based service."
"Unit 42 MDR provides us with managed detection and response functionalities, eliminating the need for capital expenditure since it is an operational expenditure-based service."
 

Cons

"It was an intimidating tool for us to jump into at the beginning."
"The UI could be updated. Some elements of the KPI section aren't where you'd expect. It looks like a website from 2010 or maybe older. You can't change some things, like if it doesn't word-wrap well. For example, if you have a long list of KPIs that exceed a character limit, you need to hover over them and wait for the HTML text to pop up to see which KPI it is."
"Splunk ITSI should include ease of integration and more templating."
"Currently, Glass tables in ITSI only display metrics related to KPIs."
"While Splunk has existing add-ons, they are unreliable and do not provide accurate results."
"When configuring a dashboard, we can write search criteria. Based on the search criteria, the dashboard shows all the alerts, including the alert time, creation time, and a summary description of the alert. When you add an extra column, such as the user that triggered the alert, the next time he refreshes the dashboard, he wants to know that the alert is acknowledged. We want to improve that comment feature."
"ITSI could benefit from a security model that would allow operations team members to get involved in model building, KPI implementation, and model maintenance, while maintaining appropriate segregation of duties."
"We'd like them to show more inputs on the dashboard."
"I also have a concern regarding pricing, which is perceived as high compared to competitors."
"I have a concern regarding pricing, which is perceived as high compared to competitors."
 

Pricing and Cost Advice

"It is interesting. I am not involved that much lately, but if I recall correctly, you license primarily on the volume of data that you are using in Splunk ITSI, but there is no way Splunk can ever check if that is true, so that is interesting. We are not doing it, but someone can pretend to just use 10%, and it would be super cheap. It is tricky, but it is more tricky for Splunk than for us."
"I wouldn't say there's been an issue with the solution's pricing because we went through the AWS marketplace and negotiated directly with Splunk."
"Splunk ITSI is expensive; however, with the appropriate use case, it justifies the cost."
"Splunk ITSI is a premium application and comes with a premium price tag."
"Pricing was pretty good, and it is possible to just add on the features we want."
"Splunk ITSI is an expensive tool, and we need to purchase the utility license."
"The cost of the modules is a bit high for non-global companies, making it difficult for them to afford Splunk ITSI."
"It would have been good if the product cost was much lower."
Information not available
report
Use our free recommendation engine to learn which IT Alerting and Incident Management solutions are best for your needs.
862,543 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
19%
Government
11%
Computer Software Company
11%
Manufacturing Company
8%
Manufacturing Company
12%
Insurance Company
10%
Computer Software Company
10%
Marketing Services Firm
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Splunk ITSI (IT Service Intelligence)?
Pricing can vary significantly based on the selected modules and deployment choices. Splunk ITSI tends to be more expensive compared to some open-source solutions.
What needs improvement with Splunk ITSI (IT Service Intelligence)?
Splunk ITSI could benefit from including more features that other solutions support, such as vulnerability management modules. This would help manage vulnerabilities effectively, allowing my organi...
What is your experience regarding pricing and costs for Unit 42 Managed Detection and Response?
I find the pricing to be expensive, especially when compared with competitors who offer significant discounts. Palo Alto has room to become more competitive in its pricing.
What needs improvement with Unit 42 Managed Detection and Response?
I prefer having local data sovereignty. It would be advantageous for Palo Alto to have local data centers across different countries to adhere to this requirement. I also have a concern regarding p...
What is your primary use case for Unit 42 Managed Detection and Response?
Unit 42 is a Managed Detection and Response solution with MDR capabilities. I use it in a managed service context where my organization's security needs are catered to by Palo Alto. Generally, it i...
 

Overview

 

Sample Customers

TransUnion, Cox Automotive, Carnival Cruises, Leidos, Econocom, National Ignition Factory, Entrust Datacard, Molina Healthcare, United States Census Bureau
Information Not Available
Find out what your peers are saying about PagerDuty, Atlassian, Splunk and others in IT Alerting and Incident Management. Updated: June 2025.
862,543 professionals have used our research since 2012.