It monitors every level of infrastructure in our environment, including remote locations across the world.
Splunk Admin at UniFirst
Allows instant use of the gathered metrics and reduces the time to identify and resolve an issue
Pros and Cons
- "Instant usability of gathered event metrics is available. We have metrics data from systems, and we can use that to instantly get system status and trends."
- "There should be entity conflict resolution, specifically regarding duplicate entities. There should be case sensitivity for various keys amongst entities, specifically host names. We need IT metrics-based indexes and more content packs. I know they are coming out with these features"
What is our primary use case?
How has it helped my organization?
Splunk ITSI has end-to-end visibility into the cloud-native environment. This is important but not as important because we are primarily on-prem in every aspect of our IT infrastructure. However, for things that we do have in the cloud, it is important that we have visibility there.
Splunk ITSI has helped reduce our mean time to resolve. We can see very quickly when things are down and where they are down. I have taken steps to reduce the time to identify and time to resolve with Splunk ITSI.
The unified platform helps consolidate networking, security, and IT observability tools. It forces certain groups to work together and more closely, as they should. It increases awareness of the current statuses of other environments, which is important.
What is most valuable?
Instant usability of gathered event metrics is available. We have metrics data from systems, and we can use that to instantly get system status and trends.
What needs improvement?
There should be entity conflict resolution, specifically regarding duplicate entities. There should be case sensitivity for various keys amongst entities, specifically host names. We need IT metrics-based indexes and more content packs. I know they are coming out with these features.
Buyer's Guide
Splunk ITSI (IT Service Intelligence)
August 2026
Learn what your peers think about Splunk ITSI (IT Service Intelligence). Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
914,262 professionals have used our research since 2012.
For how long have I used the solution?
I have been using Splunk ITSI for two years.
What do I think about the stability of the solution?
Its stability is great.
What do I think about the scalability of the solution?
It is handling well what it is supposed to handle for some parts of our setup, and with the new version, it is only going to get better.
How are customer service and support?
I have never used their support. Community is the first place I go.
Which solution did I use previously and why did I switch?
I started with the company two years ago. They had it long before that.
What other advice do I have?
I would rate Splunk ITSI an eight out of ten. It is pretty good, but there are some inflexibilities with the analyzer that can be annoying.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Associate at Cognizant
Has good data forwarding and marketplace features and allows us to size resources to match the demand
Pros and Cons
- "I particularly appreciate two features of Splunk ITSI: data forwarding and the marketplace."
- "The user interface visualization could be improved."
What is our primary use case?
We use Splunk ITSI for monitoring and analytics.
How has it helped my organization?
We spent two months evaluating Splunk before deploying it in production, and by the end of that period, I fully realized the tool's benefits.
Splunk allows us to size resources to match the demand.
Splunk significantly improved our organization's efficiency. Previously, identifying application failures required manual checks or creating custom email templates. However, this process has been fully automated since Splunk was integrated into our applications. We now receive instant email alerts for any issues, reducing our response time from hours to minutes and seconds.
It reduced the mean time for detection by 60 percent.
Since implementing Splunk ITSI, we now receive alerts within seconds of detection.
Splunk ITSI has significantly reduced the time spent on routine tasks. Previously, locating errors could consume minutes or even hours, but now it takes seconds.
It is easily integrated and capable of ingesting data efficiently.
What is most valuable?
I particularly appreciate two features of Splunk ITSI: data forwarding and the marketplace. Data forwarding allows us to ingest data from at least three different sources directly into Splunk. The marketplace, on the other hand, empowers us to create and share custom applications or functionalities that aren't already available.
What needs improvement?
The user interface visualization could be improved. Splunk ITSI currently utilizes a candid design.
For how long have I used the solution?
I have been using Splunk ITSI for 11 months.
What do I think about the stability of the solution?
Splunk ITSI is stable on the Cloud.
What do I think about the scalability of the solution?
Our project generated millions of lines of data every ten minutes, which Splunk ITSI successfully processed.
Which solution did I use previously and why did I switch?
We migrated from New Relic over to Splunk ITSI because of budget constraints.
How was the initial setup?
The deployment is straightforward.
What other advice do I have?
I would rate Splunk ITSI eight out of ten.
A dedicated Splunk team deals with maintenance.
Before using Splunk ITSI, it is recommended to take advantage of the free trial period to explore the application and thoroughly read the documentation. This will allow you to determine if it meets your needs before diving in.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Splunk ITSI (IT Service Intelligence)
August 2026
Learn what your peers think about Splunk ITSI (IT Service Intelligence). Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
914,262 professionals have used our research since 2012.
AIOPS Architect at a comms service provider with 1-10 employees
The solution has a correlation layer where you can normalize the events from different sources
Pros and Cons
- "What I like the most is the event correlations. It's a file structure, and ITSI has a correlation layer where you can normalize the events from different sources. Once these events are normalized, you set up rules to aggregate them into different or the same attributes. After the rules are defined, you can automate the process to solve the issue automatically."
- "One thing ITSI could improve on is the maintenance windows. I have a huge case where I had to implement something related to the maintenance window. If you try to look up the issues in ITSI, you have to check the incidents individually, and putting hundreds of hosts in maintenance can be a hindrance."
What is our primary use case?
I use ITSI for different companies but with the same objective: to correlate alerts from different sources and assess them according to multiple frameworks. For example, I can combine the alerts from different sources into a single episode. The analyst can resolve the issue without looking in multiple places to get the necessary information.
