Rootly vs Splunk On-Call: An Incident Management comparison for 2026

Stanley Ulili
Updated on October 8, 2026

Rootly's marketing lists Splunk On-Call among the legacy pagers it wants to replace. Rootly's documentation tells a more interesting story. Its VictorOps integration lets Rootly create, update, and resolve Splunk On-Call incidents, receive Splunk On-Call webhooks, and pull Splunk On-Call responders into a Rootly incident, and an optional migration flow imports Splunk On-Call teams into Rootly when you are ready to switch.

In other words, Rootly is built to sit on top of Splunk On-Call as well as to replace it. That changes the question. You are not only choosing between two tools, you are choosing between keeping your pager, adding a response layer above it, or moving everything to Rootly.

The two products do different jobs, which is why combining them works. Splunk On-Call is a long-standing paging and routing tool, built as VictorOps and owned by Splunk since 2018, with a rules engine that shapes alerts and a mobile app users still praise. Rootly covers what Splunk On-Call leaves out. Rootly is a Slack- and Teams-based response platform with its own pager, adding incident channels, configurable workflows, status pages, an AI assistant, and a separately priced AI SRE.

This comparison covers where Splunk On-Call stands, the three ways to combine or replace these tools, paging, the response, AI, status pages and retrospectives, cost, and migration.

Quick comparison

These are the rows buyers tend to check before anything else. Several of them explain why the two tools are often run together.

Category Rootly Splunk On-Call
Origin Independent startup VictorOps, acquired by Splunk in 2018
Owner today Independent Cisco, through Splunk
Development Active Maintenance, according to analysts and reviewers
Core job Running the response Paging the right person
Integrates with the other ✔, escalates into Splunk On-Call and imports teams Webhooks and API
Alert shaping Alert routing in On-Call ✔, rules engine with transforms and annotations
Responder suggestions Catalog ownership ✔, machine learning
Incident channels in Slack or Teams ✔ Slack integration
Lifecycle workflows ✔ ✘
Status pages ✔ ✘
AI assistant ✔, Essentials ✘
AI root-cause investigation ✔, AI SRE, priced by quote ✘
MCP server ✔, GA since March 2026 ✘
List price $20 per user for response, $20 for on-call From $5 per user for up to 10 users
Logs, metrics, traces ✘ ✘, separate Splunk Observability Cloud

Where Splunk On-Call stands

Day to day, Splunk On-Call works as it always has: alerts flow in from Splunk and a long list of third-party tools, and people get paged through their schedules and the mobile app. Splunk has not announced an end-of-life date.

Screenshot of Splunk On-Call incident dashboard

What has changed is the investment behind it. After Cisco bought Splunk in 2024, Constellation Research reported that the VictorOps product and strategy teams were wound down, leaving engineering and support to keep it running. Reviews in 2026 describe an interface that has barely moved in years, and Splunk's newer incident features go into Incident Intelligence inside Splunk Observability Cloud. Rootly is only one possible destination, and if you are still weighing others, the Splunk On-Call alternatives roundup lists the rest.

Three ways to combine them

Rootly's integration gives you more choices than a straight swap, and each fits a different situation.

Keep Splunk On-Call alone. If paging is the whole job, incidents involve one or two people, and the bill matters most, Splunk On-Call still does that well for very little.

Put Rootly on top of Splunk On-Call. Splunk On-Call keeps receiving alerts and paging people. Rootly runs the incident in Slack or Teams, escalates into Splunk On-Call when it needs to reach a team, and pulls those responders into the incident. You buy only Rootly's incident response license, leave your schedules and rules engine untouched, and add workflows, status pages, and the AI assistant.

Replace Splunk On-Call with Rootly On-Call. Rootly imports your Splunk On-Call teams through its migration flow, you rebuild schedules and routing in Rootly On-Call, and everything lives in one product. This costs more per person but removes a tool whose future is uncertain.

Many teams move through these in order, starting with Rootly on top, then replacing the pager once the response side has proven itself.

Approach What you buy Best for
Splunk On-Call only Splunk On-Call Small teams that only need paging
Rootly on top Rootly Incident Response plus Splunk On-Call Teams that want a better response without touching paging
Full replacement Rootly Incident Response and On-Call Teams leaving Splunk On-Call for good

Paging

Splunk On-Call's paging is mature. Rootly's is newer and aimed at the people on the rotation.

