# Rootly vs Splunk On-Call: An Incident Management comparison for 2026

Rootly's marketing lists Splunk On-Call among the legacy pagers it wants to replace. Rootly's documentation tells a more interesting story. Its VictorOps integration lets Rootly create, update, and resolve Splunk On-Call incidents, receive Splunk On-Call webhooks, and pull Splunk On-Call responders into a Rootly incident, and an optional migration flow imports Splunk On-Call teams into Rootly when you are ready to switch.

In other words, Rootly is built to sit on top of Splunk On-Call as well as to replace it. That changes the question. You are not only choosing between two tools, you are choosing between keeping your pager, adding a response layer above it, or moving everything to Rootly.

[ad-uptime]

The two products do different jobs, which is why combining them works. **Splunk On-Call is a long-standing paging and routing tool**, built as VictorOps and owned by Splunk since 2018, with a rules engine that shapes alerts and a mobile app users still praise. Rootly covers what Splunk On-Call leaves out. **Rootly is a Slack- and Teams-based response platform with its own pager**, adding incident channels, configurable workflows, status pages, an AI assistant, and a separately priced AI SRE.

This comparison covers where Splunk On-Call stands, the three ways to combine or replace these tools, paging, the response, AI, status pages and retrospectives, cost, and migration.

## Quick comparison

These are the rows buyers tend to check before anything else. Several of them explain why the two tools are often run together.

| Category | Rootly | Splunk On-Call |
|---|---|---|
| **Origin** | Independent startup | VictorOps, acquired by Splunk in 2018 |
| **Owner today** | Independent | Cisco, through Splunk |
| **Development** | Active | Maintenance, according to analysts and reviewers |
| **Core job** | Running the response | Paging the right person |
| **Integrates with the other** | ✔, escalates into Splunk On-Call and imports teams | Webhooks and API |
| **Alert shaping** | Alert routing in On-Call | ✔, rules engine with transforms and annotations |
| **Responder suggestions** | Catalog ownership | ✔, machine learning |
| **Incident channels in Slack or Teams** | ✔ | Slack integration |
| **Lifecycle workflows** | ✔ | ✘ |
| **Status pages** | ✔ | ✘ |
| **AI assistant** | ✔, Essentials | ✘ |
| **AI root-cause investigation** | ✔, AI SRE, priced by quote | ✘ |
| **MCP server** | ✔, GA since March 2026 | ✘ |
| **List price** | $20 per user for response, $20 for on-call | From $5 per user for up to 10 users |
| **Logs, metrics, traces** | ✘ | ✘, separate Splunk Observability Cloud |

## Where Splunk On-Call stands

Day to day, Splunk On-Call works as it always has: alerts flow in from Splunk and a long list of third-party tools, and people get paged through their schedules and the mobile app. Splunk has not announced an end-of-life date.

![Screenshot of Splunk On-Call incident dashboard](https://imagedelivery.net/xZXo0QFi-1_4Zimer-T0XQ/a1fa830c-7406-4ec7-3088-ae542589ec00/orig =1520x1000)

What has changed is the investment behind it. After Cisco bought Splunk in 2024, Constellation Research reported that the VictorOps product and strategy teams were wound down, leaving engineering and support to keep it running. Reviews in 2026 describe an interface that has barely moved in years, and Splunk's newer incident features go into Incident Intelligence inside Splunk Observability Cloud. Rootly is only one possible destination, and if you are still weighing others, the [Splunk On-Call alternatives](https://betterstack.com/community/comparisons/splunk-victorops-alternatives/) roundup lists the rest.

## Three ways to combine them

Rootly's integration gives you more choices than a straight swap, and each fits a different situation.

**Keep Splunk On-Call alone.** If paging is the whole job, incidents involve one or two people, and the bill matters most, Splunk On-Call still does that well for very little.

**Put Rootly on top of Splunk On-Call.** Splunk On-Call keeps receiving alerts and paging people. Rootly runs the incident in Slack or Teams, escalates into Splunk On-Call when it needs to reach a team, and pulls those responders into the incident. You buy only Rootly's incident response license, leave your schedules and rules engine untouched, and add workflows, status pages, and the AI assistant.

**Replace Splunk On-Call with Rootly On-Call.** Rootly imports your Splunk On-Call teams through its migration flow, you rebuild schedules and routing in Rootly On-Call, and everything lives in one product. This costs more per person but removes a tool whose future is uncertain.