How has it helped my organization?
ITSI was initially challenging, but you can pick it up quickly once you understand the concept. It also depends on the goal. Combining different sources into episodes is one thing, but integrating ITSI with automation or other ITSM solutions may take longer.
The solution has a forecasting module. You must have a good infrastructure because AI takes a lot of processing, but it works well. Based on previous data, you can assess it in 30 minutes or so. Having that predictive ability is a lifesaver.
It can streamline incident management. ITSI has a feature called Teams that lets you control access to different services to control which teams are responsible. You can control permissions and everything else. Everyone is assigned to a team with a unique experience while using the frame of the platform.
ITSI has a feature called NetFlow. It depends on what you plug into it, but in my use case, we usually click alerts before they become incidents and measure how many alerts become incidents to get an idea of how much it's helping to resolve things before they turn into incidents and have an impact.
It has helped to reduce alert noise because we can group alerts from different sources into one ITSM ticket with information from various sources. This helps our team resolve the issue because they only need to look at a single ticket instead of opening multiple ITSMs to gather all the necessary information to assess the problem.
The amount of alert noise reduced depends on the maturity of the environment. When you set up rules to aggregate events, you have to know some information about those events, like the team that created them, the system they belong to, the impact, and whether they're infrastructure, a service, or an application. If you have those all set up, it could be a 75 percent noise reduction.
ITSI reduced our meantime to detection because ITSI is plugged into each search, and as soon as an event is detected, it's processed and sent to the responsible team. It has helped us to detect issues and resolve them faster so we can provide more information upfront to IT.
It helps the IT team resolve things faster, but it depends on the information that ITSI is grouping. If you have enough information to find the root cause, it can help to resolve everything quicker. For example, let's say an analyst is looking at five impacted services, but one of them is the root cause. If we can provide that information upfront to the analyst, he can resolve the issue much faster because he doesn't have to look at each separately to assess the cause.
ITSI has helped us automate some tasks. Many issues aren't easily solved. You must have good communication with the team and analysts to see the steps they take to resolve something, but it can tackle the most common issues and free up time. But you must be careful not to automate something a developer should fix. Automation helps a lot, but you can't automate everything.
What is most valuable?
What I like the most is the event correlations. It's a file structure, and ITSI has a correlation layer where you can normalize the events from different sources. Once these events are normalized, you set up rules to aggregate them into different or the same attributes. After the rules are defined, you can automate the process to solve the issue automatically.
Generally, the visibility is decent, but you need to set it up properly to have good visibility in a way that makes sense to see the issues you need to see. In ITSI, you have the concept of services and a service tree. If it's set up correctly, it can help you find the root cause of a problem. You need someone who understands ITSI and your business.
What needs improvement?
One thing ITSI could improve on is the maintenance windows. I have a huge case where I had to implement something related to the maintenance window. If you try to look up the issues in ITSI, you have to check the incidents individually, and putting hundreds of hosts in maintenance can be a hindrance.
For how long have I used the solution?
I have used Splunk ITSI for four years.
What do I think about the stability of the solution?
I rate ITSI nine out of 10. I've had issues before, but they are usually caused by the configuration or infrastructure. You have to be careful when deploying Splunk across your infrastructure.
What do I think about the scalability of the solution?
ITSI is scalable, but its engine is somewhat of a weakness. The engine runs on one machine, but ITSI is scalable because even though the engine runs on one machine, it assigns processes to other machines to work on. You can do well with ITSI horizontally, but sometimes, you need to think vertically because the processing takes some memory.
How are customer service and support?
I rate Splunk support seven out of 10. Like any support, how fast they respond depends on the priority. Overall, they've helped a lot and were willing to enter a call to see the environment and the issues themselves. I would say do a good job overall.
How would you rate customer service and support?
Neutral
How was the initial setup?
The complexity depends on your infrastructure. It's a lot easier if you have a single instance, but deploying on a cluster requires a little care. The package formats are specific to the roles of your cluster. We have to be careful with that. It's not too difficult. You can set it up in a day or two if you read the documentation.
One person can set it up, depending on the size of the cluster. For example, if it only has two machines, one person can do it easily. You can set up a batch script to accelerate the installation. If you have that setup, you can do it easily in a day with one person. If you don't have that, it could take up to two days if you don't have much experience with ITSI.
What other advice do I have?
I rate Splunk ITSI eight out of 10. I would recommend Splunk ITSI, depending on the company's context. If the ITSM solution they have serves them well, I don't think it's necessary to switch to ITSI because it's costly. I would only recommend it to someone who knows they will get a return and have the capital to invest. Small companies probably have a bit of difficulty using ITSI. If you're a big company having issues, ITSI can help you out.
I recommend new users read the documentation carefully and watch a few videos on it. The first thing is to wrap your head around the concept. If you try to speculate at once without understanding a few things, it could be a lot more difficult. It's helpful if they stop and read the documentation to understand each piece.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Splunk Consultant at a financial services firm with 1,001-5,000 employees
An intelligent and scalable platform for operational excellence
Pros and Cons
- "The service analyzer view and automatic creation of incidents are valuable."
- "The biggest improvement area is making it open to developers. Right now, it is very closed. It can only be downloaded by people who have a license to and not everyone. If it is open to everybody, more people will use it."
