Try our new research platform with insights from 80,000+ expert users

Everbridge IT Alerting vs Splunk Enterprise Security vs Splunk On-Call comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

IT Alerting and Incident Management
Security Information and Event Management (SIEM)
IT Alerting and Incident Management
 

Featured Reviews

it_user741570 - PeerSpot reviewer
Gets the right parties to the table at the right time - our mean time to restore has diminished, saving us money
In recent weeks we've been talking to Everbridge about leveraging some new functionality that they're demploying right now around orchestration. Imagine a full, closed-loop event remediation: auto-remediation. A server throws an alert. We catch it in our monitoring tool. We page or SMS text, using Everbridge IT Alerting. A group member receives that text and responds to the text with "Option One." Option one can say, "I want to go ahead and execute an orchestration that will automatically stop and restart the services on that box or even reboot the box." That would, again, further reduce service restoration time, and significantly reducing the manual engagement of logging a ticket, logging onto the box, restarting the box or the servers or services manually. All of that can be done through automation. We're not there yet, but that's what we're talking about right now, as a part of our next wave of moving along the crawl, walk, run journey. In terms of what could be improved, almost always, there is something that could be improved. I've been in this industry long enough to know that there is no perfect system. All the good ones still offer opportunities for getting better. I think if you were to look from their point of view, they would also see themselves in a crawl, walk, run journey. They may be further along in their walk, but they're probably not in the "Olympic sprint" or "Olympic marathon" stage yet. They've got lots of potential, room for feature enhancements, improvements. A couple of key ones might include - and I think they are working towards these things - analytics. If I want to do sophisticated reporting and analysis of the data that's being captured in IT Alerting, at the moment, the reporting interface is immature. They're very helpful. They get it. They're listening to us, but it's weak. It's growing. It's getting better. Reporting and analytics would be one space. Their integration capabilities are still progressing, but not quite where we'd like to see them yet. They're moving there with that orchestration capability where they're seeing the potential of an API-first mentality. So instead of trying to build custom connections into everything, you open up APIs to allow other systems to talk to IT Alerting and allow IT Alerting to talk to other systems. There is room for improvement, but they get it. They're listening in that space, too. Sure, there are things they can be doing better, but in partnership with them, us among other customers, I think we've got their ear, and they're being very proactive about listening.
ROBERT-CHRISTIAN - PeerSpot reviewer
Has many predefined correlation rules and is brilliant for investigation and log analysis
It is very complicated to write your own correlation rules without the help of Splunk support. What Splunk could do better is to create an API to the standard SIEM tools, such as Microsoft Sentinel. The idea would be to make it less painful. In ELK Stack, Kibana is the query language with which you can search log files. I believe Splunk has also a query language in which they search their log files, but once you have identified the log file that you want to use for further security correlation, you want to very quickly transport that into your SIEM tool, such as Microsoft Sentinel. That is something that Splunk could make a little bit less painful because it is a lot of effort to find that log file and forward it. An API with Microsoft Sentinel or a similar SIEM tool would be a good idea.
Wojtek Witowski - PeerSpot reviewer
Allows us to create flexible schedules for on-call rotations
For alerts, we could choose to get a text message, app notification, or a phone call. The phone calls were very unusable, because it just read a bunch of numbers, like an ID of the alert. If there was a way to customize the phone call message, that would be great. Later, we would try to read the message, but it wasn't great at reading that. They had some sort of internal chat functionality where if we got an alert, we could write to somebody else and ask them for help, but that was super cumbersome. There could be improvements with communicating an incident or alert. Imagine you call the help desk and you say that your computer is broken and then they say, "Actually, the internet is broken, so let us forward your alerts to the network people." And the network people say, "Actually, the electricity is the problem, so let us forward it to the electricity people." Basically, you could send the alert between the support teams inside the company.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"You can configure the tool to escalate if no action is taken within a certain time period. That avoids sending off an alert that nobody deals with and where nobody knows that nobody has dealt with it."
"Valuable features include incident management and ease of integrations."
"Powerful conference bridging that rigorously reaches out to stakeholders, which saves time working an issue. The mobile app provides ease of use for our resolvers and mobile push has proven quick and reliable. It also gives us flexibility around creating sometimes complex shifts within an on-call calendar."
"The most valuable feature is automated escalation, as it eliminates a manual process which is prone to errors."
"It's mainly for mass notification and pooling of contacts. Pooling of customers is valuable."
"The rotation and replacement options save our managers a lot of time."
"By leveraging Everbridge, with a few clicks of a mouse, we are able to go in and request as many teams as we require to respond to an incident and bring them together to collaborate much faster."
"I manage the platform, and I don't really use it. The scheduling aspect of it is valuable where you create your groups and then either manually or via API call, you can initiate an alert. It'll look at the schedule and only contact those people who are on-call. So, it takes the guesswork out."
"Splunk Enterprise Security allows us to create custom dashboards by changing fonts and modifying widgets."
"Splunk Enterprise Security offers two valuable features: the Common Information Model and arrangement modules."
"From the class that I took this week, being able to create notable events from whatever you find in the data set is pretty useful."
"The solution's most valuable feature is the aggregation of all the logs in one place, using enterprise securities built-in or ESCU use cases to find them."
"The most valuable feature is the incident dashboard, and the extensive use of correlation searches, which isn't available with a standard Splunk search package. This feature is important to me because it enables SOC analysts to do their job more efficiently and be able to investigate or mediate incidents at a faster pace."
"The flexibility of the search capability is most valuable. You can use it for more than just a basic log aggregator. It is powerful in that regard."
"Splunk Enterprise Security quickly gives us a view of an endpoint or a user or identity. If I want to look for an identity or an asset, I just quickly go into Splunk Enterprise Security. I know where to go and get a quick analysis for a respective object."
"Ease of correlation, creating correlation searches are easy and you can combine multiple sources with little effort"
"The most valuable feature of the solution is helpdesk escalation."
"VictorOps has been good enough for us and it's effective for our needs in case of an on-call escalation process."
"Transmogrifier and automatic solution report gives me a report with the solution and the way to solve issues when an error occurred."
"The alert calling feature is the best because notifications are delivered via phone messages."
"The flexible schedule is the most valuable feature. It was very easy to set out a rotation."
 

