Rootly's marketing lists Splunk On-Call among the legacy pagers it wants to replace. Rootly's documentation tells a more interesting story. Its VictorOps integration lets Rootly create, update, and resolve Splunk On-Call incidents, receive Splunk On-Call webhooks, and pull Splunk On-Call responders into a Rootly incident, and an optional migration flow imports Splunk On-Call teams into Rootly when you are ready to switch.
In other words, Rootly is built to sit on top of Splunk On-Call as well as to replace it. That changes the question. You are not only choosing between two tools, you are choosing between keeping your pager, adding a response layer above it, or moving everything to Rootly.
The two products do different jobs, which is why combining them works. Splunk On-Call is a long-standing paging and routing tool, built as VictorOps and owned by Splunk since 2018, with a rules engine that shapes alerts and a mobile app users still praise. Rootly covers what Splunk On-Call leaves out. Rootly is a Slack- and Teams-based response platform with its own pager, adding incident channels, configurable workflows, status pages, an AI assistant, and a separately priced AI SRE.
This comparison covers where Splunk On-Call stands, the three ways to combine or replace these tools, paging, the response, AI, status pages and retrospectives, cost, and migration.
Quick comparison
These are the rows buyers tend to check before anything else. Several of them explain why the two tools are often run together.
Category
Rootly
Splunk On-Call
Origin
Independent startup
VictorOps, acquired by Splunk in 2018
Owner today
Independent
Cisco, through Splunk
Development
Active
Maintenance, according to analysts and reviewers
Core job
Running the response
Paging the right person
Integrates with the other
✔, escalates into Splunk On-Call and imports teams
Webhooks and API
Alert shaping
Alert routing in On-Call
✔, rules engine with transforms and annotations
Responder suggestions
Catalog ownership
✔, machine learning
Incident channels in Slack or Teams
✔
Slack integration
Lifecycle workflows
✔
✘
Status pages
✔
✘
AI assistant
✔, Essentials
✘
AI root-cause investigation
✔, AI SRE, priced by quote
✘
MCP server
✔, GA since March 2026
✘
List price
$20 per user for response, $20 for on-call
From $5 per user for up to 10 users
Logs, metrics, traces
✘
✘, separate Splunk Observability Cloud
Where Splunk On-Call stands
Day to day, Splunk On-Call works as it always has: alerts flow in from Splunk and a long list of third-party tools, and people get paged through their schedules and the mobile app. Splunk has not announced an end-of-life date.
What has changed is the investment behind it. After Cisco bought Splunk in 2024, Constellation Research reported that the VictorOps product and strategy teams were wound down, leaving engineering and support to keep it running. Reviews in 2026 describe an interface that has barely moved in years, and Splunk's newer incident features go into Incident Intelligence inside Splunk Observability Cloud. Rootly is only one possible destination, and if you are still weighing others, the Splunk On-Call alternatives roundup lists the rest.
Three ways to combine them
Rootly's integration gives you more choices than a straight swap, and each fits a different situation.
Keep Splunk On-Call alone. If paging is the whole job, incidents involve one or two people, and the bill matters most, Splunk On-Call still does that well for very little.
Put Rootly on top of Splunk On-Call. Splunk On-Call keeps receiving alerts and paging people. Rootly runs the incident in Slack or Teams, escalates into Splunk On-Call when it needs to reach a team, and pulls those responders into the incident. You buy only Rootly's incident response license, leave your schedules and rules engine untouched, and add workflows, status pages, and the AI assistant.
Replace Splunk On-Call with Rootly On-Call. Rootly imports your Splunk On-Call teams through its migration flow, you rebuild schedules and routing in Rootly On-Call, and everything lives in one product. This costs more per person but removes a tool whose future is uncertain.
Many teams move through these in order, starting with Rootly on top, then replacing the pager once the response side has proven itself.
Approach
What you buy
Best for
Splunk On-Call only
Splunk On-Call
Small teams that only need paging
Rootly on top
Rootly Incident Response plus Splunk On-Call
Teams that want a better response without touching paging
Full replacement
Rootly Incident Response and On-Call
Teams leaving Splunk On-Call for good
Paging
Splunk On-Call's paging is mature. Rootly's is newer and aimed at the people on the rotation.