What is our primary use case?
Splunk ITSI is a product for operations. I use it for detecting issues in the operations and generating alerts for them.
It is an intelligence platform for operational excellence.
How has it helped my organization?
The end-to-end visibility is a great thing about Splunk ITSI. It provides an end-to-end view to any user, from a normal engineer to a high-level manager.
We were able to realize the benefits of Splunk ITSI immediately.
Splunk ITSI helps to right-size resources to match the demand. It improves the quality. It is more organized. It can definitely help in rightsizing.
It helps to avoid duplicated alerts. If rightly implemented, it can reduce the duplication of alerts and provide more specific and accurate context.
Splunk ITSI has helped reduce incident volume. The reduction is implementation-dependent. If it is rightly implemented, we can reduce it to a very low percentage. Out of 100, we get only 10 alerts. If the context is correct, we only need one alert. This can be achieved with ITSI.
Splunk ITSI has helped reduce our alert noise, but I do not have the numbers because the initial implementation was not right. There were so many alerts, but when we corrected the implementation, it reduced them by a lot. I do not have the numbers, but thousands have become hundreds.
Splunk ITSI has helped reduce our mean time to detect (MTTD). It is at least five minutes. The mean time to resolve is dependent on the team. I do not have control over that because, in Splunk ITSI, we generate alerts for multiple teams, not just one team. It all depends on their SLAs.
Splunk ITSI helps us to automate alerting and automatically generate alerts or create incidents. It is not an automation tool to reduce mundane tasks.
Splunk ITSI helped us save costs by reducing downtime and manpower costs or avoiding SLA penalties.
What is most valuable?
The service analyzer view and automatic creation of incidents are valuable.
What needs improvement?
Better documentation would definitely help. Many people do not know about it, so better documentation and use case explanations would be helpful. There should be more YouTube videos about how to implement ITSI
The biggest improvement area is making it open to developers. Right now, it is very closed. It can only be downloaded by people who have a license to and not everyone. If it is open to everybody, more people will use it.
For how long have I used the solution?
It has been quite a long time. It has been more than four or five years.
What do I think about the stability of the solution?
It is pretty stable. If we have the proper infrastructure, this tool is very stable. It does not crash.
What do I think about the scalability of the solution?
Its scalability is high. It can scale very well. You can increase the size of the cluster. You can increase the capacity vertically and horizontally. It is very scalable.
How are customer service and support?
They are good. They respond based on the SLAs. The quality of service depends on how informative you are when you provide the case details to them, but they have the ability to escalate it to higher levels and get help. They have the skills, but sometimes, the support is not in the UK. It sometimes comes from the US, so there may be time constraints when you set up a call. Otherwise, they are good.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I have used other solutions. In the old days, I used a BMC system. Splunk ITSI is a completely different type of alerting system.
The BMC solution is more monotonic. It does not have the intelligence like Splunk ITSI to reduce the noise. It just picks up a metric and alerts based on that threshold, whereas, in ITSI, we have the control to reduce the number of alerts generated on the same threshold by adding some intelligence to it. It has the ability to do that Intelligence part. That is why it is called ITSI.
How was the initial setup?
We have both on-premises and cloud deployment models. Its deployment is difficult for a beginner user. You need a consultant or somebody experienced in Splunk ITSI to implement it properly. Splunk ITSI is a premium product. You need very good Splunk infrastructure initially to run this on top. To run it properly, you should have good knowledge. You should at least have Splunk Architect-level certification. Otherwise, you can implement it, but it will not work properly or as you expect.
It is mostly a clustered solution. It is not normally done on a single server. We need to build the entire cluster. The initial build probably can take two weeks. Configuring everything can take a long time. Six months can be considered a good time to make it run properly for enterprise usage.
It needs regular upgrades, backups, and time-to-time updates to the system configurations. It requires a dedicated team. Once it is properly set up, less than ten people can manage it.
What about the implementation team?
I am an ITSI consultant, so I am not a user. I set it up for customers.
The number of people required depends on how much data we need to bring in. If we have a lot of data and a variety of systems, more people are required. If we are just focusing on a singular system, one person can do the job.
In an enterprise environment, there are a multitude of systems and monitoring requirements. Usually, there is a team onboarding data and setting it up. 10-15 people are a good choice for a big enterprise, like a banking client.
What's my experience with pricing, setup cost, and licensing?
It is more of a premium product. I do not have much visibility into pricing because it is taken care of by high-level enterprise customers. I just ask for the license that I need and they negotiate. It all happens between Splunk and the company. I know that it is expensive, but I do not think there is another solution that can do similar things for that price.
What other advice do I have?
To someone who already has an IT alerting and incident management solution but is considering switching to Splunk ITSI, I would say that it will add value to their organization. It can reduce a lot of noise. I would suggest going for it, but it should be the right implementation. You should have knowledgeable people to implement it from the beginning.
It is not something that you just buy and switch on and will start working. It needs a lot of configuration and proper configuration to make it run properly. That is an important part for Splunk ITSI. It is not just the product. The person who is implementing it should be very good. Then only its value can be seen. Otherwise, you have the application but may not get the right value out of it.
Overall, from my experience, I would rate Splunk ITSI an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Principal architect at a retailer with 1-10 employees
Offers a return on investment but needs to improve in the area of revolving around dashboards
Pros and Cons
- "The solution's scalability is fine."
