Splunk On-Call is the cheapest name you are likely to have on this shortlist. Splunk's own pricing page lists it at $5 per user per month for up to ten seats, a fraction of what PagerDuty charges once its add-ons load. If price were the whole story, this comparison would be over in a paragraph.
It is not the whole story, because that price is attached to a product Splunk has largely stopped building. Splunk On-Call is the former VictorOps, acquired in 2018 and rebranded, and the sign-up form still routes you to a victorops.com URL. After Cisco completed its acquisition of Splunk in 2024, industry analysts reported that Splunk wound down the product and strategy teams behind VictorOps and its Incident Intelligence line, leaving engineering and support to maintain them while new incident-response investment moved toward Incident Intelligence inside Observability Cloud and a newer AI SRE. There is no public end-of-life notice, but the signals, stagnant releases, disbanded product teams, and reviews describing a tool that has barely changed in years, all point the same way.
So the real comparison is not close on price alone. PagerDuty is the actively developed, independent category incumbent, with mature AIOps, a GA AI agent, and an MCP server. Splunk On-Call is a capable but effectively frozen on-call tool, cheap and reliable at the basics, inside a suite whose incident-response future is being routed elsewhere. This walks through platform status, on-call, alert handling, incident response, AI, automation, the observability question, pricing, security, and that roadmap directly, so a low sticker price does not decide a multi-year commitment on its own.
Quick comparison at a glance
Read the table with the product-status column in mind. Several of Splunk On-Call's checks are real capabilities on a product that is not being meaningfully advanced.
Category
PagerDuty
Splunk On-Call
Product type
Digital-operations incident platform
On-call and alerting tool, former VictorOps
Maturity and status
Founded 2009, actively developed
VictorOps from 2012, maintenance mode under Cisco
On-call scheduling
✔, most configurable in the category
✔, rotations, overrides, escalations
Mobile app
✔
✔, well regarded
Alert noise reduction
Mature ML, AIOps add-on from $699/month
ML-based responder recommendations, rules engine
AI agent
✔, GA SRE Agent, needs Advance plus AIOps
✘
MCP server
✔, GA, Professional and above
✘
Automation
Automation add-on and process automation
Rules engine, limited
Status pages
Add-on from $89 per 1,000 subscribers
✘, not part of the product
Observability
✘, consumes alerts only
✘ in On-Call, separate in Splunk Observability Cloud
Pricing model
Per user plus add-ons
Per user, from $5 up to 10 seats
Owner
Independent, public
Cisco, via Splunk
Compliance
SOC 2, GDPR, FedRAMP authorized, HIPAA-eligible
SOC 2, GDPR, under Splunk and Cisco umbrella
Platform status and direction
The most important difference here is not a feature, it is momentum. One of these products is being actively developed, and the other is being maintained.
PagerDuty: the actively developed operations cloud
PagerDuty's Operations Cloud centers on an event pipeline that ingests alerts from more than 700 integrations, deduplicates and groups them, applies orchestration rules, and routes the result through escalation policies. It has shipped a steady stream of new capability, mature AIOps, a GA SRE Agent, an MCP server, agent-to-agent automation, and it remains an independent company whose entire roadmap points at incident operations. It collects none of the telemetry it routes, by design, but the product itself is advancing.
Splunk On-Call: VictorOps under maintenance
Splunk On-Call is the VictorOps engine with Splunk branding. It ingests alerts from Splunk products and hundreds of third-party tools, routes them to on-call responders through schedules and escalation policies, and drives notifications to a well-regarded mobile app. The core is solid, and for teams that want simple, cheap on-call it still works. What has changed is the trajectory. After the Cisco acquisition, analyst reporting indicated Splunk disbanded the product and strategy teams behind VictorOps, keeping the lights on through engineering and support while directing incident investment to Incident Intelligence within Observability Cloud. Recent user reviews describe long-standing bugs and a product that has not evolved. None of that breaks it today, but it shapes any decision measured in years rather than months.
