No more typing reviews! Try our Samantha, our new voice AI agent.
Ahmed Naguib - PeerSpot reviewer
Director at Techpace
Reseller
Top 5
Sep 14, 2025
Identifying complex diagnostics and alert management improvements needed
Pros and Cons
  • "The best features of Splunk ITSI (IT Service Intelligence) are the APM, the Application Performance Monitoring, and the diagnostic capabilities; it is state-of-the-art."
  • "Splunk ITSI (IT Service Intelligence) can be improved in terms of the service management function, which is the only drawback, and there are some limitations in terms of event correlation, specifically when correlating between different CIs."

What is our primary use case?

I recommend Splunk ITSI (IT Service Intelligence) for large enterprises and the government sector.

What is most valuable?

The best features of Splunk ITSI (IT Service Intelligence) are the APM, the Application Performance Monitoring, and the diagnostic capabilities. It is state-of-the-art.

The intelligent alerting in Splunk ITSI (IT Service Intelligence) is very good. The predictive analysis can give you proactive information about potential bottlenecks that can occur on applications, desk, storage, SQL servers, databases, or other systems. It is very effective.

The customizable dashboards in Splunk ITSI (IT Service Intelligence) facilitate our customers because they are highly adaptable. We have multiple types of dashboards, depending on who will be utilizing them, such as engineering, middle management, IT heads, or NOC teams that will be monitoring systems.

The metrics I rely on for monitoring in Splunk ITSI (IT Service Intelligence) depend on what kind of asset or CI we are monitoring. For applications, we have the number of concurrent transactions, response time from the database, and write time on the desk. There are multiple parameters and metrics that we utilize in the monitoring part within ITSI.

What needs improvement?

Splunk ITSI (IT Service Intelligence) can be improved in terms of the service management function, which is the only drawback, and there are some limitations in terms of event correlation, specifically when correlating between different CIs. If this were fixed, it would be an amazing function, with cross-correlation between different CIs.

I would appreciate additional features in the next release of Splunk ITSI (IT Service Intelligence) such as cloud infrastructure monitoring including CICDs, Kubernetes, and similar technologies. This would be brilliant.

For how long have I used the solution?

I have been working with Splunk ITSI (IT Service Intelligence) for four years now, or possibly more.

Buyer's Guide
Splunk ITSI (IT Service Intelligence)
September 2026
Learn what your peers think about Splunk ITSI (IT Service Intelligence). Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,287 professionals have used our research since 2012.

Which other solutions did I evaluate?

If you are looking for only a shallow solution, there are other alternative options that can be useful for such purposes.

What other advice do I have?

Other Splunk products are much better, including Splunk ITSI (IT Service Intelligence), EPM, Enterprise Security, and core. Everything is perfect.

It is not suitable for smaller companies because they do not need it and it is expensive. It will be very expensive and complex for them.

The implementation process for Splunk ITSI (IT Service Intelligence) is complex, but this is typical for this type of product.

I do not utilize its incident management features much; we typically integrate Splunk ITSI (IT Service Intelligence) with other ITSM solutions for incident management. We do not utilize the service management modules because it is not what it is meant to do. We only use it for data diagnostic, alert management, performance, proactive monitoring, diagnostic, and event correlations related to performance or availability.

The impact of ITSI's predictive analytics on decision-making processes is very good.

Concerning performance, scalability, and interface, everything is perfect.

On a scale of 1-10, I rate this solution a 9.

Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
Deekshit Kalakuntla - PeerSpot reviewer
Lead Data Center Operations Technician at a consultancy with 11-50 employees
Real User
Top 20
Mar 30, 2026
Intelligent alerting has reduced noise and provides proactive insights into critical incidents
Pros and Cons
  • "The predictive analysis feature is quite useful, as it helps identify potential issues before they impact services and allows for proactive action."
  • "One of the main downsides is the complexity of configuration and maintenance, especially when dealing with large-scale environments."

What is our primary use case?

I use it to investigate research on logs and data.

What is most valuable?

One of the main downsides is the complexity of configuration and maintenance, especially when dealing with large-scale environments.

I use intelligent alerting, and it is very effective in reducing noise and prioritizing critical incidents based on impact.

The predictive analysis feature is quite useful, as it helps identify potential issues before they impact services and allows for proactive action.

The customizable dashboards are very helpful and provide great visibility. Though, configuring them can take some time to align with specific business needs.

Overall, it is quite stable, though occasionally lag can occur during heavy data processing or large dashboard loads.

It is highly scalable and can handle large volumes of data efficiently, as long as the infrastructure is properly sized and optimized.

What needs improvement?

One of the main downsides is the complexity of configuration and maintenance, especially when dealing with large-scale environments.

The pricing is on the higher side, especially for large deployments. It is justified by the depth of insights and customization it offers.

For how long have I used the solution?

I have almost two years of experience with Splunk ITSI (IT Service Intelligence).

What do I think about the stability of the solution?

Overall, it is quite stable, though occasionally lag can occur during heavy data processing or large dashboard loads.

What do I think about the scalability of the solution?

It is highly scalable and can handle large volumes of data efficiently, as long as the infrastructure is properly sized and optimized.

On a scale from one to ten, I would rate scalability around nine because it adapts well to growing data and user demands.

How are customer service and support?

I have contacted their technical support a few times, and they were quite responsive and helpful in resolving configuration issues.

I rate them around an eight out of ten for their responsiveness and technical expertise.

Which solution did I use previously and why did I switch?

Alternative tools include Dynatrace and AppDynamics, which offer similar monitoring and performance insights.

How was the initial setup?

The initial deployment can be challenging because it requires proper configuration and data mapping. However, once setup is done, it runs smoothly.

It takes around a few weeks to fully deploy and fine-tune the configuration for optimal performance.

Which other solutions did I evaluate?

Alternatives include Dynatrace and AppDynamics, which offer similar monitoring and performance insights.