- "The dashboard function inside the individual episodes, not at the ITSI Notable Event Aggregation Policy level but actually at the correlation search layer, is an area where improvements are required."
What is our primary use case?
I use the solution in my company for event management and areas consisting of episodes.
How has it helped my organization?
Splunk ITSI (IT Service Intelligence) has helped our organization correlate events into episodes.
What is most valuable?
The most valuable feature of the solution is event analytics, and it is because that was our core function when we moved from NOC to IBM Netcool Network Management and then from IBM Netcool Network Management to Splunk ITSI (IT Service Intelligence).
The main benefit I have experienced from using Splunk ITSI is that it has been helpful to have one consolidated tool.
My organization monitors multiple cloud environments using the product. In terms of the ease or difficulty one may have when trying to monitor multiple cloud environments, it is tricky. You have to learn and test things out.
It is important for our organization that Splunk ITSI (IT Service Intelligence) provides visibility into our cloud-native environment, but I would say that it is done in the dev and production environments.
Splunk ITSI (IT Service Intelligence) has helped us with the organization's business resilience. My impression of Splunk's ability to predict, identify, and solve problems in real-time, is that with the new AI feature set coming in, users can apply that logic to the episodes.
I have experienced cost efficiencies by switching to Splunk ITSI (IT Service Intelligence). The doc suggests that too has one pane of glass to go into the system and do automation straight from one page because they get hit with thousands of alerts and alarms every day, and we try to correlate that to a simplistic event.
I have experienced time to value using Splunk ITSI (IT Service Intelligence) over a couple of months.
Splunk's unified platform helps consolidate networking and IT observability tools but not security because our company is not in that space. The consolidation of tools impacts our organization since I feel it is easier to have fewer tools than more.
What needs improvement?
The dashboard function inside the individual episodes, not at the ITSI Notable Event Aggregation Policy level but actually at the correlation search layer, is an area where improvements are required.
In the next release of the tool, the product should offer a dashboard ID in the correlation search.
For how long have I used the solution?
I have been using Splunk ITSI (IT Service Intelligence) for five years.
What do I think about the stability of the solution?
In the early days, the Java-based engine was kinda buggy, and some of the interfaces for Splunk ITSI (IT Service Intelligence) and event analytics needed to feel new and not outdated. It still kinda feels outdated, and I feel like Splunk hasn't really put a lot of thought into such a specific area in the last few years.
What do I think about the scalability of the solution?
The solution's scalability is fine.
How are customer service and support?
The solution's technical support team is okay. For most of the stuff I escalate, I have to always wait for a response from tier-two or tier-three level support.
I am used to solving stuff myself and providing a lot of debugging as to what tier-one or tier-two level support would do, and by the time I get to the aforementioned spot, I see that I have to wait and explain a lot of cycles because I am doing the same research as level one or level two support. I rate the technical support a five out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I have experience with Tivoli Netcool, which is a legacy event system from IBM that has the same or similar approach as Splunk ITSI (IT Service Intelligence). I saw that Splunk ITSI (IT Service Intelligence) provides the same features as Tivoli Netcool.
How was the initial setup?
When it came to the deployment part, Splunk's professional services did not know much of what our company needed, considering the level that we were expecting from the product. I come from a telco background where the company used to deal with 1,00,000 alarms a day, and event analytics wasn't something that was really built for it in the beginning when I first deployed it. There were a lot of learning curves that I had to go through to deal with the tool. As I continued to grow with the product, I started pitching probably around 20 ideas at a time to the team, and a lot of my ideas actually made it to Splunk's GA launches. I worked with Isha, Ross Wilkinson, and another person who was right in the middle between them. Though I had spoken to the senior VP of a particular sector and pitched the idea of using Fandom for IT automation, it eventually died out.
The solution is deployed on an on-premises model. I use the cloud services from AWS.
What about the implementation team?
Splunk directly helped with the product's deployment.
What was our ROI?
I have experienced an ROI using the tool, considering the efficiency it offers so that we do not have to take care of certain functions.
What's my experience with pricing, setup cost, and licensing?
Pricing was pretty good, and it is possible to just add on the features we want.
Which other solutions did I evaluate?
I considered Resolve systems for automation and a tool named Moogsoft. Moogsoft has a lot better visual capabilities and looks better than Splunk ITSI (IT Service Intelligence) when it comes to event analytics. I am hoping that with a better dashboard, Splunk ITSI (IT Service Intelligence) can build a better UI layer.
What other advice do I have?
I feel like there is a lot more that can be done in the tool, but I don't know if it is going to be a dying product or if Splunk Observability will try to take over some of the core functions of Splunk ITSI (IT Service Intelligence).
I rate the solution a seven out of ten.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Splunk Dev & IT Si Admin at Solugenix
Reduces alerts, offers good performance metrics and has helpful support
Pros and Cons
- "Our mean time to detect is down to five minutes."
- "We're getting alerts with delays of maybe five minutes, however, we'd like to see real-time alerting in the future."
What is our primary use case?
We use the solution to monitor throughout the enterprise. We get alerts and create incidents and use it in our ticketing tool.
How has it helped my organization?
We have set up alerts so we can effectively monitor our infrastructure. Even small alerts the users face we can monitor.
We started small with a few users and once we saw the visibility we could achieve and the performance of the solution, we rolled it out on a larger scale.