Splunk On-Call: routing keys and a rules engine
Each incoming alert carries a routing key, and that key decides which team owns it. On the way through, the rules engine can edit the alert, add runbook links, dashboards, or notes, redirect it, or drop it entirely, so the person paged has context before they open a laptop. Machine learning suggests responders who handled similar problems before.
Schedules support rotations, overrides, and multi-step escalation, and the mobile app is the part ex-customers most often say they miss.
Rootly On-Call: built for the rotation
Rootly On-Call is its own $20-per-user license and covers schedules, escalation policies, and overrides, and adds shadow rotations for engineers learning the rotation, detection of gaps in coverage, and routing for inbound phone calls. It can run without Rootly's incident response product, though most teams buy both. Rootly positions On-Call as a full PagerDuty replacement, and our PagerDuty vs Rootly comparison tests that claim against the tool Splunk On-Call users most often consider alongside it.
Paging
Rootly On-Call
Splunk On-Call
Rotations and overrides
✔
✔
Multi-step escalation
✔
✔
Alert transforms and annotations
Routing rules
✔, rules engine
Responder suggestions
Catalog ownership
✔, machine learning
Shadow rotations
✔
✘
Coverage gap detection
✔
✘
Mobile app
✔
✔, long a strength
Pricing
$20 per user
Low per-user list price
On-call that lives with the monitoring
Splunk On-Call depends on routing keys from other tools, and Rootly On-Call is a second license on top of its response product. Better Stack runs on-call schedules and escalations in the same platform as its uptime checks, logs, and metrics, at $29 per responder with unlimited phone calls and SMS.
When the monitor and the pager are one product, there is no routing key to get wrong.Explore Better Stack on-call.
Running the response
This is the gap Rootly was built to fill.
Declare an incident in Rootly and it spins up a Slack or Teams channel, hands out roles, begins recording a timeline, and prompts whoever is leading with what to do next. Workflows react to severity changes, role assignments, and status updates, paging more people, creating tickets, and updating the status page as the incident develops.
Splunk On-Call records what happened in each incident, supports multi-team collaboration, and keeps ServiceNow and similar ITSM tickets in step in both directions. The coordination itself, the channel, the bridge, and the notes, usually happens in Slack and a shared doc outside the product. That gap is the same one every chat-native tool points to, and our incident.io vs Splunk On-Call comparison looks at it from incident.io's side.
Response
Rootly
Splunk On-Call
Automatic incident channel
✔
✘
Role assignment
✔
✘
Lifecycle workflows
✔
✘
Timeline and audit trail
✔
✔
ITSM ticket sync
Jira, ServiceNow, and others
ServiceNow and others, bidirectional
Watch the logs from inside the incident
Rootly gives responders a channel and Splunk On-Call gives them a timeline, but confirming a fix still means opening a separate log tool. Better Stack lets responders live tail the affected services' logs from the platform that paged them, so they can watch errors stop in real time.
Splunk On-Call's smarts predate the current AI wave: a model that recommends responders based on who fixed similar problems, and links to related past incidents.
Rootly includes an AI assistant on Essentials that catches late joiners up, answers questions about the incident, and drafts the retrospective. The AI SRE, sold separately, investigates while people work, weighing recent changes, related alerts, and past incidents, and posts a likely cause with a confidence score. For assistants, Rootly ships an MCP server, GA since March 2026, that you can use hosted or self-hosted to give Claude and similar tools read and write access to incidents, alerts, and schedules. Splunk On-Call has no MCP server.
AI and MCP
Rootly
Splunk On-Call
Responder suggestions
Catalog ownership
✔
Incident summaries
✔
✘
AI retrospective drafts
✔
✘
Root-cause hypothesis
✔, AI SRE
✘
MCP server
✔
✘
Status pages and retrospectives
Status pages come with Rootly Essentials, and because workflows control them, customers can be updated the moment severity changes. Splunk On-Call has none, so most of its customers run a separate status page product.
Rootly's AI turns the recorded channel history into a first-draft retrospective and pushes action items to your tracker. Splunk On-Call offers post-incident reviews plus standard reports on volume and response times, largely unchanged for years.