I would choose AppDynamics and Splunk ITSI (IT Service Intelligence) because of its flexibility and strong correlation capabilities across complex IT environments.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Mar 30, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Splunk ITSI (IT Service Intelligence)
September 2026
Learn what your peers think about Splunk ITSI (IT Service Intelligence). Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,287 professionals have used our research since 2012.
Systems Engineer at a tech consulting company with 1,001-5,000 employees
Real User
Top 20
Mar 25, 2026
Intelligent monitoring has improved workload prediction and optimized resource utilization
Pros and Cons
  • "It has saved a lot of time, made things more efficient, made budgeting easy, and made it enjoyable to learn and use as a tool."
  • "Splunk ITSI (IT Service Intelligence) can be improved through alerts and additional features."

What is our primary use case?

My main use is monitoring. We use Splunk ITSI (IT Service Intelligence) to predict workloads for a very big bank in Kenya. The client consumes their compute environment at either 80% or 60%, which helps us in monitoring.

How has it helped my organization?

It has saved the organization money by maximizing resource utilization so the company does not have to buy a lot of infrastructure if they do not need it. The infrastructure is there, and you can easily predict the workloads and distribute it evenly.

What is most valuable?

The best features Splunk ITSI (IT Service Intelligence) offers include prediction because you can get to know the resource utilization, and you can have an idea from a budgeting perspective of how many resources you will need at any given time, which helps the team in planning and budgeting.

It has saved a lot of time, made things more efficient, made budgeting easy, and made it enjoyable to learn and use as a tool. Installing it is easy, and using it is simpler than most other tools in the market. Splunk ITSI (IT Service Intelligence) is an easy tool to use, an easy platform to use, and it is simple to upscale and learn, so the team loves using it.

What needs improvement?

Splunk ITSI (IT Service Intelligence) can be improved through alerts and additional features. I use it more on the Linux side, and for Windows users, the Windows version is not as good as the Linux version, so more work needs to be done on the Windows version.

For how long have I used the solution?

I have used Splunk ITSI (IT Service Intelligence) for two years.

What do I think about the stability of the solution?

In my experience, Splunk ITSI (IT Service Intelligence) is very stable.

What do I think about the scalability of the solution?

Splunk ITSI (IT Service Intelligence)'s scalability is great because it is something you can deploy in the public cloud.

How are customer service and support?

Customer support for Splunk ITSI (IT Service Intelligence) is great, especially when getting it from a partner.

Which solution did I use previously and why did I switch?

I have used IBM Instana previously, but Splunk ITSI (IT Service Intelligence) has more features and is more enterprise-focused than IBM Instana, which was more SMB-oriented.

How was the initial setup?

Installing it is easy, and using it is simpler than most other tools in the market. Splunk ITSI (IT Service Intelligence) is an easy tool to use, an easy platform to use, and it is simple to upscale and learn, so the team loves using it.

What about the implementation team?

We are a partner and reseller of this vendor, so we have a business relationship with them beyond just being a customer.

What's my experience with pricing, setup cost, and licensing?

From a pricing perspective, it is not that bad because we get it from a distributor and do not purchase it directly from Splunk. We get it from a distributor who gives the pricing to a partner and who then gives it to us. The pricing could be lowered because it is quite expensive.

Which other solutions did I evaluate?

Before choosing Splunk ITSI (IT Service Intelligence), I evaluated IBM Instana and one more solution from Forcepoint.

What other advice do I have?

Splunk ITSI (IT Service Intelligence) is a great tool. My advice to others looking into using Splunk ITSI (IT Service Intelligence) is that it is a great tool to use, and you should get resources who can handle the product. I would rate this product 9 out of 10.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Mar 25, 2026
Flag as inappropriate
PeerSpot user
Senior consultant at a tech services company with 51-200 employees
Consultant
Top 10
Mar 26, 2025
Enables comprehensive event management and improves organizational security through efficient alert correlation
Pros and Cons
  • "Having worked closely with Splunk support engineers, I've observed their high capabilities in resolving issues."
  • "Splunk ITSI could benefit from including more features that other solutions support, such as vulnerability management modules."

What is our primary use case?

Splunk ITSI (IT Service Intelligence) is primarily used for managing alerts and events. It helps me monitor different APIs in inbound and outbound scenarios and triggers alerts. The tool is primarily used to handle threat intelligence and manage event alerts, despite certain limitations like false positives.

How has it helped my organization?

Splunk ITSI has enabled us to better manage events and alerts, aiding in quicker data retrieval and enhanced system uptime. Its ability to correlate multiple event sources allows for comprehensive integration, which has been valuable in improving our organization's security posture.

What is most valuable?

Splunk ITSI allows for integration with threat intelligence, enabling my organization to correlate more than two events for generating alerts. It has a swift data ingestion and retrieval capability due to its robust query language. The system helps reduce data loss and improve event management, offering a platform for various deployment models. The global trust in its capabilities is evident, especially given the preference by financial sectors. Additionally, having features like IT Service Intelligence enhances our organization by providing actionable insights quickly, which is crucial for operational efficiency.

What needs improvement?

Splunk ITSI could benefit from including more features that other solutions support, such as vulnerability management modules. This would help manage vulnerabilities effectively, allowing my organization to track patch management and compliance more thoroughly. It would be beneficial to include a feature that provides comprehensive vulnerability management similar to open-source solutions.

For how long have I used the solution?

I have been working with Splunk ITSI (IT Service Intelligence) for nearly two and a half years.

What do I think about the stability of the solution?

Splunk ITSI is quite stable, and I would rate its stability at around eight point five to nine. The setup, however, must be done correctly as incorrect deployment can lead to issues.

What do I think about the scalability of the solution?

Splunk is highly scalable, with the ability to expand efficiently. I would rate its scalability at nine.

How are customer service and support?