Both, as the on-call product you are comparing, stop at the alert. The evidence behind it lives in a monitoring tool. For Splunk that tool exists, Observability Cloud, but it is a separate product with separate host-based pricing, not part of On-Call.
Platform aspect
PagerDuty
Splunk On-Call
Development status
Actively developed
Maintenance mode
Core engine
Operations Cloud event pipeline
VictorOps
Ownership
Independent, public
Cisco, via Splunk
Forward incident investment
This product
Incident Intelligence and AI SRE, elsewhere in Splunk
Telemetry collection
✘
✘
The search that lives in another product
PagerDuty routes the alert and Splunk On-Call pages the responder, but the logs that explain the incident live in a separate product, a different tab for PagerDuty, and a separately priced Observability Cloud subscription for Splunk. Better Stack keeps the search where the alert lands: logs, metrics, and traces sit in the same platform as on-call, queryable directly, so the engineer investigates without switching products or buying a second one.
When the alert and the query share a platform, there is no separate product to open, or to pay for.See how querying works.
On-call scheduling and escalation
This is the ground both products were built to cover, and it is where Splunk On-Call is strongest relative to its price. The gap is in configurability and in how actively each is maintained.
PagerDuty: the most configurable escalation engine in the category
PagerDuty's policies support unlimited tiers, multi-user escalation, time-based delays, automatic reassignment on no-acknowledgement, and iCal-imported schedules, scoped per service, per team, or globally. Paired with event orchestration, it absorbs enormous volume without paging a human for everything, and it is the deepest escalation logic in the market.
Splunk On-Call: solid scheduling and a strong mobile app
Splunk On-Call covers the essentials cleanly: rotations, overrides, escalation policies, and intelligent routing, with a mobile app that reviewers consistently single out as one of the better ones for actually waking people up. Its rules engine attaches runbooks, articles, and dashboards to incidents so responders have context on arrival, and machine-learning responder recommendations suggest who has the right expertise based on similar past incidents. For a small team that wants dependable paging at $5 a seat, this is more than enough. What it will not do is match PagerDuty's depth of escalation configuration, and it is not gaining new capability at PagerDuty's pace.
On-call feature
PagerDuty
Splunk On-Call
Rotations and overrides
✔
✔
Multi-tier escalation
✔, unlimited tiers
✔
Intelligent routing
✔, event orchestration
✔, rules engine
Responder recommendations
Via AIOps
✔, ML-based
Mobile app
✔
✔, well regarded
Configurability
Deepest in category
Solid, not deepening
Escalation on the same platform as the data
Both tools escalate well, and both escalate over alerts handed across from a monitoring product they do not own. Better Stack's escalation policies run on the same platform that captured the telemetry, so the page that reaches the on-call engineer carries the logs and traces behind it rather than a pointer to another system. The routing and the evidence are one product.
Escalation is more useful when the alert it delivers already has its evidence attached.See escalation flows.
Alert handling and noise reduction
Both reduce noise, but at very different levels of sophistication and cost. PagerDuty runs a mature ML pipeline as a paid add-on. Splunk On-Call relies on its rules engine and responder-recommendation model.
PagerDuty: a mature ML pipeline, sold as an add-on
PagerDuty's AIOps engine has learned from event patterns across thousands of enterprise customers for years. Alert grouping clusters correlated events into one incident, outlier detection flags the unusual, and probable-origin tracing points at the likely source. It lives in the AIOps add-on from $699 per month metered per accepted event, so the capability is strong and separately priced.
Splunk On-Call: rules engine and responder recommendations
Splunk On-Call approaches noise through its rules engine, which transforms, annotates, and routes incoming alerts, and through machine-learning responder recommendations and similar-incident context. This is useful, and it is included rather than a five-figure add-on, but it is not a dedicated correlation-and-suppression AIOps engine of PagerDuty's depth, and it has not advanced in recent cycles. For ordinary noise it is adequate. For extreme event volume, PagerDuty's engine is the more capable tool.