Splunk On-Call: routing keys and a rules engine

Each incoming alert carries a routing key, and that key decides which team owns it. On the way through, the rules engine can edit the alert, add runbook links, dashboards, or notes, redirect it, or drop it entirely, so the person paged has context before they open a laptop. Machine learning suggests responders who handled similar problems before.

Diagram of Splunk On-Call alert routing architecture

Schedules support rotations, overrides, and multi-step escalation, and the mobile app is the part ex-customers most often say they miss.

Screenshot of Splunk On-Call on-call schedule and rotation view

Rootly On-Call: built for the rotation

Rootly On-Call is its own $20-per-user license and covers schedules, escalation policies, and overrides, and adds shadow rotations for engineers learning the rotation, detection of gaps in coverage, and routing for inbound phone calls. It can run without Rootly's incident response product, though most teams buy both. Rootly positions On-Call as a full PagerDuty replacement, and our PagerDuty vs Rootly comparison tests that claim against the tool Splunk On-Call users most often consider alongside it.

Screenshot of Rootly on-call schedule and escalation view

Paging Rootly On-Call Splunk On-Call
Rotations and overrides ✔ ✔
Multi-step escalation ✔ ✔
Alert transforms and annotations Routing rules ✔, rules engine
Responder suggestions Catalog ownership ✔, machine learning
Shadow rotations ✔ ✘
Coverage gap detection ✔ ✘
Mobile app ✔ ✔, long a strength
Pricing $20 per user Low per-user list price

On-call that lives with the monitoring

Splunk On-Call depends on routing keys from other tools, and Rootly On-Call is a second license on top of its response product. Better Stack runs on-call schedules and escalations in the same platform as its uptime checks, logs, and metrics, at $29 per responder with unlimited phone calls and SMS.

When the monitor and the pager are one product, there is no routing key to get wrong. Explore Better Stack on-call.

Running the response

This is the gap Rootly was built to fill.

Declare an incident in Rootly and it spins up a Slack or Teams channel, hands out roles, begins recording a timeline, and prompts whoever is leading with what to do next. Workflows react to severity changes, role assignments, and status updates, paging more people, creating tickets, and updating the status page as the incident develops.

Screenshot of Rootly incident coordination and roles in Slack

Screenshot of the Rootly full incident lifecycle overview

Splunk On-Call records what happened in each incident, supports multi-team collaboration, and keeps ServiceNow and similar ITSM tickets in step in both directions. The coordination itself, the channel, the bridge, and the notes, usually happens in Slack and a shared doc outside the product. That gap is the same one every chat-native tool points to, and our incident.io vs Splunk On-Call comparison looks at it from incident.io's side.

Screenshot of Splunk On-Call incident timeline and collaboration view

Response Rootly Splunk On-Call
Automatic incident channel ✔ ✘
Role assignment ✔ ✘
Lifecycle workflows ✔ ✘
Timeline and audit trail ✔ ✔
ITSM ticket sync Jira, ServiceNow, and others ServiceNow and others, bidirectional

Watch the logs from inside the incident

Rootly gives responders a channel and Splunk On-Call gives them a timeline, but confirming a fix still means opening a separate log tool. Better Stack lets responders live tail the affected services' logs from the platform that paged them, so they can watch errors stop in real time.

The surest sign a fix worked is the error stream going quiet while you watch. See Better Stack log management.

AI and MCP

Splunk On-Call's smarts predate the current AI wave: a model that recommends responders based on who fixed similar problems, and links to related past incidents.

Screenshot of Splunk On-Call responder suggestions

Rootly includes an AI assistant on Essentials that catches late joiners up, answers questions about the incident, and drafts the retrospective. The AI SRE, sold separately, investigates while people work, weighing recent changes, related alerts, and past incidents, and posts a likely cause with a confidence score. For assistants, Rootly ships an MCP server, GA since March 2026, that you can use hosted or self-hosted to give Claude and similar tools read and write access to incidents, alerts, and schedules. Splunk On-Call has no MCP server.

Screenshot of Rootly AI SRE root cause analysis

AI and MCP Rootly Splunk On-Call
Responder suggestions Catalog ownership ✔
Incident summaries ✔ ✘
AI retrospective drafts ✔ ✘
Root-cause hypothesis ✔, AI SRE ✘
MCP server ✔ ✘

Status pages and retrospectives

Status pages come with Rootly Essentials, and because workflows control them, customers can be updated the moment severity changes. Splunk On-Call has none, so most of its customers run a separate status page product.