Having worked closely with Splunk support engineers, I've observed their high capabilities in resolving issues. The technical support is excellent, and I would rate it at ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Previously, we have used other solutions like Wazuh and IBM QRadar. We recommend Wazuh primarily due to its lower cost and robust capabilities, although it may lack in certain areas where Splunk ITSI excels.

How was the initial setup?

The initial setup for Splunk ITSI can be a complex process, especially when compared to the simplicity of open-source solutions like Wazuh.

What's my experience with pricing, setup cost, and licensing?

Pricing can vary significantly based on the selected modules and deployment choices. Splunk ITSI tends to be more expensive compared to some open-source solutions.

Which other solutions did I evaluate?

We have evaluated several solutions, including Wazuh, IBM QRadar, and other open-source platforms.

What other advice do I have?

Overall, I would rate Splunk ITSI at nine or nine point two. I would recommend it for enterprise-level organizations due to its cost implications; smaller companies may prefer open-source solutions to reduce expenses. The solution could improve by integrating more vulnerability management features. I would rate the overall solution at nine.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Sunil K R - PeerSpot reviewer
Senior Software Engineer at Wipro Limited
Real User
May 12, 2024
Helps improve our incident response time, and our mean time to resolve, but visibility is limited
Pros and Cons
  • "The most valuable features are the service analyzer and Glass Tables."
  • "The end-to-end visibility in Splunk ITSI is limited and has room for improvement."

What is our primary use case?

We use Splunk ITSI to monitor the different stages, spaces, and processes of payment operation.

How has it helped my organization?

Splunk helps us improve our incident response time. We have a dedicated observability monitoring team that continuously monitors our systems for failures or delays in payments, 24/7. This monitoring generates alerts that we use to identify potential issues. We have established SLAs for all of these issues. Splunk allows us to alert the appropriate people well in advance of a potential breach, so they can resolve the issue faster and minimize downtime.

I would rate Splunk's predictive analytics for preventing incidents an 8 out of 10.

Splunk ITSI has helped reduce our mean time to resolve.

What is most valuable?

The most valuable features are the service analyzer and Glass Tables.

What needs improvement?

Since ITSI is primarily used for monitoring-related services, it would be beneficial if Splunk offered pre-built dashboards or a drag-and-drop interface for creating custom dashboards. This would simplify the process for users, especially for monitoring basic services like Windows and Linux servers. Currently, Splunk doesn't provide this functionality, requiring users to write queries and build dashboards manually. Including pre-built panels would significantly enhance the value of Splunk for ITSI users.

The end-to-end visibility in Splunk ITSI is limited and has room for improvement.

For how long have I used the solution?

I have been using Splunk ITSI for over 1 year.

What do I think about the stability of the solution?

Splunk is generally considered stable when deployed on-premises. However, its performance on cloud platforms like AWS or others may vary.

I would rate the stability 7 out of 10.

The resilience of Splunk is based on how well it performs on high loads so I would rate it 7 out of 10.

What do I think about the scalability of the solution?

I would rate the scalability 9 out of 10.

How are customer service and support?

I am dissatisfied with the customer support team's response times. When we submit a ticket for a high-priority incident, it takes Splunk support approximately 2 hours to respond and connect with us. We have consistently experienced these delays on multiple occasions.

Additionally, when encountering issues with core configuration or out-of-the-box features, tickets are frequently reassigned to different representatives. This handoff process necessitates us to explain the problem repeatedly, which is frustrating and time-consuming.

How would you rate customer service and support?

Neutral

How was the initial setup?

In my previous project, I successfully led the end-to-end deployment of a Splunk migration. The process went smoothly thanks in part to Splunk's professional services team. They conducted a thorough assessment, identified all our potential pain points, and developed a tailored solution and migration plan. This comprehensive approach ensured a seamless transition.

Our core deployment team consisted of 5 internal members and two specialists from Splunk. Additionally, the project included a project manager and a product owner. We also benefited from the expertise of two professional service consultants and two representatives from the customer's side. An on-site admin architect further provided valuable technical support.

Throughout the deployment process, we leveraged support from various resources whenever necessary. This included assistance with configuration changes, deployments, and other related tasks. We also collaborated effectively with our teammates to ensure a smooth and successful implementation.

What about the implementation team?

For the implementation, we had a consultant from Splunk in-house.

What's my experience with pricing, setup cost, and licensing?

Splunk ITSI is expensive. While tools like Grafana offer a significantly lower cost around 30 percent of Splunk's price, their capabilities are more limited. Splunk can ingest and store a much larger volume of raw data up to 50 percent compared to Grafana's 15 percent. This translates to greater observability but at a higher price point.

Splunk ITSI is worth the cost.

Which other solutions did I evaluate?

I compared Grafana, New Relic, and Dynatrace to understand their competitive landscape. Splunk was the most impressive option, except for its pricing.

What other advice do I have?

I would rate Splunk ITSI 7 out of 10.

For organizations already using a different APM solution, Splunk ITSI offers a compelling alternative. While other tools might focus on onboarding metrics, Splunk ITSI prioritizes log data analysis for deeper insights. In addition to ITSI's capabilities, a Splunk Enterprise license unlocks log monitoring functionalities. This provides a comprehensive solution, and if you plan to migrate to Splunk Enterprise Security in the future, you'll be well-positioned. By purchasing a single Splunk Enterprise license and the ITSI and Enterprise Security premium apps, you'll gain a one-stop shop for all your event management, internal monitoring, and APM observability needs.

Splunk ITSI is deployed in multiple site clusters and located in multiple data centers. We have around 500 users.

Platform maintenance is handled by the Linux team. We take care of everything else.

I recommend Splunk ITSI to those looking to implement ITSI.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2518416 - PeerSpot reviewer
Sr. Splunk Admin / Developer Engineer at a financial services firm with 10,001+ employees
Real User
Aug 4, 2024
We can use end-to-end visibility and analytics to allocate resources more precisely
Pros and Cons
  • "Splunk's intuitive interface and scalability make it accessible to non-technical users, and its capacity to monitor every millisecond of data across multiple applications is truly impressive."
  • "While Splunk has existing add-ons, they are unreliable and do not provide accurate results."