Noise reduction
PagerDuty
Splunk On-Call
Alert grouping and correlation
✔, mature ML, add-on
Rules engine
Suppression and transforms
✔, event orchestration
✔, rules engine
Responder recommendations
Via AIOps
✔, ML-based
Similar-incident context
✔
✔, audit trail
Pricing
Add-on from $699 per month
Included
Incident response and collaboration
Once an incident is open, both assemble responders and track the timeline. PagerDuty leans on workflows and its event model. Splunk On-Call leans on the collaboration and context features VictorOps built.
Splunk On-Call: context, audit trail, and the war room
Splunk On-Call centralizes the incident lifecycle: a timeline of what happened, an audit trail, cross-team collaboration, and post-incident reviews, with reporting on incident frequency, MTTA, and MTTR. Bi-directional ITSM integrations sync incidents to ServiceNow and similar systems. It is a competent incident hub, and customers cite dramatic MTTA improvements. The features are stable, which is both the appeal and the caution: stable here also means static.
PagerDuty: workflows and orchestrated response
PagerDuty automates coordination through incident workflows, available from the Business tier, that fire on declaration to open tickets, notify stakeholders, post to Slack, assign roles, and update status pages, gaining conditional branching and loops on the Digital Operations tier. It is more actively extended than Splunk On-Call's collaboration layer, and it ties into PagerDuty's newer AI capabilities rather than standing still.
Incident response
PagerDuty
Splunk On-Call
Timeline and audit trail
✔
✔
Cross-team collaboration
✔, Slack and Teams
✔
Post-incident review
✔, actively extended
✔, stable
Workflow automation
✔, incident workflows
Rules engine
ITSM sync
✔
✔, bi-directional
Reporting
✔
✔, MTTA and MTTR
AI and MCP
This is where the two diverge most sharply, and where a maintenance-mode product shows its age. PagerDuty has shipped an autonomous agent and an MCP server. Splunk On-Call has neither.
PagerDuty: mature AIOps, a GA SRE Agent, and MCP
Above AIOps sits a GA SRE Agent that recommends and executes diagnostics, with a virtual-responder mode in early access as of the August 2026 drop and agent-to-agent interaction with AWS and Azure agents heading to GA by the end of the first half of FY27. PagerDuty's MCP server is GA to Professional customers and above, so Claude or Cursor can query incidents, services, and schedules directly.
Splunk On-Call: ML recommendations, and no agent
Splunk On-Call's AI begins and ends with responder recommendations and similar-incident matching. There is no autonomous agent and no MCP server on the product. Splunk the company is investing in AI incident response, but through its newer AI SRE and Incident Intelligence lines inside Observability Cloud, not inside On-Call. So if agent-driven investigation or AI-assistant access matters to you, On-Call is not where Splunk is building it, and PagerDuty is well ahead on this axis regardless.
AI and MCP
PagerDuty
Splunk On-Call
ML noise reduction
✔, AIOps add-on
Responder recommendations
AI SRE agent
✔, GA, executes diagnostics
✘ in On-Call
MCP server
✔, GA, Professional and above
✘
AI investment location
This product
Elsewhere in Splunk
AI data source
Events plus connected tools
Alert and incident metadata
Automation
PagerDuty offers automation as a broad, separately sold product line. Splunk On-Call keeps automation to its rules engine.
PagerDuty's automation reaches past incident runbooks into event-driven jobs and, at the top end, process automation spanning change management and provisioning, priced as its own product with runbook automation around $125 per user per month plus an unpublished platform fee. Splunk On-Call's automation is its rules engine: transform and route alerts, attach runbooks and dashboards, trigger integrations. It handles in-incident context well but does not attempt PagerDuty's broader operational automation, and it is not being extended toward it.
Automation
PagerDuty
Splunk On-Call
In-incident automation
✔, automation add-on
✔, rules engine
Event-driven jobs
✔
Limited
Enterprise process automation
✔, dedicated product
✘
Actively extended
✔
✘
The observability question
Both products, as incident tools, leave the telemetry to something else, but the shape of that gap differs. PagerDuty has no observability at all and never claimed to. Splunk does have a full observability suite, Observability Cloud, with logs, metrics, traces, APM, RUM, and synthetics, but it is a separate product on separate host-based pricing, and the on-call piece integrated with it is Incident Intelligence, not the standalone On-Call you are comparing here.