What is most valuable?
The analysis and KPIs it provides are very useful. We can create episode monitoring.
The service analyzer is quite useful.
Its end-to-end visibility is very good. We can get to the root cause of troubleshooting. It makes the process easier. Troubleshooting happens very quickly - and that means we have less downtime.
We use the predictive analysis capabilities. It plays a major role as it allows us to act faster.
Our response time is almost instant. We can create alerts and check reports. It checks everything in real-time so that we can jump into action much faster.
It's helped with incident management. It's helped us reduce incidents while improving performance and visibility. It reduces the amount of work we need to do as well. We've likely reduced work by 30% or so.
Since it's reduced alerts, it's reduced alert noise. We do have triggers for alerts, and we can shortlist them and troubleshoot the ones that create the most noise.
Our performance metrics have improved. Alert noise has dropped by 60%. We've been able to maintain everything much easier. Handling the infra is simpler.
Our mean time to detect is down to 5 minutes. That's down from 15 to 20 minutes in the past.
What needs improvement?
We're getting alerts with delays of maybe five minutes, however, we'd like to see real-time alerting in the future.
From a predictive analysis point of view, we'd like to see emails corresponding to the alerts we get. That would be an added benefit.
For how long have I used the solution?
I've been using the solution at least 2 years.
What do I think about the stability of the solution?
Every time we upgrade, we do find some issue, however, it does get resolved. Overall, I'd rate stability 9 out of 10. Most of the time, it's stable.
What do I think about the scalability of the solution?
We have two to three people using the solution. We have the solution across multiple locations.
The solution is very scalable.
How are customer service and support?
Technical support is very good. I'm satisfied with the level of knowledge the techs have and the response time.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We did not use any other solutions.
How was the initial setup?
The initial setup is not complex. I'm not sure exactly how long it takes to implement as it was already in place when I began.
There is some maintenance required. You may have to run regular upgrades.
What was our ROI?
We've seen an ROI in the lack of downtime, which has improved by 80%.
What's my experience with pricing, setup cost, and licensing?
I don't have any visibility on the cost of the product.
What other advice do I have?
I'm a Splunk customer.
We don't have Splunk integrated with any other solutions.
For someone who already has an APM solution, but is considering switching to Splunk ITSI, I'd advise them to take a look at it against other solutions. However, Splunk is very, very good. It's likely to help any organization. I'd recommend it over a different monitoring solution. It eliminates much broader downtime and allows teams to act on alerts faster.
resilience is very important to us and Splunk helps us maintain that. It's very reliable.
I'd recommend the solution to others.
It's a good idea to go through the documentation so that everyone is on the same page with the setup.
I'd rate the solution ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Splunk admin and splunk ITSI at Convergys Corporation
Easily integrates, provides end-to-end visibility, and saves time
Pros and Cons
- "The KPS used to automate the integration policy is the most valuable feature of Splunk ITSI."
- "After upgrading Splunk ITSI from version 4.11 to 4.13, the analyzer stopped finding values for KPS and services."
What is our primary use case?
Splunk ITSI is our platform for data ingestion from various sources. We leverage it to manage Kubernetes configurations, licenses, reports, dashboards, and user permissions. Additionally, we utilize ITSI for field extraction and data model retrieval.
How has it helped my organization?
We successfully integrated Splunk ITSI with ServiceNow. The integration process was straightforward. We downloaded the Splunk Integration application from the ServiceNow app store and configured the ServiceNow account using the provided URL, username, password, and authentication method.
Splunk ITSI offers end-to-end visibility through a centralized admin console. This console allows us to monitor all aspects of our system, including indexing performance, daily resource usage, CPU utilization, and insights.
Splunk ITSI has helped our organization save time. We saw the benefits within the first three minutes of use.
We saw time to value within minutes of using Splunk ITSI.
What is most valuable?
The KPS used to automate the integration policy is the most valuable feature of Splunk ITSI.
What needs improvement?
After upgrading Splunk ITSI from version 4.11 to 4.13, the analyzer stopped finding values for KPS and services. We had to manually deploy a script to resolve this issue.
For how long have I used the solution?
I have been using Splunk ITSI for three years.
What do I think about the stability of the solution?
Splunk ITSI is stable.
Splunk ITSI is a resilient solution able to recover quickly.
What do I think about the scalability of the solution?
Splunk ITSI is scalable.
How are customer service and support?
The technical support team is great. They've helped troubleshoot our issues. Once we raise a ticket, we can continue the process using a DLL file.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial deployment is straightforward. The setup is automated.
Five people were required for the deployment.
What about the implementation team?
The implementation was completed in-house.
What's my experience with pricing, setup cost, and licensing?
The licensing is based on data usage.
What other advice do I have?
I would rate Splunk ITSI eight out of ten.
I recommend Splunk ITSI over other APMs because we can monitor everything from a single console.
Splunk ITSI is deployed across multiple locations.
No maintenance is required for Splunk ITSI.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
AIOPS Consultant at AIOPS Consultant
Good compatibility and end-to-end visibility with helpful support
Pros and Cons
- "Customers have noted the solution helps streamline incident management."
- "The license cost is expensive."
What is our primary use case?
We use the solution for intelligence. For example, if I have a website that sells games, it might have a lot of things like databases, servers, et cetera. I can see how many users have logged in, what purchases can be made, and so on. Splunk provides the logs to see all of the data for all actions on the site. I can see things on a technical level, like how CPUs are performing.