What is our primary use case?

I have experience utilizing Splunk ITSI in financial institutions and federal government settings. As a Splunk administrator at a bank, I focus on the platform's administration and development aspects. We are migrating from an on-premises environment to the cloud, leveraging Splunk ITSI to provide a unified view of the client's infrastructure. Through ITSI-generated reports, we are developing a strategic roadmap to guide our clients' IT journey.

How has it helped my organization?

End-to-end visibility simplifies our configurations by allowing us to index or search at the cluster level. We can utilize multiple indexers or split the workload as needed. For instance, long-running queries exceeding 15 minutes can be removed from the main list, improving efficiency for other users.

Splunk ITSI is a powerful tool for predictive data analysis. When we create and test KPIs within ITSI, it becomes significantly easier to set targets. For instance, if a system's memory capacity is 100 GB and usage consistently approaches or exceeds 80 to 90 percent, ITSI can generate alerts, visualize in a dashboard, and send notifications to the team. This proactive monitoring prevents potential issues. Similarly, ITSI can identify performance bottlenecks in search queries, allowing workload distribution to optimize system efficiency. The entire environment becomes transparent, simplifying tasks for developers and users alike. Regarding user criteria, ITSI offers a tree diagram visualization to easily understand data distribution across indexes, source types, business units, states, and communities with a single click.

Splunk ITSI enables us to allocate resources more precisely to meet demand. Its unified view provides full information in one location, allowing me to monitor index CPU and memory usage, injection rates, and individual user data. While gathering this information might take around ten minutes, the streamlined process significantly simplifies my work.

Splunk has significantly streamlined our incident management process. Its ability to analyze usage, memory consumption, and other environmental factors makes it superior to other tools, allowing us to delve deeper into complex issues. Regardless of length, we can effortlessly examine any log and pinpoint the exact cause of problems, such as UI errors or system failures. We can quickly identify code changes, root causes, and error origins by simply writing a query, providing invaluable insights that accelerate problem resolution and enhance overall system reliability.

It has been instrumental in reducing the overall volume of incidents by automatically triggering alerts when potential issues are detected before they escalate into full-blown incidents. This proactive approach simplifies data analysis and enables us to identify and rectify errors before they impact our systems. Consequently, we can more confidently implement changes or updates without fear of unforeseen complications, as ITSI helps us prevent errors from occurring in the first place.

Splunk ITSI has helped reduce our alert noise by ten percent and improved the mean time to detect down to ten minutes.

Our mean time to remediate is less than one hour when using Splunk ITSI.

We've implemented automation using Splunk, replacing multiple tools previously used for backend testing. We integrated Splunk with ServiceNow to automatically send alerts to the team whenever issues arise. This eliminates the need for manual ticket creation and assignment, streamlines the process, and ensures timely responses, saving us around ten hours weekly.

Splunk has helped us significantly reduce downtime, manpower costs, and the penalties for missing service level agreements. Previously, we relied on two to three people, primarily from the testing team, to manage these issues. By implementing Splunk, we've decreased staffing needs while improving workflow efficiency and reducing overall costs.

What is most valuable?

Splunk impressed me because it can monitor and modify live data flexibly, generating live data, reports, alerts, or dashboards as needed. Its single-pane-of-glass view provides a full overview of the entire environment, and its easy ingestion of diverse data sources, such as databases, AWS, or any cloud platform, is remarkable. Additionally, Splunk's intuitive interface and scalability make it accessible to non-technical users, and its capacity to monitor every millisecond of data across multiple applications is truly impressive.

What needs improvement?

Some developers struggle to write accurate queries, often inputting incorrect text or using asterisks in the source or index, which can significantly degrade search performance and overwhelm the queues. To prevent this, I suggest implementing a system that warns users about incorrect syntax or automatically corrects errors, particularly for complex queries like regular expressions. While Splunk has existing add-ons, they are unreliable and do not provide accurate results. Improving query autocorrection and regular expression handling would be beneficial.

For how long have I used the solution?

I have been using Splunk ITSI for eight years.

What do I think about the stability of the solution?

I have frequently observed Splunk ITSI experiencing lagging and crashing issues. As a result, several customers have transitioned from Splunk to Elk and other alternatives.

What do I think about the scalability of the solution?

I would rate the scalability of Splunk ITSI eight out of ten.

How are customer service and support?

The response time and quality of technical support vary between P1 and P2 levels. For instance, our dashboard, containing 120 panels, experiences significant lag. When reported, support prioritizes issues differently; dashboard loading, while crucial for customer interaction and satisfaction, is deemed less important to them. This discrepancy in perspective leads to delayed responses, impacting our ability to provide a seamless customer experience.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We utilized Kibana, Elk, Cribl, and Tableau for our analysis. Elk, in particular, excelled in certain areas compared to other tools. Our business team previously compared Elk and Splunk, finding Elk to be faster. I observed that Splunk typically had a higher user count, while Elk's user base was smaller. This difference and the reduced search and checking workload in Elk compared to Splunk influenced our decision. Some customers migrated applications to Elk due to its accurate log-checking capabilities despite encountering minor challenges.

How was the initial setup?

Initial Splunk ITSI deployment is straightforward, especially if you are familiar with Linux-based unzip commands. With all prerequisites, a single knowledgeable person can typically complete the process within 40 minutes.

What other advice do I have?

I would rate Splunk ITSI eight out of ten.

I suggest using Splunk because the live data is good. The market is constantly evolving, with new applications and alternatives emerging yearly. Splunk offers a full suite of tools and add-ons that can match or exceed the capabilities of these alternatives at a similar cost. Although Splunk may be more expensive, it provides a robust cloud-based solution and can significantly simplify data management and analysis tasks, ultimately improving efficiency.

