TrustRadius: an HG Insights company

Elasticsearch vs. Splunk IT Service Intelligence (ITSI)

Save this comparison

Save this comparison

Add Product

Recommended Comparisons

    Overview
    ProductRatingMost Used ByProduct SummaryStarting Price

    Elasticsearch

    Score8.5 out of 10
    N/AElasticsearch is an enterprise search tool from Elastic in Mountain View, California.

    $16

    per month

    Splunk IT Service Intelligence (ITSI)

    Score10 out of 10
    N/ASplunk supports IT operations analytics with the Splunk IT Service Intelligence premium offering, a software application available to subscribers to Splunk Cloud or Splunk Enterprise log analytics and SIEM platforms.N/A
    Pricing
    ElasticsearchSplunk IT Service Intelligence (ITSI)
    Editions & Modules
    Standard
    $16.00
    per month
    Gold
    $19.00
    per month
    Platinum
    $22.00
    per month
    Enterprise
    Contact Sales
    No answers on this topic
    Offerings
    Pricing Offerings
    ElasticsearchSplunk IT Service Intelligence (ITSI)
    Free Trial
    NoNo
    Free/Freemium Version
    NoNo
    Premium Consulting/Integration Services
    NoYes
    Entry-level Setup FeeNo setup feeNo setup fee
    Additional Details——
    More Pricing Information
    Community Pulse
    ElasticsearchSplunk IT Service Intelligence (ITSI)
    Considered Both Products
    Elastic
    Chose Elasticsearch
    I think Elasticseach works less great compared to Splunk. Mainly the way the Splunk search head works is vastly superior to the way the Elasticsearch query language works. Furthermore, the Splunk architecture is in my opinion easier to roll out and scale-up. Splunk also has a …
    Incentivized
    Cisco
    Chose Splunk IT Service Intelligence (ITSI)
    No tool has the power that the combination of Splunk and ITSI has. You can certainly cover all that ITSI does by combining several tools with custom developed integrations, but the out of the box functionality of Splunk leveraged with ITSI is unparalleled.
    Incentivized
    Key User Insights
    Would buy again
    82%
    Would buy again
    14 Answers
    100%
    Would buy again
    24 Answers
    Delivers good value for the price
    100%
    Delivers good value for the price
    16 Answers
    100%
    Delivers good value for the price
    19 Answers
    Happy with the feature set
    100%
    Happy with the feature set
    17 Answers
    100%
    Happy with the feature set
    24 Answers
    Lived up to sales and marketing promises
    100%
    Lived up to sales and marketing promises
    13 Answers
    83%
    Lived up to sales and marketing promises
    15 Answers
    Implementation went as expected
    87%
    Implementation went as expected
    13 Answers
    100%
    Implementation went as expected
    20 Answers
    Best Alternatives
    ElasticsearchSplunk IT Service Intelligence (ITSI)
    Small Businesses
    Apache Solr
    Score7.9 out of 10
    No answers on this topic
    Medium-sized Companies
    IBM Watson Discovery
    Score9 out of 10
    No answers on this topic
    Enterprises
    Amazon CloudSearch
    Score8.5 out of 10
    DX Spectrum
    Score7 out of 10
    All AlternativesView all alternativesView all alternatives
    User Ratings
    ElasticsearchSplunk IT Service Intelligence (ITSI)
    Likelihood to Recommend
    9.0
    (48 ratings)
    10.0
    (28 ratings)
    Likelihood to Renew
    10.0
    (1 ratings)
    8.2
    (2 ratings)
    Usability
    10.0
    (1 ratings)
    10.0
    (1 ratings)
    Support Rating
    7.8
    (9 ratings)
    8.9
    (2 ratings)
    Implementation Rating
    9.0
    (1 ratings)
    -
    (0 ratings)
    User Testimonials
    ElasticsearchSplunk IT Service Intelligence (ITSI)
    Likelihood to Recommend
    Elastic
    Elasticsearch is a really scalable solution that can fit a lot of needs, but the bigger and/or those needs become, the more understanding & infrastructure you will need for your instance to be running correctly. Elasticsearch is not problem-free - you can get yourself in a lot of trouble if you are not following good practices and/or if are not managing the cluster correctly. Licensing is a big decision point here as Elasticsearch is a middleware component - be sure to read the licensing agreement of the version you want to try before you commit to it. Same goes for long-term support - be sure to keep yourself in the know for this aspect you may end up stuck with an unpatched version for years.
    Incentivized
    Read full review
    Cisco
    Splunk ITSI is a great tool (and toolbox) for combining together numerous and varied monitoring regimes to bring more holistic analysis and reduce alert fatigue. By leveraging the Splunk ITSI service and KPI modeling regime, ecosystem telemetry can be turned into a more reliable, clearer, high-level perspective on the current state of your components and services.
    Read full review
    Pros
    Elastic
    • As I mentioned before, Elasticsearch's flexible data model is unparalleled. You can nest fields as deeply as you want, have as many fields as you want, but whatever you want in those fields (as long as it stays the same type), and all of it will be searchable and you don't need to even declare a schema beforehand!
    • Elastic, the company behind Elasticsearch, is super strong financially and they have a great team of devs and product managers working on Elasticsearch. When I first started using ES 3 years ago, I was 90% impressed and knew it would be a good fit. 3 years later, I am 200% impressed and blown away by how far it has come and gotten even better. If there are features that are missing or you don't think it's fast enough right now, I bet it'll be suitable next year because the team behind it is so dang fast!
