Skip to content
IncidentBot

Splunk On-Call alternative and VictorOps alternative with Slack incidents and status pages

IncidentBot is a Splunk On-Call alternative for engineering and IT teams that want on-call, escalation, Slack incident channels, a status page and postmortems in one product with a published price per responder seat. Teams coming from VictorOps keep the concepts they know (rotations, escalation policies, routing keys) and move them over with a parallel run, so nobody misses a page during the switch. As a VictorOps alternative it starts at 24 USD per user billed annually, with a public status page and read-only stakeholders included.

What changed since VictorOps became Splunk On-Call

VictorOps was acquired by Splunk in 2018 and renamed Splunk On-Call, and Cisco completed its acquisition of Splunk in March 2024. The product still pages people, but it now sits inside a large observability portfolio, and that changes the buying experience for a team that only needs on-call and incident response.

None of these is a reason to panic. They are good reasons to compare, especially before a renewal date.

  • Pricing is not published as a simple per-seat list. Splunk's pricing page steers buyers toward platform pricing models and a sales conversation, which makes a quick budget check hard for a 10 person team.
  • Incident coordination happens around the pager, not inside one workflow. Teams often add a separate Slack bot, a separate status page product and a postmortem document template.
  • Roadmap questions come up in every renewal. When the paging tool is a small part of a big platform, teams want to know what they are committing to for the next three years.

Who switches, and who should stay

Teams that switch are usually 5 to 200 responders, run their incidents in Slack, and pay for on-call as a line item they want to understand. Teams that should stay are the ones whose alert processing depends on deep Splunk Observability Cloud workflows they have tuned for years. If that describes you, weigh the migration cost honestly.

Splunk On-Call vs IncidentBot at a glance

This table compares what a buyer checks first. For Splunk On-Call, confirm current packaging with Splunk, because it changes with their platform bundles.

What you checkSplunk On-Call (VictorOps)IncidentBot
Published per-seat priceNot listed as a simple per-user price on Splunk's pricing pageStarter 24 USD, Team 49 USD, Business 99 USD per responder per month billed annually
On-call rotations and overridesYesYes, with swaps, follow-the-sun and calendar sync
Escalation policiesYesYes, tiers, timeouts, repeats and fallbacks
Paging channelsPush, SMS, phone, emailPush, SMS, voice, email and Slack, independent of Slack uptime
Incident run in SlackChat integration for notifications and actions/incident opens a channel, assigns commander, comms and scribe, sets severity, keeps the timeline
Status pageUsually paired with a separate status page productHosted status page in every plan, drafted from the live incident
PostmortemsPost-incident review reportsDraft built from the captured timeline, action items synced to Jira and Linear
Stakeholders who only readCheck your contractRead-only viewers included in every plan, never billed
Buy without a sales callSales-led for most buyersCreate an account and pick a plan online

Where Splunk On-Call wins: if your alerts already flow through Splunk Observability Cloud and you use its correlation and enrichment, keeping everything in one vendor has real value. Where IncidentBot wins: a clear seat price, the whole incident lifecycle in one tool, and stakeholders who do not cost a seat.

From VictorOps concepts to IncidentBot

The building blocks of on-call are the same everywhere, so the move is mostly a translation.

In Splunk On-CallIn IncidentBot
TeamsTeams with members, services and owners
Rotations and shiftsOn call scheduling software: rotations, overrides, swaps, follow-the-sun
Escalation policiesEscalation policies with tiers, timeouts and repeats
Routing keysServices, each with its own alert source and escalation policy
Alert rules engine (Transmogrifier)Routing rules, grouping, deduplication and maintenance windows on Team and above, runbook links on each service
Personal paging policiesPersonal notification preferences: push, SMS, voice, email, Slack
Incident timelineLive incident timeline, the source of the postmortem draft

Routing keys are the part to plan. Each routing key usually becomes one service, and that is a good moment to delete keys nobody has paged on in a year.

VictorOps migration in five steps

This order keeps paging safe at every point, because Splunk On-Call keeps paging until the last step.