So a team choosing Splunk On-Call for cheap paging is not choosing Splunk observability, and a team wanting Splunk's integrated incident-plus-observability experience is looking at Observability Cloud at $15 to $75 per host per month, a different product and a different bill. Either way, the on-call tool in this comparison hands investigation off to a separate system, exactly as PagerDuty does.
Observability capability
PagerDuty
Splunk On-Call
Log management
✘
✘ in On-Call, separate in Observability Cloud
Metrics and infrastructure
✘
✘ in On-Call, separate in Observability Cloud
Distributed tracing and APM
✘
✘ in On-Call, separate in Observability Cloud
Real user monitoring
✘
✘ in On-Call, separate in Observability Cloud
Uptime monitoring
✘
✘ in On-Call, separate in Observability Cloud
Investigation data in the on-call tool
External
External
The dashboard neither one draws
PagerDuty draws no dashboards from your telemetry because it holds none, and Splunk On-Call draws none because the telemetry lives in a separate Observability Cloud subscription. Better Stack builds charts directly from the logs, metrics, and traces on the same platform as the incident, by drag and drop or SQL, so the graph that explains the outage sits next to the escalation that raised it.
The chart that explains the incident should be one click from the page, not one product away.Build a chart in Better Stack.
Pricing
Price is Splunk On-Call's headline advantage, and it is real, with an asterisk. PagerDuty prices per user with the advanced capabilities in add-ons. Splunk On-Call is cheap, and you should understand what the low number does and does not include.
Splunk On-Call: cheap seats, a narrow product
Splunk lists On-Call at $5 per user per month for up to ten seats, billed annually, with larger deployments routed to sales. That is the lowest entry price in this whole category. The caveats are that lower-tier plans can feel stripped of essentials, with notification quotas and advanced features nudging you toward pricier arrangements, that the product is not being advanced, and that Splunk observability is an entirely separate host-based purchase. You are buying dependable, inexpensive paging, not a platform on a growth path.
PagerDuty: a competitive sticker, expensive add-ons
PagerDuty's tiers, on annual billing, are Free for up to 5 users, Professional at $21 per user per month, Business at $41 per user per month, and a custom Digital Operations tier. The capabilities teams want most sit in add-ons: AIOps from $699 per month metered per accepted event, PagerDuty Advance around $415 per month for the AI agents, and status pages from $89 per 1,000 subscribers. It is far more expensive than On-Call, and it buys an actively developed platform with AIOps, an AI agent, and an MCP server that On-Call does not offer.
Head-to-head cost for a 20-person team
The scenario assumes 20 responders and each vendor's realistic feature set for a team that wants noise reduction and modern AI. It excludes observability, which both leave to a separate product.
Cost component
PagerDuty
Splunk On-Call
Base seats
20 on Business at $41, so $820 per month
20 at roughly $5, so about $100 per month at small scale
Noise reduction
AIOps add-on from $699 per month
Rules engine included
AI features
Advance around $415 per month
✘, not in the product
Status pages
Add-on from $89 per month
✘
Monthly total, incident tooling
Roughly $2,023 per month
Around $100, with sales pricing above 10 seats
Observability platform
Separate, not included
Separate, Observability Cloud host pricing
Splunk On-Call is dramatically cheaper, and for a small team that wants nothing more than reliable paging, that is a legitimate reason to choose it. What the low price cannot buy is a modern AIOps engine, an AI agent, an MCP server, or a product on an active roadmap.
One bill instead of a host count and a seat count
The cheap on-call seat and the host-priced observability suite are two separate invoices, whether you assemble them from Splunk's own products or from PagerDuty plus a monitoring vendor. Better Stack charges by data volume plus $29 per responder, with monitoring, incident management, on-call, and status pages on one bill, so you are not reconciling a seat count against a host count across two products.
One platform means one invoice for the monitoring and the on-call, not a seat count beside a host count.See what one platform covers.