I can see things in real-time, and it's based on real data. This is the advantage Splunk has. There is complete visibility and I can monitor KPIs as well.
I can look at how my database looks, how my sales look, et cetera, and all metrics are in one place.
There's machine learning as well, including anomaly detection. You can look at and understand the date very easily. It helps us provide a complete understanding of business so that I can understand anomalies better and watch the daily data. It gives me alerts in which I can take a deeper dive.
I have a ticketing system. If I have a Splunk power user, they can look at the data and create a ticket for future inspection. People can correlate and collaborate on the same ticket.
Basically, everything you need you can find on Splunk. You can also create custom actions.
We can do actions right on the Splunk UI.
What is most valuable?
The compatibility is good.
The end-to-end visibility is okay. The only thing that is lacking is the application monitoring. We struggled with one use case where payments were failing and they couldn't understand if it was the infrastructure or bandwidth. The capability of recording any transaction is not possible in Splunk. You have to write your own scripts, however, it's not as user-friendly.
The predictive analytics are pretty good. I've seen people using it. That said, I'd say the admin needs a deep understanding of the infrastructure. It has a tendency to create noise. If you have a noisy system, when there's an alert, people tend to miss issues.
Customers have noted the solution helps streamline incident management. At a single glance, there is a complete view of infrastructure. It's good for the customer on the technical side. Teams were able to map the availability of the system more accurately - up by 28%.
It's helped reduce alert noise. It can aggregate the alerts and just create an alert only when needed. From the UI, you can correlate the alerts using dynamic conditions (not just static ones).
We've been able to reduce the mean time to detect. It has a similar meantime to detect as Dynatrace. We've used it when there wasn't an existing system, and we would have had similar results with other tools in the market. It's helped with MTTR for sure. Previous to implementing Splunk, the mean time was one hour or so. Once we implemented it, the alert notification was automatically sent to people, so it automatically reduced the time to two to five minutes.
The mean time to resolve has been reduced thanks to Splunk.
What needs improvement?
If you are using Splunk ITS and Splunk Enterprise Security, you have to run different searches. You cannot run both on the same server. You can bifurcate it however you want, however.
The license cost is expensive. When I want a premium application it's extra. I need to pay for this on top of my base license.
We'd like to see more use of artificial intelligence. There's no easy knowledge-base bot. It would help if they had a ChatGPT-like AI that could show them the knowledge base information they could use to address tickets.
For how long have I used the solution?
I've used Splunk as a product for about five years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution can scale. I'd rate it seven out of ten. There are some requirements on the backend in terms of scaling. If you want extra storage, it will cost more money. If you are adding a new server you will have to go and configure it and then you have to restart everything, so there may be downtime.
How are customer service and support?
I've contacted technical support. They were good in terms of experience. The cloud support is excellent.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I did not previously use a different solution.
How was the initial setup?
You can install the solution on-premises or on the cloud. If you want to send the data to your own on-premises environment, you can do so.
I was involved in the initial deployment. The setup was very straightforward, however, the requirements gathering can be complex, as well as gathering the KPIs and developing an understanding of requirements. You need someone who has a complete understanding and a holistic view of the environment.
How many people you need for the deployment depends on how big the infrastructure is, what you want to monitor, and the timeline you have.
The on-premises deployment requires maintenance as you have to monitor the server. The cloud requires less maintenance.
What about the implementation team?
We tend to implement the solution for our customers.
What's my experience with pricing, setup cost, and licensing?
The solution can be costly. You have to have a fixed license. It's very difficult for people to know beforehand how much they will be charged.
What other advice do I have?
We're Splunk partners.
For someone who already has an APM solution and is considering switching to ITSI, I'd advise them to look at the licensing and their budget and to consider where their APM is currently lacking. If you aren't getting the alerts you need or you can't see how your infrastructure looks, it might make sense to switch. They need to be aware, however, there will be an extra cost.
Secondly, if you can't see the logs in your application and can't fetch the logs, for example, if you are on Dynatrace, and Dynatrace does not provide your login analysis, you can just go and write a query. However, it depends on what your end customer needs as well. If they need good dashboards and they need flexible dashboarding, to which you can add images, and customize the way you want, you may need something more robust, like Splunk. We were able to pull it off using Splunk ITSI as it gives you very easy-to-customize dashboards.
To someone who's considering a point monitoring system instead of ITSI, I'll say that, depending on your infrastructure, it might be a good idea. If you have less data, and you can manage with the manual alerts, you're fine. However, if you're wasting a lot of time with the alerts and get a lot of alert noise, that means you can be missing major alerts. For major infrastructure, it's a good idea to have ITSI.
You need a minimum of 14 days before seeing time to value. 14 days is required in order to be able to use the complete solution. That allows the system to get good at anomaly detection.
I'd rate the solution eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
Splunk Administrator / Architect at MetLife
Provides great end-to-end visibility into our network environment and helped us reduce alert noise
Pros and Cons
- "Splunk ITSI helps us secure our environment by allowing us to create automatons that run when alerts are triggered."
- "The data recovery has room for improvement."
What is our primary use case?
Splunk ITSI is used to analyze data and create alerts. This helps us to maintain our security best practices.
How has it helped my organization?