End users do not need to perform maintenance; however, as administrators, we are responsible for monitoring the environment for updates and changes.

Users familiar with Splunk's flexibility and features will more easily experiment and envision how the solution can best fit their organization's needs.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Senior Consultant at North Swindon Practice Group Surgery
Real User
Aug 4, 2024
The KPI and correlation search aspects are powerful, and the service creation suits the project well
Pros and Cons
  • "ITSI's KPI and correlation search aspects are powerful, and the service creation suits the project well. It allows for good segregation of the monitoring solution, and up-to-date quick-time monitoring. We're notified quickly when something goes wrong."
  • "The UI could be updated. Some elements of the KPI section aren't where you'd expect. It looks like a website from 2010 or maybe older. You can't change some things, like if it doesn't word-wrap well. For example, if you have a long list of KPIs that exceed a character limit, you need to hover over them and wait for the HTML text to pop up to see which KPI it is."

What is our primary use case?

We use ITSI in the health industry. In the UK, the NHS currently uses ITSI as one of its monitoring sources of information. In ITSI, service components are based around each area of the NHS. For any solutions that have been digitally transformed and require monitoring related to our vaccination campaigns, the logs are ingested through Splunk and monitored through ITSI.

How has it helped my organization?

We realized ITSI's benefits immediately after it was deployed. When the COVID pandemic broke out, it kicked off a lot of crazy stuff within the UK. Having a powerful tool to aggregate data and allow real-time monitoring helped our campaign.

ITSI can help us right-size resources, but it depends on how you do things. We have a culture, and Splunk told us not to do this because they have different methods and stuff. In ITSM, you skim what you need at the source and then push that into Splunk. Having that as the centralized logging analytic is great for that, especially when so many things are tied to ingestion, storage, etc. However, for what we do, it leaves much to be desired. You're talking about an enterprise solution on the scale of the NHS with multiple people, contractors, and all these moving parts. Some services do it well where they only send in what you need. Some services just dump everything. You've got a load of load of logs. We can right size appropriately, but it's just yeah. For us, it's it's not really done now as well, I think.

ITSI has helped us streamline our incident management. We have a 24/7 service team working around the clock, responding to alerts that Splunk produces. It's linked to ServiceNow, our service management tool. When the team inputs all the information from Splunk into these tickets, they're raised in ServiceNow. Previously, we used software called Cherwell that looked horrendous. This helps bring the package together.

We've reduced our alerts, but it requires a conscious effort to configure them. That depends on how you use the platform. It goes back to getting the right metrics out of the logs that you're producing. The tool itself is powerful, but if you don't use it properly, things can be a bit noisy, and this is quite noisy, whereas that's down to our configuration sometimes.

Reducing alert noise also takes some tweaking. You've got KPIs and correlation searches that are great for real-time monitoring, but if you set them up immediately, you will get a lot of noise anyway. It depends on how you configure it. They have a couple of tools in the forwarders to say you're only ingesting alert logs or error logs, so you pick up on whatever those error logs would trigger.

It would help to give you accuracy in your ITSI alert noise. However, it might get a bit noisy if you've got more than that and they're not configured into the perfect use case you need. Overall, it's been a conscious effort to ensure we've got our stuff configured right.

It has reduced our mean detection time. For Microsoft/CloudStrike stuff, we can have an SLA as short as three minutes. The feeds are coming in quickly, so our detection time is between three and 10 minutes. For major outages, an SLA of a few minutes is good, especially when it's not a cyber-level threat. 

The resolution time is determined by how quickly we can pass the detection along to the IT team and triage the logs to determine the issue. We've had quite quick resolutions because everything's partitioned in a way where it is specifically service-bound. You can look through the data and specific areas. You can optimize these things.  The search system in Splunk is powerful and helps speed up resolutions. 

ITSI helps to automate routine tasks. That's what the safe searches are for. It's a complete package with Splunk Cloud and ITSI for deeper drill-downs, but not everyone can access the ITSI dashboard all day. Automation helps us get these alert structures, especially at night. When you've got a file that's meant to come in at 3 a.m., you don't need someone waiting around to look at that. 

This is what those alerts and automation are for. You can put custom wrappers around stuff. It's a custom output. However, Splunk is trying to make something more standardized at the moment. It saves our IT services multiple hours a week because you don't have to do tasks or sit and look through dashboards to ensure everything is all right. These constant checks every five minutes add up over the week, so that equals tens of hours a week for a lot of different services.

What is most valuable?

ITSI's KPI and correlation search aspects are powerful, and the service creation suits the project well. It allows for good segregation of the monitoring solution and up-to-date quick-time monitoring. We're notified quickly when something goes wrong.

The end-to-end visibility is excellent. A lot of the information we get is from the cloud, and the data pipelines we introduce have a clear log trail, so it's easy to pinpoint where it goes wrong. 

What needs improvement?

The UI could be updated. Some elements of the KPI section aren't where you'd expect. It looks like a website from 2010 or maybe older. You can't change some things, like if it doesn't word-wrap well. For example, if you have a long list of KPIs that exceed a character limit, you need to hover over them and wait for the HTML text to pop up to see which KPI it is.

Packaging synthetic monitoring in ITSI would be good. I'd also like a complete package for doing health checks. It would also be nice if Splunk standardized the add-ons. Splunk relies on these add-ons that users build. It's like the App Store. People put time and effort into these custom things, and if they get big enough, Splunk will purchase them and take them over. 

For example, we have a custom Slack output. It'd be good if they put some effort into stuff like that because it's useful. Instead, we're putting custom wrappers around stuff, but why isn't this a thing produced by this massive platform that costs so much? They recently partnered with Cisco and don't have any plans to improve ITSI in that area. It feels like they could do more.

For how long have I used the solution?

I have used Splunk ITSI for two and a half years.

What do I think about the stability of the solution?