Status and review
Rootly
Splunk On-Call
Status pages
✔
✘
Retrospectives
✔, AI-drafted
Post-incident reviews
Follow-up sync
✔
Via ITSM sync
MTTA and MTTR reporting
✔
✔
Post-mortems with the evidence attached
Rootly drafts retrospectives from its chat timeline, and Splunk On-Call reports response times, but neither can include the logs and metrics that show what failed. Better Stack builds post-mortems from incidents that already carry their triggering telemetry.
Neither tool stores logs, metrics, or traces. Splunk does sell observability, but as Splunk Observability Cloud, a different contract priced by host that On-Call customers do not get by default. Rootly's AI SRE works from whatever your monitoring integrations pass in. Either way, responders keep a monitoring tool open throughout an investigation.
Observability
Rootly
Splunk On-Call
Logs, metrics, traces
✘
✘, separate Splunk products
Uptime monitoring
✘
✘
Where investigation data lives
Connected integrations
Connected integrations
Fast queries without a second contract
Splunk's observability is a separate purchase from its pager, and Rootly holds no telemetry at all. Better Stack stores logs, metrics, and traces in one warehouse you query with SQL, with Query Boost keeping searches fast at volume, and runs on-call and incidents on the same platform.
Paying for the pager and the evidence under one contract is simpler than reconciling two.See Better Stack dashboards.
What each approach costs
Splunk's published On-Call price is $5 a user per month, billed annually, covering up to 10 users, with larger deployments quoted by sales and older listings showing tiers between $10 and $45. Rootly charges $20 per user for Incident Response Essentials and $20 for On-Call Essentials, with the AI SRE priced separately.
For a 25-person engineering team with 10 people taking pages, list prices work out like this. Splunk's figure for 25 users is an estimate.
Cost component
Splunk On-Call only
Rootly on top of Splunk On-Call
Full Rootly
Paging
About $125, sales quote likely
About $125, sales quote likely
10 at $20, so $200
Incident response
✘
25 at $20, so $500
25 at $20, so $500
Monthly total
About $125
About $625
About $700
Status pages
Separate product
Included
Included
AI
✘
Assistant included, AI SRE extra
Assistant included, AI SRE extra
Layering Rootly on top costs almost as much as replacing the pager outright. The main reason to layer is to avoid migrating schedules and routing rules all at once, not to save money.
Migrating to Rootly
If you decide to replace Splunk On-Call, plan it in stages.
Connect Rootly's VictorOps integration first, so Rootly runs incidents while Splunk On-Call keeps paging.
Import teams through Rootly's migration flow, if it is enabled for your workspace.
Translate routing keys into Rootly teams and services, and decide which rules-engine logic becomes alert routing and which becomes workflows.
Switch alert sources over gradually, and leave Splunk On-Call in place as a safety net until each source pages correctly through Rootly.
Overlap the two for a complete rotation cycle, and line the final cutover up with your Splunk contract end date.
Which one fits your team
Keep Splunk On-Call by itself if paging is all you need and cost matters most. It remains reliable and familiar, though you should revisit the decision at each renewal.
Put Rootly on top if your incidents have outgrown a pager and a shared doc, but you are not ready to move schedules and routing rules. You get the Slack response, status pages, and AI assistant without touching the pager.
Move fully to Rootly if you want one actively developed product for paging and response, plus access to an AI SRE and an MCP server. Budget for both licenses for anyone who responds and carries the pager.
Final thoughts
Rootly's integration turns this from a replacement decision into a sequence. Splunk On-Call can keep paging people while Rootly takes over everything after the page, which lets you fix the response before you touch the pager.
So the real question is not whether to leave Splunk On-Call, but in what order. If your incidents feel chaotic, start with the layer on top, and let the pager be the last thing you migrate.
One MCP endpoint for incidents and telemetry
Rootly's MCP server exposes incident data, and Splunk On-Call has no MCP server at all, but neither can give an AI assistant your logs or traces, because neither stores them. Better Stack's MCP server covers the whole platform, so Claude or Cursor can query your logs with SQL, check who is on call, acknowledge an incident, and build a dashboard chart in one conversation.
With incidents and telemetry behind one MCP endpoint, your assistant can investigate and respond without switching tools.Try Better Stack.