Many teams move through these in order, starting with Rootly on top, then replacing the pager once the response side has proven itself.

| Approach | What you buy | Best for |
|---|---|---|
| **Splunk On-Call only** | Splunk On-Call | Small teams that only need paging |
| **Rootly on top** | Rootly Incident Response plus Splunk On-Call | Teams that want a better response without touching paging |
| **Full replacement** | Rootly Incident Response and On-Call | Teams leaving Splunk On-Call for good |

## Paging

Splunk On-Call's paging is mature. Rootly's is newer and aimed at the people on the rotation.

### Splunk On-Call: routing keys and a rules engine

Each incoming alert carries a routing key, and that key decides which team owns it. On the way through, the rules engine can edit the alert, add runbook links, dashboards, or notes, redirect it, or drop it entirely, so the person paged has context before they open a laptop. Machine learning suggests responders who handled similar problems before.

![Diagram of Splunk On-Call alert routing architecture](https://imagedelivery.net/xZXo0QFi-1_4Zimer-T0XQ/227a79b0-7d40-4a38-4f68-31512d48fd00/lg1x =2048x993)

Schedules support rotations, overrides, and multi-step escalation, and the mobile app is the part ex-customers most often say they miss.

![Screenshot of Splunk On-Call on-call schedule and rotation view](https://imagedelivery.net/xZXo0QFi-1_4Zimer-T0XQ/9d3ee33e-0b1a-402c-c8ae-7738a5691400/lg2x =760x500)

### Rootly On-Call: built for the rotation

Rootly On-Call is its own $20-per-user license and covers schedules, escalation policies, and overrides, and adds shadow rotations for engineers learning the rotation, detection of gaps in coverage, and routing for inbound phone calls. It can run without Rootly's incident response product, though most teams buy both. Rootly positions On-Call as a full PagerDuty replacement, and our [PagerDuty vs Rootly comparison](https://betterstack.com/community/comparisons/pagerduty-vs-rootly/) tests that claim against the tool Splunk On-Call users most often consider alongside it.

![Screenshot of Rootly on-call schedule and escalation view](https://imagedelivery.net/xZXo0QFi-1_4Zimer-T0XQ/67a07abb-4b14-473a-903a-dd71e0963000/lg1x =2838x1920)

| Paging | Rootly On-Call | Splunk On-Call |
|---|---|---|
| **Rotations and overrides** | ✔ | ✔ |
| **Multi-step escalation** | ✔ | ✔ |
| **Alert transforms and annotations** | Routing rules | ✔, rules engine |
| **Responder suggestions** | Catalog ownership | ✔, machine learning |
| **Shadow rotations** | ✔ | ✘ |
| **Coverage gap detection** | ✔ | ✘ |
| **Mobile app** | ✔ | ✔, long a strength |
| **Pricing** | $20 per user | Low per-user list price |

[summary]
### On-call that lives with the monitoring

<iframe class="aspect-video h-auto" width="100%" height="315" src="https://www.youtube.com/embed/E8JQPRVR20E" title="On-call Overview | Better Stack" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>

Splunk On-Call depends on routing keys from other tools, and Rootly On-Call is a second license on top of its response product. Better Stack runs on-call schedules and escalations in the same platform as its uptime checks, logs, and metrics, at $29 per responder with unlimited phone calls and SMS.

**When the monitor and the pager are one product, there is no routing key to get wrong.** [Explore Better Stack on-call](https://betterstack.com/incident-management).
[/summary]

## Running the response

This is the gap Rootly was built to fill.

Declare an incident in Rootly and it spins up a Slack or Teams channel, hands out roles, begins recording a timeline, and prompts whoever is leading with what to do next. Workflows react to severity changes, role assignments, and status updates, paging more people, creating tickets, and updating the status page as the incident develops.

![Screenshot of Rootly incident coordination and roles in Slack](https://imagedelivery.net/xZXo0QFi-1_4Zimer-T0XQ/5686aea2-1a90-4111-37dc-f8e8883c1a00/public =2856x1800)

![Screenshot of the Rootly full incident lifecycle overview](https://imagedelivery.net/xZXo0QFi-1_4Zimer-T0XQ/601d2089-fbb3-4ba2-7f22-9d12b04ba300/lg1x =3006x1382)

Splunk On-Call records what happened in each incident, supports multi-team collaboration, and keeps ServiceNow and similar ITSM tickets in step in both directions. The coordination itself, the channel, the bridge, and the notes, usually happens in Slack and a shared doc outside the product. That gap is the same one every chat-native tool points to, and our [incident.io vs Splunk On-Call comparison](https://betterstack.com/community/comparisons/incident-io-vs-splunk-on-call/) looks at it from incident.io's side.