Our organization was looking for a security monitoring tool. I use Splunk ITSI as a monitoring and security tool. It helps me to protect data and prevent malware and hackers from accessing my environment. Splunk ITSI can be used to protect our role and infrastructure. It can also provide insights into how and what is helpful within our infrastructure.
Splunk ITSI provides great end-to-end visibility into our network environment. It can identify the exact root cause of an issue without any additional troubleshooting on my part.
Predictive analytics is valuable for preventing incidents before they occur because it allows me to see when the data stopped being indexed, which saves me time from having to investigate.
Splunk ITSI makes it easier to secure our entire infrastructure. Before Splunk ITSI, our environment was chaotic.
Splunk ITSI streamlines our incident management by providing a financial report of all applications in our environment.
Splunk ITSI has helped us reduce alert noise. After configuring ITSI, we set certain parameters based on our alerts. These alerts are the conditions that ITSI uses to automatically reduce noise.
Splunk ITSI helps to reduce our mean time to detect by monitoring key performance indicators such as CPU overload and the percentage of use revenue trend. On average the automation has reduced our mean time to detect by five minutes.
Splunk ITSI significantly reduces our mean time to resolve because most of our time was previously spent troubleshooting. With ITSI, we don't have to troubleshoot at all.
Splunk ITSI can help reduce downtime, but the extent of its effectiveness depends on how it is implemented.
What is most valuable?
Splunk ITSI has a lot of advantages. There are a lot of different aspects when implementing Splunk ITSI in our environment.
Splunk ITSI helps us secure our environment by allowing us to create automatons that run when alerts are triggered. This automation can pass through the CI/CD pipeline tool, which helps to increase security.
What needs improvement?
The data recovery has room for improvement.
For how long have I used the solution?
I have been using Splunk ITSI for three years now.
Splunk ITSI can be deployed on-premises or in the cloud. However, we typically deploy it in the cloud because of the available services. These services do require a lot of permissions.
What do I think about the stability of the solution?
Splunk ITSI is stable.
What do I think about the scalability of the solution?
Splunk ITSI is scalable.
How are customer service and support?
The quality of support depends on the individual use case and how we configure the solution.
How would you rate customer service and support?
Positive
How was the initial setup?
Splunk ITSI can be installed remotely or manually. The deployment time depends on the operating system being used to deploy the solution into the cloud. Once ITSI is deployed, I can perform a ROM test through the CI/CD pipeline.
What was our ROI?
Splunk ITSI's visibility into our environment provides good value to our organization.
What's my experience with pricing, setup cost, and licensing?
Splunk ITSI is a pay-per-use service that is priced fairly based on the amount of data we use.
What other advice do I have?
I give Splunk ITSI an eight out of ten.
Splunk ITSI is a cheaper and easier-to-use alternative to APM solutions. Unlike APM solutions, Splunk ITSI also helps with application management, memory management, host log volume, and CPU usage.
Our clients vary in size, with some using small amounts of data and others using terabytes of data within Splunk ITSI.
Splunk ITSI maintenance involves updating the software and ensuring that it is compatible with the applications that it will integrate with.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: partner
Observability Platform Architect at a tech vendor with 10,001+ employees
A reliable solution that enables users to build glass tables and set up thresholds
Pros and Cons
- "The glass tables are very helpful."
- "If the product had some prebuilt machine learning features, it would add value to our use cases."
What is our primary use case?
I have used Splunk ITSI to build a lot of glass tables and set up thresholds. We have also used MLTK for machine learning, predictive analytics, and anomaly detection. We use MLTK, which is an external application. We can get notified of issues well before the time to take proactive action.
How has it helped my organization?
We use core Splunk and Splunk IT Service Intelligence. It is a multisided cluster environment. Whenever the customer wants glass tables, notable events, or to set up some alert notifications, the product has helped our organization. We can set up our own threshold activities. We can also add ad-hoc searches in the solution. We can get the data of the indexes and alerts tracking by writing a search query.
What is most valuable?
The glass tables are very helpful. The solution also provides topologies showing exceptions or criticalities whenever something goes down. It is very helpful for customers. The notable events, glass tables, and setting up thresholds are the most valuable features of the solution.
Every customer has a different need and their own customized threshold settings. Some customers need 99% as critical, and some need 80%. We can set the customized thresholds in the product and get the alerts.
What needs improvement?
If the product had some prebuilt machine learning features, it would add value to our use cases. It would be very good if the product had some in-built predictive analytics and future forecasting features.
For how long have I used the solution?
I have been using Splunk for almost fouteen years.
How are customer service and support?
The support depends on the licensing we use. There are different licenses available based on the volume and vCPUs. We use the license based on vCPU. It depends on how many virtual CPUs we use. It would be good if Splunk could give on-demand support.
Whenever we raise a support case, the support team follows the SLA and gives us a response. Sometimes, companies will also have on-demand support based on the support credits. Companies generally expect support persons and engineers to join the Zoom sessions when P1 and P2 issues arise. The support team takes a long time to join the meetings at such times. If we can have an engineer join the Zoom sessions right away, it would be helpful for the customers. The support team needs to respond quickly to P2 issues.
We had a P3-level case with a severity level of S2. It was a corrupt bucket issue. The case was in open status for six months. Generally, we don't need six months to fix a corrupt bucket issue. If the support case had been escalated to a higher-level engineer with advanced knowledge in debugging the issues, it would have been easier and would have taken less time.