Screenshot of Rootly status pages

Rootly's AI turns the recorded channel history into a first-draft retrospective and pushes action items to your tracker. Splunk On-Call offers post-incident reviews plus standard reports on volume and response times, largely unchanged for years.

Status and review Rootly Splunk On-Call
Status pages ✔ ✘
Retrospectives ✔, AI-drafted Post-incident reviews
Follow-up sync ✔ Via ITSM sync
MTTA and MTTR reporting ✔ ✔

Post-mortems with the evidence attached

Rootly drafts retrospectives from its chat timeline, and Splunk On-Call reports response times, but neither can include the logs and metrics that show what failed. Better Stack builds post-mortems from incidents that already carry their triggering telemetry.

A post-mortem is easier to trust when the graphs are in it. See Better Stack post-mortems.

The telemetry neither tool holds

Neither tool stores logs, metrics, or traces. Splunk does sell observability, but as Splunk Observability Cloud, a different contract priced by host that On-Call customers do not get by default. Rootly's AI SRE works from whatever your monitoring integrations pass in. Either way, responders keep a monitoring tool open throughout an investigation.

Observability Rootly Splunk On-Call
Logs, metrics, traces ✘ ✘, separate Splunk products
Uptime monitoring ✘ ✘
Where investigation data lives Connected integrations Connected integrations

Fast queries without a second contract

Splunk's observability is a separate purchase from its pager, and Rootly holds no telemetry at all. Better Stack stores logs, metrics, and traces in one warehouse you query with SQL, with Query Boost keeping searches fast at volume, and runs on-call and incidents on the same platform.

Paying for the pager and the evidence under one contract is simpler than reconciling two. See Better Stack dashboards.

What each approach costs

Splunk's published On-Call price is $5 a user per month, billed annually, covering up to 10 users, with larger deployments quoted by sales and older listings showing tiers between $10 and $45. Rootly charges $20 per user for Incident Response Essentials and $20 for On-Call Essentials, with the AI SRE priced separately.

For a 25-person engineering team with 10 people taking pages, list prices work out like this. Splunk's figure for 25 users is an estimate.

Cost component Splunk On-Call only Rootly on top of Splunk On-Call Full Rootly
Paging About $125, sales quote likely About $125, sales quote likely 10 at $20, so $200
Incident response ✘ 25 at $20, so $500 25 at $20, so $500
Monthly total About $125 About $625 About $700
Status pages Separate product Included Included
AI ✘ Assistant included, AI SRE extra Assistant included, AI SRE extra

Layering Rootly on top costs almost as much as replacing the pager outright. The main reason to layer is to avoid migrating schedules and routing rules all at once, not to save money.

Migrating to Rootly

If you decide to replace Splunk On-Call, plan it in stages.

  1. Connect Rootly's VictorOps integration first, so Rootly runs incidents while Splunk On-Call keeps paging.
  2. Import teams through Rootly's migration flow, if it is enabled for your workspace.
  3. Translate routing keys into Rootly teams and services, and decide which rules-engine logic becomes alert routing and which becomes workflows.
  4. Switch alert sources over gradually, and leave Splunk On-Call in place as a safety net until each source pages correctly through Rootly.
  5. Overlap the two for a complete rotation cycle, and line the final cutover up with your Splunk contract end date.

Which one fits your team

Keep Splunk On-Call by itself if paging is all you need and cost matters most. It remains reliable and familiar, though you should revisit the decision at each renewal.

Put Rootly on top if your incidents have outgrown a pager and a shared doc, but you are not ready to move schedules and routing rules. You get the Slack response, status pages, and AI assistant without touching the pager.

Move fully to Rootly if you want one actively developed product for paging and response, plus access to an AI SRE and an MCP server. Budget for both licenses for anyone who responds and carries the pager.

Final thoughts

Rootly's integration turns this from a replacement decision into a sequence. Splunk On-Call can keep paging people while Rootly takes over everything after the page, which lets you fix the response before you touch the pager.

So the real question is not whether to leave Splunk On-Call, but in what order. If your incidents feel chaotic, start with the layer on top, and let the pager be the last thing you migrate.

One MCP endpoint for incidents and telemetry

Rootly's MCP server exposes incident data, and Splunk On-Call has no MCP server at all, but neither can give an AI assistant your logs or traces, because neither stores them. Better Stack's MCP server covers the whole platform, so Claude or Cursor can query your logs with SQL, check who is on call, acknowledge an incident, and build a dashboard chart in one conversation.

With incidents and telemetry behind one MCP endpoint, your assistant can investigate and respond without switching tools. Try Better Stack.