Security and compliance
Both cover the enterprise basics. Splunk On-Call carries SOC 2 and GDPR, and sits under the broader Splunk and Cisco compliance umbrella, which spans extensive certifications across the wider platform, though the standalone On-Call product's own scope is narrower and worth confirming for a regulated deployment. PagerDuty carries SOC 2 and GDPR plus a FedRAMP-authorized offering and HIPAA eligibility, which is a clear edge for public-sector and healthcare procurement.
Security and compliance
PagerDuty
Splunk On-Call
SOC 2 Type II
✔
✔
GDPR
✔
✔
HIPAA
✔, HIPAA-eligible
Confirm for On-Call scope
FedRAMP
✔, authorized offering
Via broader Splunk platform, confirm scope
SSO, SCIM, RBAC
✔
✔
Vendor umbrella
Independent
Splunk and Cisco
The roadmap question
For most comparisons the ownership note is a footnote. Here it is central, because it changes what you are actually buying. Splunk On-Call is a Cisco product by way of Splunk, built on VictorOps, and the credible reading of the last two years is that it is in maintenance rather than development. Analyst reporting after the Cisco deal described product and strategy teams for VictorOps and Incident Intelligence being wound down, and Splunk's own site steers new incident-response interest toward Incident Intelligence in Observability Cloud and a separate AI SRE. The tool still runs, still pages reliably, and still costs very little. But choosing it in 2026 means choosing a product whose vendor has signaled, through where it spends, that the future of its incident-response story is somewhere else.
PagerDuty is the opposite bet: more expensive, independent, and visibly investing in the product you would be buying. Neither fact decides the matter alone, but for a multi-year commitment the direction of travel belongs in the decision, not underneath it.
Where each platform fits
Reach for Splunk On-Call when the requirement is narrow and the budget is tight. If you want dependable paging with a strong mobile app for a small team, do not need modern AIOps or an AI agent, and can accept a product that is not advancing, its $5 seat is hard to argue with on cost alone.
Reach for PagerDuty when incident response is core and you expect the tool to keep growing with you. If you want the deepest escalation, mature ML noise reduction, a GA AI agent, an MCP server, FedRAMP on the checklist, and a vendor whose whole roadmap is this product, PagerDuty justifies its premium, provided you can absorb the add-on pricing.
The boundary they share stays in view for both. Whichever you pick, you are buying the response layer, the intelligence in each is bounded by the telemetry your monitoring exposes, and the total cost carries a separate observability bill either way.
Final thoughts
The $5-per-seat price that opens this comparison is useful, but it does not tell the whole story. Splunk On-Call is inexpensive because it is a mature, largely finished product, while PagerDuty costs more because it is still investing heavily in AIOps, agents, and integrations.
That makes the real deciding factor your time horizon. If you need straightforward on-call coverage right now, Splunk On-Call can still be a practical and inexpensive choice. If you are building an incident response program you expect to keep evolving over the next several years, PagerDuty's higher price buys you a platform that is still actively expanding.
The risk with Splunk On-Call is not what it can do today. It is what it may not become tomorrow. A stable product can be exactly what you need for a narrow use case, but that stability matters less if your requirements are likely to grow.
There is also one limitation both platforms share. When the page fires, you still need to open a separate monitoring or observability tool to find the evidence. That means another product, another bill, and another jump between the response workflow and the telemetry behind it.
So the deeper question is not only which platform can page your engineers more cheaply. It is whether the system coordinating the response should be separate from the system that already holds the data you need to resolve it.
One assistant, the whole stack
PagerDuty exposes its operational data over MCP, and Splunk On-Call offers no MCP server at all, so an AI assistant working either one stops at the alert and reaches elsewhere for the data. Better Stack's MCP server spans both sides: Claude or Cursor can query your logs with SQL, check who is on call, acknowledge an incident, and build a dashboard chart in one conversation, because the observability and the incident workflow are the same platform.
One MCP endpoint over the whole stack lets the assistant read the evidence and run the response from the same place.Try Better Stack.