![Screenshot of Splunk On-Call incident timeline and collaboration view](https://imagedelivery.net/xZXo0QFi-1_4Zimer-T0XQ/0a83d8b9-3817-4249-a133-0f5217d27100/lg1x =760x500)

| Response | Rootly | Splunk On-Call |
|---|---|---|
| **Automatic incident channel** | ✔ | ✘ |
| **Role assignment** | ✔ | ✘ |
| **Lifecycle workflows** | ✔ | ✘ |
| **Timeline and audit trail** | ✔ | ✔ |
| **ITSM ticket sync** | Jira, ServiceNow, and others | ServiceNow and others, bidirectional |

[summary]
### Watch the logs from inside the incident

<iframe class="aspect-video h-auto" width="100%" height="315" src="https://www.youtube.com/embed/kGdyxT1JnqQ" title="Live Tail | Better Stack" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>

Rootly gives responders a channel and Splunk On-Call gives them a timeline, but confirming a fix still means opening a separate log tool. Better Stack lets responders live tail the affected services' logs from the platform that paged them, so they can watch errors stop in real time.

**The surest sign a fix worked is the error stream going quiet while you watch.** [See Better Stack log management](https://betterstack.com/log-management).
[/summary]

## AI and MCP

Splunk On-Call's smarts predate the current AI wave: a model that recommends responders based on who fixed similar problems, and links to related past incidents.

![Screenshot of Splunk On-Call responder suggestions](https://imagedelivery.net/xZXo0QFi-1_4Zimer-T0XQ/cbacd243-0efe-44eb-2ddd-a0c4de3df400/orig =760x500)

Rootly includes an AI assistant on Essentials that catches late joiners up, answers questions about the incident, and drafts the retrospective. The AI SRE, sold separately, investigates while people work, weighing recent changes, related alerts, and past incidents, and posts a likely cause with a confidence score. For assistants, Rootly ships an MCP server, GA since March 2026, that you can use hosted or self-hosted to give Claude and similar tools read and write access to incidents, alerts, and schedules. Splunk On-Call has no MCP server.

![Screenshot of Rootly AI SRE root cause analysis](https://imagedelivery.net/xZXo0QFi-1_4Zimer-T0XQ/06969716-5cfb-480f-9fff-937b35334800/md1x =1904x1124)

| AI and MCP | Rootly | Splunk On-Call |
|---|---|---|
| **Responder suggestions** | Catalog ownership | ✔ |
| **Incident summaries** | ✔ | ✘ |
| **AI retrospective drafts** | ✔ | ✘ |
| **Root-cause hypothesis** | ✔, AI SRE | ✘ |
| **MCP server** | ✔ | ✘ |

## Status pages and retrospectives

Status pages come with Rootly Essentials, and because workflows control them, customers can be updated the moment severity changes. Splunk On-Call has none, so most of its customers run a separate status page product.

![Screenshot of Rootly status pages](https://imagedelivery.net/xZXo0QFi-1_4Zimer-T0XQ/3b9e0fcf-b920-4c95-f22f-ead31e3c3d00/md2x =3464x1945)

Rootly's AI turns the recorded channel history into a first-draft retrospective and pushes action items to your tracker. Splunk On-Call offers post-incident reviews plus standard reports on volume and response times, largely unchanged for years.

| Status and review | Rootly | Splunk On-Call |
|---|---|---|
| **Status pages** | ✔ | ✘ |
| **Retrospectives** | ✔, AI-drafted | Post-incident reviews |
| **Follow-up sync** | ✔ | Via ITSM sync |
| **MTTA and MTTR reporting** | ✔ | ✔ |

[summary]
### Post-mortems with the evidence attached

<iframe class="aspect-video h-auto" width="100%" height="315" src="https://www.youtube.com/embed/aaJ_YYYvN_4" title="Post-mortems | Better Stack" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>

Rootly drafts retrospectives from its chat timeline, and Splunk On-Call reports response times, but neither can include the logs and metrics that show what failed. Better Stack builds post-mortems from incidents that already carry their triggering telemetry.