Splunk ITSI is generally stable. It's the system that has problems. When we have problems, we escalate them to a higher authority, who sorts everything out. We've only experienced two big glitches with the product and indexes not performing as they need to be. 

What do I think about the scalability of the solution?

ITSI is quite scalable. When we have problems, we can discuss them with our Splunk case manager at biweekly meetings. We might need to add some more indexing capability. With the team's support, it's easy to add new indexes and scale up.

How are customer service and support?

I rate Splunk support five out of 10. The support quality leaves much to be desired because ITSI support can be outsourced. If you're dealing with regulations that limit data access to people and entities within the country, outsourced support can cause problems. We've had a couple of calls outsourced to India, and they couldn't access the data because they weren't in the UK.  

When we've received local support from professional services, they've been helpful. Also, sometimes, we've asked a few questions and it didn't feel like we got a real answer or the answer was that we essentially had to solve the issue ourselves. 

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I've used New Relic and Dynatrace. They have good visualizations and use similar processing languages. However, you can get locked into Splunk because other competitors aren't as powerful. Though Splunk is expensive, it's a powerful platform. 

What's my experience with pricing, setup cost, and licensing?

Splunk ITSI is an expensive solution. Splunk probably doesn't save us money because it's one of the most expensive monitoring solutions on the market. This isn't a tool to save money. You purchase this to improve the efficacy of your service department. This is especially true now that Cisco has acquired them. Cisco is notorious for its high prices.

Which other solutions did I evaluate?

There's another called LogicMonitor that has better metrics and observability, but we found that it lacks as much power as Splunk. We're heavily in favor of Splunk.

What other advice do I have?

I rate Splunk ITSI nine out of 10 and would recommend it, depending on the use case. If someone wants to switch, it comes down to a financial decision. You need to compare your current platform's capabilities to what Splunk can offer you. If it's a perfect match, then I would say go for it. 

Sometimes, there's a steep learning curve, but you get out of it what you put into it. The visualizations are great, and the ITSI search function enables you to narrow down log analytics well. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2879574 - PeerSpot reviewer
Senior Data Engineer at a tech vendor with 10,001+ employees
Real User
Top 20
Jul 28, 2026
Predictive dashboards have improved service error monitoring and data-driven decision making
Pros and Cons
  • "The data I got from Splunk ITSI (IT Service Intelligence) and the information provided by it is what I like most about the dashboarding and predictive features, and Splunk ITSI (IT Service Intelligence) made it easier for me to get data and to work on that, which has positively impacted my organization."
  • "Training the database could make Splunk ITSI (IT Service Intelligence) even better for my work."

What is our primary use case?

I have been using Splunk ITSI (IT Service Intelligence) for the last two to three years for my data handling.

I do IT implementation with strong technical skills. I sometimes use Splunk ITSI (IT Service Intelligence) as a business analyst. I use the technical expertise in software development and work on post-launch documentation, initial setup, and making some RFP.

I sometimes use Splunk ITSI (IT Service Intelligence) for API as well. I need to check the service error rate and predictive analysis. I have worked with predictive analysis in Splunk ITSI (IT Service Intelligence), mostly during my dashboarding, and I take help from it.

What is most valuable?

The data I got from Splunk ITSI (IT Service Intelligence) and the information provided by it is what I like most about the dashboarding and predictive features. Splunk ITSI (IT Service Intelligence) made it easier for me to get data and to work on that, which has positively impacted my organization.

What needs improvement?

Training the database could make Splunk ITSI (IT Service Intelligence) even better for my work.

I sometimes feel a lag with Splunk ITSI (IT Service Intelligence). I gave it a nine out of ten.

For how long have I used the solution?

I have been working here for the last eight years.

What do I think about the stability of the solution?

Splunk ITSI (IT Service Intelligence) is stable in my experience.

What do I think about the scalability of the solution?

Splunk ITSI (IT Service Intelligence) works good for me. Everything seems good when I use it. When I need something, I search for it and I get it.

How are customer service and support?

Customer support for Splunk ITSI (IT Service Intelligence) is really good. I have no issue with that.

Which solution did I use previously and why did I switch?

I did not previously use a different solution before Splunk ITSI (IT Service Intelligence).

What was our ROI?

I have not seen anything regarding return on investment from using Splunk ITSI (IT Service Intelligence). I am a developer and I am using it.

Which other solutions did I evaluate?

It is not my work to evaluate other options before choosing Splunk ITSI (IT Service Intelligence). The pre-sales team decides on that. We just got to work on that.

What other advice do I have?

Everything is going good with Splunk ITSI (IT Service Intelligence). The R&D team is doing good work. They are analyzing and doing updates, which is good for me. Splunk ITSI (IT Service Intelligence) has done my job.

Governance and security is good, which I found in Splunk ITSI (IT Service Intelligence). I do not have any issue with that.

Regarding accuracy, I only trust the AI data in Splunk ITSI (IT Service Intelligence) at ninety percent. The rest I need to check. I give it a ninety percent on that. For every AI, I feel the same.

I gave Splunk ITSI (IT Service Intelligence) an overall rating of nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jul 28, 2026
Flag as inappropriate
PeerSpot user
Ravikranth Telekarapu - PeerSpot reviewer
Splunk Engineer at Prudent Technologies and Consulting, Inc.
Real User
Top 20
Oct 7, 2024
Provides good visibility, reduces alert noise, and improves detection
Pros and Cons
  • "The most valuable feature is event correlation, which ensures that only one ticket is generated per issue, eliminating duplicates and reducing noise from multiple alerts."
  • "While integrating services and KPIs in ITSI is straightforward, I found it challenging to analyze them with the service analyzers; specifically, using the deep dive feature to pinpoint the exact source and time of an issue proved difficult."

What is our primary use case?