Cons

"They still have a limitation due to their partner, I believe it's Twilio, where, if you're on an incident call, there is a four-hour time limit. We often have calls that go over four hours in length so people have to drop and rejoin to reset their four-hour timer. It's a minor inconvenience, but it's not ideal."
"The integration with other solutions needs improvement... Due to issues with the libraries provided by Everbridge, we have not been able to integrate IT Alerting with our incident management tool."
"One thing that could be improved would be to enable the mobile app to more easily display published calendars via the Member Portal. Currently, it is quite difficult."
"The initial setup was very complex. We did not have a very good experience with our initial deployment. Most of this was due to customizations in our ServiceNow instance."
"It could use more enhancement type integrations, but no improvements to functionality are needed."
"I've worked closely with Everbridge teams in my previous positions too, and the one thing I would like to see is the distance. You have to measure it, and it's not really accurate. If we could have a general distance within the alert itself to tell us where the closest asset is, it would be useful. That's one thing I'd like to see."
"An ability to get to the database that houses our information would be great. Currently, we are at the mercy of Everbridge and, if they do not have the function built, we cannot gather the information that we would like."
"The solution's non-targeted communication with external parties could be enhanced."
"Data retention can be better. If we want to look at the data for five months or six months, that is not available to us."
"The solution is expensive."
"Splunk's ability to analyze malicious activities scores an 8 out of 10, but there's room for improvement. By analyzing emerging patterns, Splunk could identify and predict potential threats more effectively."
"Splunk could enhance its services by providing more comprehensive professional assistance aimed at optimizing our investment."
"I would like to get visibility into the data pipelines on heavy forwarders and indexers to see exactly their source and the cause of saturation when it occurs. This would help us learn even more about our high use applications."
"The price has room for improvement."
"Most of my interaction is with the user community, which is how Splunk wants it. When I need help, that community is very hit or miss."
"I would like to see the asset and identity lookups be more automatic and less manual."
"There could be improvements with communicating an incident or alert."
"At that stage, all our needs are fulfilled, but at the beginning, we had some feature requests and they were deployed during their roadmap."
"Should have more YouTube webinars."
"The third-party configuration tool could be easier to use."
"The solution can be improved by including a wider list of permissions."
 