**A post-mortem is easier to trust when the graphs are in it.** [See Better Stack post-mortems](https://betterstack.com/incident-management).
[/summary]

## The telemetry neither tool holds

Neither tool stores logs, metrics, or traces. Splunk does sell observability, but as Splunk Observability Cloud, a different contract priced by host that On-Call customers do not get by default. Rootly's AI SRE works from whatever your monitoring integrations pass in. Either way, responders keep a monitoring tool open throughout an investigation.

| Observability | Rootly | Splunk On-Call |
|---|---|---|
| **Logs, metrics, traces** | ✘ | ✘, separate Splunk products |
| **Uptime monitoring** | ✘ | ✘ |
| **Where investigation data lives** | Connected integrations | Connected integrations |

[summary]
### Fast queries without a second contract

<iframe class="aspect-video h-auto" width="100%" height="315" src="https://www.youtube.com/embed/Zi7pi0JsgXs" title="Query Boost | Better Stack" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>

Splunk's observability is a separate purchase from its pager, and Rootly holds no telemetry at all. Better Stack stores logs, metrics, and traces in one warehouse you query with SQL, with Query Boost keeping searches fast at volume, and runs on-call and incidents on the same platform.

**Paying for the pager and the evidence under one contract is simpler than reconciling two.** [See Better Stack dashboards](https://betterstack.com/dashboards).
[/summary]

## What each approach costs

Splunk's published On-Call price is $5 a user per month, billed annually, covering up to 10 users, with larger deployments quoted by sales and older listings showing tiers between $10 and $45. Rootly charges $20 per user for Incident Response Essentials and $20 for On-Call Essentials, with the AI SRE priced separately.

For a 25-person engineering team with 10 people taking pages, list prices work out like this. Splunk's figure for 25 users is an estimate.

| Cost component | Splunk On-Call only | Rootly on top of Splunk On-Call | Full Rootly |
|---|---|---|---|
| **Paging** | About $125, sales quote likely | About $125, sales quote likely | 10 at $20, so $200 |
| **Incident response** | ✘ | 25 at $20, so $500 | 25 at $20, so $500 |
| **Monthly total** | About $125 | About $625 | About $700 |
| **Status pages** | Separate product | Included | Included |
| **AI** | ✘ | Assistant included, AI SRE extra | Assistant included, AI SRE extra |

Layering Rootly on top costs almost as much as replacing the pager outright. The main reason to layer is to avoid migrating schedules and routing rules all at once, not to save money.

## Migrating to Rootly

If you decide to replace Splunk On-Call, plan it in stages.

1. **Connect Rootly's VictorOps integration first,** so Rootly runs incidents while Splunk On-Call keeps paging.
2. **Import teams** through Rootly's migration flow, if it is enabled for your workspace.
3. **Translate routing keys into Rootly teams and services,** and decide which rules-engine logic becomes alert routing and which becomes workflows.
4. **Switch alert sources over gradually,** and leave Splunk On-Call in place as a safety net until each source pages correctly through Rootly.
5. **Overlap the two for a complete rotation cycle,** and line the final cutover up with your Splunk contract end date.

## Which one fits your team

Keep Splunk On-Call by itself if paging is all you need and cost matters most. It remains reliable and familiar, though you should revisit the decision at each renewal.

Put Rootly on top if your incidents have outgrown a pager and a shared doc, but you are not ready to move schedules and routing rules. You get the Slack response, status pages, and AI assistant without touching the pager.

Move fully to Rootly if you want one actively developed product for paging and response, plus access to an AI SRE and an MCP server. Budget for both licenses for anyone who responds and carries the pager.

## Final thoughts

Rootly's integration turns this from a replacement decision into a sequence. **Splunk On-Call can keep paging people while Rootly takes over everything after the page**, which lets you fix the response before you touch the pager.

So the real question is not whether to leave Splunk On-Call, but in what order. **If your incidents feel chaotic, start with the layer on top, and let the pager be the last thing you migrate.**

[summary]
### One MCP endpoint for incidents and telemetry

<iframe class="aspect-video h-auto" width="100%" height="315" src="https://www.youtube.com/embed/ddfuZrT7RCg" title="MCP Server | Better Stack" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>

Rootly's MCP server exposes incident data, and Splunk On-Call has no MCP server at all, but neither can give an AI assistant your logs or traces, because neither stores them. Better Stack's MCP server covers the whole platform, so Claude or Cursor can query your logs with SQL, check who is on call, acknowledge an incident, and build a dashboard chart in one conversation.

**With incidents and telemetry behind one MCP endpoint, your assistant can investigate and respond without switching tools.** [Try Better Stack](https://betterstack.com).
[/summary]