We used Splunk ITSI to monitor service health and key performance indicators across various servers, such as CPU, memory, and disk utilization—advanced detection capabilities based on defined thresholds and triggered alerts. Splunk ITSI, integrated with ServiceNow, facilitated alert generation and management. Additionally, we leveraged ITSI for event analytics and created glass tables based on configuration items. We monitored specific KPIs and generated alerts via ServiceNow based on established thresholds to meet customer requirements.

Some clients have Splunk ITSI deployed in the cloud, and others are on-premises.

How has it helped my organization?

Using a client example, I'll explain the end-to-end visibility provided by Splunk ITSI. We have over a hundred clients in our environment. Once we onboard client data, such as cloud data, we subscribe to that cloud service and integrate the data into our Splunk environment. We then create data models and correlations integrated with the ITSI service. Within ITSI, we create correlation searches and schedule them to run regularly. Each time the Splunk schedule runs, it generates notable events and checks policies to determine if an event qualifies for a ticket. If it qualifies, an episode is created in ITSI, and a ticket is automatically generated in ServiceNow. This is the complete end-to-end process within Splunk ITSI.

We use predictive analytics based on the threshold values to help prevent incidents before they occur.

It does not take long after deployment for our clients to realize the benefits of Splunk ITSI because it immediately reduces alert noise.

Both Splunk ITSI and Splunk Enterprise Security handle incident management, but Enterprise Security utilizes common data models for improved detection. ITSI employs an "episode review" concept to analyze incidents, examining their generation, root cause, trigger alert, and any alerting failures. This provides comprehensive observability of each episode. Similarly, when integrating Enterprise Security with customer systems, pre-built common data models generate alerts that require monitoring to determine their cause, priority, and severity.

Splunk ITSI, using the correlation through event management, can reduce our alert noise.

We can correlate information to receive only relevant alerts, allowing us to quickly respond to issues.

What is most valuable?

The most valuable feature is event correlation, which ensures that only one ticket is generated per issue, eliminating duplicates and reducing noise from multiple alerts. This significantly streamlines issue tracking and resolution. Additionally, the system analyzes service performance by identifying areas of impact and tracking key performance indicators. This deep-dive analysis allows for the precise identification of issues and facilitates data-driven improvements.

What needs improvement?

While integrating services and KPIs in ITSI is straightforward, I found it challenging to analyze them with the service analyzers; specifically, using the deep dive feature to pinpoint the exact source and time of an issue proved difficult. Although I'm proficient in service analytics management, the deep dive aspect requires further development.

For how long have I used the solution?

I have been using Splunk ITSI for two years.

What do I think about the stability of the solution?

Splunk ITSI is stable.

What do I think about the scalability of the solution?

Splunk ITSI is scalable. It is easy to scale on the cloud platform.

How are customer service and support?

The Splunk support team is adequate, but their response time is slow.

How would you rate customer service and support?

Positive

How was the initial setup?

The deployment is straightforward. We acquired a license and integrated it into our current Splunk environment.

What's my experience with pricing, setup cost, and licensing?

Splunk ITSI is a premium application and comes with a premium price tag.

What other advice do I have?

I would rate Splunk ITSI nine out of ten. Splunk ITSI is a valuable tool for IT and operations teams.

I recommend Splunk ITSI. It's an excellent tool for infrastructure monitoring, direct management, and service analytics, providing a clear, consolidated view of your IT environment.

Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
Srinivasulu Soolluru - PeerSpot reviewer
Splunk ITSI Developer at Tata Consultancy
Real User
Aug 6, 2024
It speeds up incident response by automating alerts and ticket creation
Pros and Cons
  • "The search function is the most valuable. It includes regular expressions and wild card searches. We'll write searches using field and case-sensitive services and use all of these search types to write an alert condition. Splunk ITSI has another feature called Glass Table that offers a visual representation."
  • "When configuring a dashboard, we can write search criteria. Based on the search criteria, the dashboard shows all the alerts, including the alert time, creation time, and a summary description of the alert. When you add an extra column, such as the user that triggered the alert, the next time he refreshes the dashboard, he wants to know that the alert is acknowledged. We want to improve that comment feature."

What is our primary use case?

We get our customers' requirements and onboard their logs into the SIEM tool using agent-based integration or some DB Connect method. After the integration, we write the use cases. There are two types of data: fault monitoring and performance monitoring. In fault monitoring, the customer typically wants every event as an alert, so we'll do a correlation search for that alert. 

We'll add fields to the alerts, such as summaries and descriptions, and write the regular expression from the raw event to extract and display it on a table. After writing the correlation search, we will enable the policy that we'll use to trigger an incident in the ITSI tool. In our Splunk tool, there is a technical add-on called Remedy that we use to create a ticket for a correlation search and alert. 

After writing the NEAP policy, we'll display the number of tickets and all that information in a single dashboard. In the first panel, we'll display a summary of all the applications and the number of tickets divided according to the severity. The second panel displays the alert information, such as the ID, reported date, and the host. 

We have a team of four people. Two integrate the log sources into Splunk, while two write correlation searches, enable the new policies, and generate tickets in incident service with the ITSI tool. They also work on the dashboards, tables, and service analyzer.

How has it helped my organization?

With Splunk ITSI, we don't need to manually raise tickets for analysis. For example, it will not trigger a ticket if we receive an alert about a suspicious event when a set of conditions are met, but it's an invalid alert. Based on a NEAP policy, an incident will be created for each valid alert with the help of our ITSM tool. Each NEAP policy has two components: filtering criteria and action rules. The filtering criteria include sections. If the alert source equals the application log monitoring, it will group that particular event. 

For each event, it groups by incidents based on the job ID, and we write conditions for the second-action rules. The incident ticket remains in progress if the event exceeds one and the status is not closed. It shouldn't create a second incident for the same job name.

Splunk ITSI helps customers to reduce their resources. For example, they don't need extra resources to raise manual incidents for each alert. This solution enables us to raise incidents for only valid alerts, and it displays them all in a single dashboard.

It doesn't affect the effectiveness of the application monitoring, but it decreases the resources and associated costs. It will improve the performance compared to raising incidents manually and reduce human error. 