Pricing and Cost Advice

"The pricing was under $25 a month per user. We had about 1,000 defined users."
"It saves us a lot of time."
"I do not know about the licensing costs, but I know they're in groups, and there are permission caps. For example, you can have five admin accounts, and anyone can receive a notification. There's a mobile component too, which I find particularly useful, but it has to be a part of the contract."
"This product has helped us save $200,000 from being able to get rid of vendors and consolidate functionalities to doing incident reporting."
"Their call structure is based on how many people are IT alert people and who is on the calendar, and the cost will be driven by those numbers versus if you are using it for the non-IT alert. As you look at the competition and other vendors, make sure you truly understand your cost structure with them."
"Licensing cost is driven largely by the number of users in the platform including admins, group managers, and message senders, so you want to consider your needs there."
"They are one of the cheapest solutions on the market. We looked at all of the major competitors in the space. Everbridge was one of the most affordable for what they are offering."
"The end result is that we have driven down our MTTR by an average of about 45 minutes across all major outages. That is very substantial considering the cost of every minute of outage can be thousands of dollars lost."
"Pricing and licensing is quite expensive. But for the value the product provides, it seems at par in the market."
"Splunk is a bit pricier, but the benefits and ROI are huge."
"Pricing can be a limiting factor. You have to continuously tune what you are bringing in and make sure what you bring in is of value."
"Splunk Enterprise Security is not at all cost-friendly to be deployed in very small enterprises like start-ups."
"Be upfront about your needs and expectations. Splunk is great to work with."
"We have had a reduction in the time it takes to resolve issues and correlate what has failed."
"I believe that Splunk Enterprise Security is worth the price, but it is expensive."
"Splunk Enterprise Security is cheaper than competitors, but I do not know whether it is just our contract."
"The price of the solution could be less expensive."
report
Use our free recommendation engine to learn which IT Alerting and Incident Management solutions are best for your needs.
849,190 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
19%
Financial Services Firm
13%
Healthcare Company
9%
Manufacturing Company
8%
Financial Services Firm
15%
Computer Software Company
14%
Manufacturing Company
8%
Government
8%
Computer Software Company
33%
Financial Services Firm
12%
Manufacturing Company
10%
Government
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What needs improvement with Everbridge IT Alerting?
The solution's non-targeted communication with external parties could be enhanced.
What advice do you have for others considering Everbridge IT Alerting?
We are using Everbridge IT Alerting for incident and crisis modules. The tool is powerful in itself, but as with any ...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is a...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingest...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitor...
Ask a question
Earn 20 points
 

Also Known As

No data available
No data available
VictorOps
 

Overview

 

Sample Customers

Choice Hotels, Alexion, Navy Federal Credit Union, EastWest Bank, IBM, Core Logic, Paypal, Charter Communications, Lowes, Express Scripts, Finastra, Worldpay
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
NVIDIA, Cisco, NBC, Rackspace, Intuit, DirectTV, NASCAR, Arrow Electronics, Alliance Health, NetApp, Edmunds, New York Times, Return Path, Sony Playstation, CA Technologies, Sphero, Symantic, HBO, Weatherford, Blackboard, Epic Games
Find out what your peers are saying about PagerDuty, Atlassian, Splunk and others in IT Alerting and Incident Management. Updated: April 2025.
849,190 professionals have used our research since 2012.