Which solution did I use previously and why did I switch?
We have been using Enterprise Security. It is for intrusion detection and threat intelligence. It helps our enterprise security team to find vulnerabilities and take proactive actions. We started using Splunk IT Service Intelligence because it gives us some good topology if we build glass tables based on our data. The product provides us with service intelligence.
How was the initial setup?
The deployment process is straightforward. It is the same as core Splunk. The solution uses summary indexing, itsi_tracked_alerts, and itsi_summary_metrics indexes. We must ensure these indexes are available and have a good retention policy.
What was our ROI?
Our customers have seen improvements in resilience and cost.
What's my experience with pricing, setup cost, and licensing?
It would have been good if the product cost was much lower.
Which other solutions did I evaluate?
We chose Splunk over other vendors because it is much more reliable. We have done a POC to test how well the tool can help the customers and provide good value to their business. We have used other products like Elasticsearch and Cribl. However, we feel that Splunk is better. Log monitoring is very important to customers. Other log monitoring tools are not user-friendly and flexible. It is also not easy to write search queries on them. However, it is easy to write search queries on Splunk. It also has bucket lifecycles. It is easier to have a centralized repository to maintain and use the data.
What other advice do I have?
Our clients monitor multiple cloud environments. We get data from different third-party clouds like Google Cloud, Microsoft Azure, or AWS. Sometimes, we also use Snowflake. Customers mostly try to build out their own dashboards and knowledge objects. They use Splunk IT Service Intelligence to be notified about any exceptions or critical issues.
We cannot integrate the product directly with the cloud applications. First, we have to integrate our core Splunk with different clouds. We must first integrate add-ons using Splunkbase, a REST API mechanism, or an HTTP Event Collector (HEC) mechanism into core Splunk. Then, we can use the same ad-hoc search in Splunk IT Service Intelligence to get proper glass tables and results. It's easy to monitor multiple cloud environments using the solution, but we could directly integrate with it if it had the right integration features.
It is important for our organization that the solution has end-to-end visibility into our cloud-native environment. In today's world, most data goes into the cloud. Every organization wants to move the data to the cloud so that it would be more reliable and they can get the data easily. It's less cost-effective as well. So, most organizations are going to the cloud. It's really beneficial and important to the customers because they can easily get the data from the cloud and perform cost optimizations. Managing cloud-native environments with the solution is cost-effective.
The product has definitely helped reduce our mean time to resolve by 70%. If it has built-in machine learning or artificial intelligence techniques, it will be helpful to reduce the remaining 30%.
The tool has helped improve our customer's business resilience. Different SIEM applications and tools are available for enterprise security in today's world. Splunk's next version will have enhanced SOAR features. It will be useful if the product has additional features to help customers and organizations.
We used the MLTK app from Splunkbase and deployed it in Splunk IT Service Intelligence. It helped us to do predictive analysis, forecasting, and anomaly detection. It helped us gain some insights. I rate the tool's ability to provide business resilience a seven out of ten.
If we have a Splunk add-on for Unix and Windows, we can use those add-ons in our core Splunk to get the base monitoring, like OS metrics. For these things, Splunk has PowerShell scripts. It runs every five minutes. So, it is not in real-time. Every organization would need real-time monitoring. The product should provide these features in real time. For OS metrics, we use custom thresholds.
Our customers see time to value within seven days. We implement Splunk with minimal architecture, like two deployment servers, two heavy forwarders, four indexes, and three searchers. We initially had the search factor as two and the replication factor as two. We had very little data initially. We tested in our lower environment with the POC and found the data the customers wanted to see in Splunk. It was helpful for the customers. They can find the exceptions, write their own search queries, and build their own knowledge objects.
We get different types of security management tools in the market, like Enterprise Security, SOAR, and Phantom. The product brings a lot of value to the customers. It gives a lot of insights into notable events and predictive analysis. It also has a good dashboard. I expect the solution to provide enhanced features in the upcoming release.
Attending Splunk conferences provides us with an opportunity to interact and get more details on the products from different vendors. More than 1,000 vendors attend the conferences. The more we interact with the vendors, the more insights we get from them. It is also helpful to build relationships with the vendor.
Overall, I rate the tool an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Aug 27, 2026
Flag as inappropriateBuyer's Guide
Download our free Splunk ITSI (IT Service Intelligence) Report and get advice and tips from experienced pros
sharing their opinions.
Updated: August 2026
Product Categories
IT Alerting and Incident Management Application Performance Monitoring (APM) and ObservabilityPopular Comparisons
Splunk AppDynamics
Splunk Observability Cloud
Elastic Observability
Amazon OpenSearch Service
Buyer's Guide
Download our free Splunk ITSI (IT Service Intelligence) Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- How do you decide about the alert severity in your Security Operations Center (SOC)?
- What is an incident response playbook and how is it used in SOAR?
- What is the difference between mitigation and remediation in incident response?
- What tools and solutions do you use for automated incident response in an enterprise in 2022?
- What measures should a business have in place to enable an effective incident response for data breaches?
- Why a Security Operations Center (SOC) is important?
- When evaluating Incident Management Software, what aspect do you think is the most important to look for?
- What are some Incident management best practices to keep in mind?
- GoDaddy has been hacked again. What can be done better?
- Why is IT Alerting and Incident Management important for companies?




