ITSI reduced the time needed to create a ticket. Instead of raising a manual ticket, we can automatically create one after an alert is triggered based on our policy. We can see all the incidents and alerts on the dashboard. 

It has also reduced the volume of incident alerts. We sometimes raise a manual ticket for the same alert triggered yesterday or a few days before. If it is not closed, and we raise another incident by human error. We can write a new condition so that an alert name by the same name will produce no new tickets. It will update the ticket as "in progress" or change the severity from minor to major.

We can also reduce our alert noise using ITSI by writing a complex set of specific correlations. We'll write the exact conditions based on customer requirements. For example, we'll use Windows event ID 4625 for a failed login attempt. If a user wants, we can add the search criteria so only this event ID will be triggered. 

When integrating our customer logs sources, we directly integrate the real-time events into Splunk. There is no time difference from the customer side. It goes directly into Splunk ITSI. Previously, we used some integration method so that when an alert triggers in EMS, it will reach out to Splunk to create an incident within a minute.

We send the artifacts, logs, and analysis to an incident response team to resolve an incident. The response time depends on the team. They receive all the evidence about an alert. 

ITSI helps automate some reports and dashboard features. When we want to run some individual searches, it takes some time to run each search to generate a report and share it with the customer. We can add all these reports into a single dashboard, and we have a query for each report. We add all these queries into a dashboard and schedule the reports, so it generates a report daily showing all the graphs. We can download that report and share it with the customers.

When we automatically generate a ticket based on the alert, it reduces the detection time and makes the ticket-raising time nearly instantaneous. The time difference between the alert trigger and ticket creation time will be minimal as the machine is generating the ticket. The customer response time is five to 10 minutes. 

What is most valuable?

The search function is the most valuable. It includes regular expressions and wild card searches. We'll write searches using field and case-sensitive services and use all of these search types to write an alert condition. Splunk ITSI has another feature called Glass Table that offers a visual representation. 

We can manually change the dashboard by reducing its size or changing the background color. When we click on any cell, it will navigate to the next dashboard. You also have a KPI feature. Each KPI case has a separate formula, and we'll write a formula so that when a threshold is reached, it triggers a condition. All of this KPI information is displayed in one service analyzer.

ITSI's end-to-end visibility is excellent. With its help, we can monitor all the network-related log sources and infrastructure. Each log source is integrated into the tool and stored in a separate index to improve search performance. We are using this cluster environment with multiple indexes. It's better to have three to four indexes for a faster search.

The solution's preventive analytics help to prevent incidents before they occur. We write a correlation search that is reported. When an alert is triggered, we write a condition. Each incident will have a priority and a response time based on the SLA. For a priority 1 incident, we must respond within 30 minutes. It's an hour for priority 2 and two hours for priority 3. We have three to four hours for priority 4. 

A ticket will be created within this time, and the incident response team will be alerted. While raising the ticket, we analyze all the alert information and everything the incident response team needs to resolve it. The incident response team will act accordingly and close the incident within this time.

What needs improvement?

When configuring a dashboard, we can write search criteria. Based on the search criteria, the dashboard shows all the alerts, including the alert time, creation time, and a summary description of the alert. When you add an extra column, such as the user that triggered the alert, the next time he refreshes the dashboard, he wants to know that the alert is acknowledged. We want to improve that comment feature. 

In the Service Analyzer, we monitor the network infrastructure services and have a KPI for each service. When the value exceeds the threshold value, we can add the colors. For example, we can set it to green when the threshold value is within the limit. If it is red, then the value has passed the threshold. We want more colors in the service analyzer to display all these features.

For how long have I used the solution?

I have worked with ITSI for two years.

What do I think about the stability of the solution?

Splunk ITSI is stable. When Splunk releases its latest update package, we scan it for vulnerabilities and update it to the next version if there are none. 

What do I think about the scalability of the solution?

Splunk ITSI is highly scalable. 

How are customer service and support?

I rate Splunk support nine out of 10. We can get support from the Splunk community or raise a ticket to Splunk and get a reply faster.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Before implementing Splunk, we manually noted all the alert information in a notepad. I downloaded the log file and traced the incident in tools like ServiceNow and BMC Remedy. Now we have a Remedy add-on feature integrated with Splunk ITSI, so it requires no manual intervention to raise a ticket in ITSI. 

How was the initial setup?

Deploying Splunk ITSI was straightforward. We downloaded the initial version and upgraded to the latest package from the back end. It's a simple process that involves integration, log onboarding, deploying agents, and setting up DB Connect. In the agent-based method, we'll have a separate configuration. We collect the log path for all the sources and hosts that need monitoring, which will be integrated into our Splunk tool. 

It requires minimal IT resources to deploy. Two IT resources are sufficient at the time of onboarding for 10 log sources weekly. It's easy to maintain. We are maintaining the license. If your data exceeds the license limit, you need to reduce it or pay for more. 

What's my experience with pricing, setup cost, and licensing?

We have a 100 GB license. This licensing option is a bit expensive, but it can manage any type of bulk data, including database logs, network device logs, and social media devices. 

What other advice do I have?

I rate Splunk ITSI nine out of 10. No manual intervention is needed. It generates the tickets automatically when an alert is reported. If we do this manually, it will take more time to review all the alerts. 

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Srinivasulu Soolluru - PeerSpot reviewer
Srinivasulu SoolluruSplunk ITSI Developer at a consultancy with 10,001+ employees
Real User

Hi ,

Review submitted based on my experience with Splunk ITSI.

Please feel free to call me out for any suggestions.

Thank you!

Buyer's Guide
Download our free Splunk ITSI (IT Service Intelligence) Report and get advice and tips from experienced pros sharing their opinions.
Updated: September 2026
Buyer's Guide
Download our free Splunk ITSI (IT Service Intelligence) Report and get advice and tips from experienced pros sharing their opinions.