    • Elasticsearch is really, really stable. It takes a lot to bring down a cluster. It's self-balancing algorithms, leader-election system, self-healing properties are state of the art. We've never seen network failures or hard-drive corruption or CPU bugs bring down an ES cluster.
    Incentivized
    Read full review
    Cisco
    • Monitor hundreds of IT services by continuously tracking thousands of KPIs in a scalable way.
    • Quickly identify problem areas by a combination of default visualizations and ability to create custom dashboards.
    • Extremely configurable to effectively monitor nearly any KPI imaginable from Splunk.
    Incentivized
    Read full review
    Cons
    Elastic
    • Joining data requires duplicate de-normalized documents that make parent child relationships. It is hard and requires a lot of synchronizations
    • Tracking errors in the data in the logs can be hard, and sometimes recurring errors blow up the error logs
    • Schema changes require complete reindexing of an index
    Incentivized
    Read full review
    Cisco
    • ITSI really needs a robust splunk log ingestion infrastructure at its core
    • ITSI requires a great engineering team to build out the automated discovery and topology
    • Unless you use an API to build the topology, the view can quickly become static
    Incentivized
    Read full review
    Likelihood to Renew
    Elastic
    We're pretty heavily invested in ElasticSearch at this point, and there aren't any obvious negatives that would make us reconsider this decision.
    Incentivized
    Read full review
    Cisco
    We have replaced our monitoring platform with Splunk & ITSI, and with the success, it's seen at our organization thus far we would be hard-pressed to pivot to another tool. Frankly, our business partners and application teams love Splunk & ITSI.
    Read full review
    Usability
    Elastic
    To get started with Elasticsearch, you don't have to get very involved in configuring what really is an incredibly complex system under the hood. You simply install the package, run the service, and you're immediately able to begin using it. You don't need to learn any sort of query language to add data to Elasticsearch or perform some basic searching. If you're used to any sort of RESTful API, getting started with Elasticsearch is a breeze. If you've never interacted with a RESTful API directly, the journey may be a little more bumpy. Overall, though, it's incredibly simple to use for what it's doing under the covers.
    Incentivized
    Read full review
    Cisco
    Splunk IT Service Intelligence (ITSI) is a platform with extended functionality and provides various functionalities which can be utilized to improve the efficiency and accuracy in analyzing the data and detecting the attacks.
    Read full review
    Support Rating
    Elastic
    We've only used it as an opensource tooling. We did not purchase any additional support to roll out the elasticsearch software. When rolling out the application on our platform we've used the documentation which was available online. During our test phases we did not experience any bugs or issues so we did not rely on support at all.
    Incentivized
    Read full review
    Cisco
    During POC, pre-planning, and implementation, we have had interactions with numerous folks at Splunk. Everyone from sales & engineering to markets analysts to specific IT component SMEs, and a small professional services engagement to get started. They have all been exceptionally helpful and go above and beyond the call of duty. They actively reach out to ensure success is being realized and find ways to help proactively, instead of having to simply open support cases with the vendor.
    Read full review
    Implementation Rating
    Elastic
    Do not mix data and master roles. Dedicate at least 3 nodes just for Master
    Incentivized
    Read full review
    Cisco
    No answers on this topic
    Alternatives Considered
    Elastic
    As far as we are concerned, Elasticsearch is the gold standard and we have barely evaluated any alternatives. You could consider it an alternative to a relational or NoSQL database, so in cases where those suffice, you don't need Elasticsearch. But if you want powerful text-based search capabilities across large data sets, Elasticsearch is the way to go.
    Incentivized
    Read full review
    Cisco
    Splunk has raised itself as a platform not just as a tool unlike other products in the market. If I talk about Moogsoft it also has similar capabilities but Splunk ITSI has more visibility and its GUI is making a different impact on the users. ServiceNow and Splunk are equally capable products however Splunk seems to have more tech-savvy people tools than ServiceNow.
    Incentivized
    Read full review
    Return on Investment
    Elastic
    • We have had great luck with implementing Elasticsearch for our search and analytics use cases.
    • While the operational burden is not minimal, operating a cluster of servers, using a custom query language, writing Elasticsearch-specific bulk insert code, the performance and the relative operational ease of Elasticsearch are unparalleled.
    • We've easily saved hundreds of thousands of dollars implementing Elasticsearch vs. RDBMS vs. other no-SQL solutions for our specific set of problems.
    Incentivized
    Read full review
    Cisco
    • Splunk ITSI has reduced the number of alerts exposed to our Network Operations Center by 100x while increasing the context around outages.
    • Splunk ITSI has increased the accuracy of our incident detection by leveraging the Event Analytics system to weigh the behavior of the many characteristics of each component together instead of independently.
    • Splunk ITSI has reduced our incident MTTR (mean time to restore) by detecting issues faster, presenting them more clearly, and surfacing the salient details about the underlying issue.
    Read full review
    ScreenShots