  • Inventory: list teams, rotations, escalation policies, routing keys and every monitoring integration that sends alerts. Splunk On-Call's public API returns rotations and policies if you prefer a script to screenshots.
  • Rebuild schedules and policies: create teams, rotations and escalation policies in IncidentBot from the inventory. Each engineer checks their own shifts and paging preferences and sends themselves a test page.
  • Re-point integrations: add IncidentBot as a destination in Datadog, Prometheus Alertmanager, Grafana, CloudWatch, Sentry, email or webhook sources, one service at a time, starting with the least critical.
  • Run in parallel: both tools receive the same alerts for a week or two. Compare who was paged and when. Differences are almost always a timeout or a hand-off time, fixed before cut-over.
  • Cut over: remove Splunk On-Call as a destination per service once the parallel run matches, then let the contract lapse at renewal.

Moving VictorOps Transmogrifier rules

The Transmogrifier, now called the Alert Rules Engine in Splunk On-Call, is usually the part of a VictorOps setup with the most hidden logic in it. Export the rule list before anything else and sort each rule by what it does, because each type has a direct counterpart:

  • Rules that rewrite the routing key send a subset of alerts to another team. In IncidentBot they become routing rules that match on the same payload field (host, check name, tag or source) and send the alert to the owning service.
  • Rules that change message_type to INFO keep noisy checks out of the pager. Replace them with grouping and deduplication by alert key, or with a maintenance window when the noise comes from scheduled work.
  • Rules that add annotations (a runbook URL, a dashboard link or a note) move to the service itself. The runbook attached to a service is posted into every incident channel opened for it.
  • Rules that overwrite fields such as the display name or severity map to the severity and title mapping on the integration.

Rebuild the rules for one routing key, send a test alert through both tools and compare the result before you move the next key. Rules that have not matched an alert in months can usually be dropped.

Most teams finish in two to three weeks of calendar time and a few hours of work per week. On Enterprise, migration is done together with your success manager. The full setup is described on how it works.

Splunk On-Call alternative pricing

IncidentBot is priced per responder seat, monthly or annually. A seat is anyone who can be on call or act on an incident. Everyone else follows along as a read-only viewer at no charge.

Team sizeStarter, annualTeam, annual
5 responders105 USD per month245 USD per month
15 responders315 USD per month735 USD per month
40 responders840 USD per month1,960 USD per month

Starter fits small teams starting on-call. Team adds unlimited schedules and escalation policies, unlimited SMS and voice paging (fair use), alert grouping, incident roles, three status pages and postmortem drafts. Full plan details are on on call management software pricing, and if you are comparing several vendors at once, our PagerDuty pricing per user breakdown uses the same team sizes.

Other Splunk On-Call alternatives worth a look

You will see the same names on every shortlist. PagerDuty is the incumbent with the widest integration catalog and a more complex add-on price list. Opsgenie is no longer sold to new customers (Atlassian stopped new sales on June 4, 2025 and ends support on April 5, 2027), so it is not an option for a new contract; our Opsgenie alternative page covers that move. Grafana Cloud IRM suits teams already on Grafana Cloud. Slack-first tools such as incident.io, Rootly and FireHydrant focus on coordination, and incident.io sells on-call as a per-user add-on (see our incident.io alternative page); FireHydrant is now owned by Freshworks, and our FireHydrant alternative page compares it plan by plan. Our best incident management software guide lists the criteria that separate them.

FAQ

What is the best VictorOps alternative?

The best VictorOps alternative depends on where your monitoring lives. Teams staying on Splunk observability usually keep Splunk On-Call. Enterprises with ServiceNow workflows compare PagerDuty. Engineering teams of 5 to 200 responders that run incidents in Slack and want paging, a status page and postmortems on one published seat price pick IncidentBot, from 24 USD per user billed annually.

Is Splunk On-Call being discontinued?

Splunk has not announced an end of life for Splunk On-Call as of September 2026. It remains part of the Splunk observability portfolio under Cisco. Teams usually move for pricing clarity and a Slack-first incident workflow, not because the product is shutting down, so you can plan the switch on your own timeline.

What was Splunk On-Call formerly called?

Splunk On-Call was formerly called VictorOps. Splunk acquired VictorOps in 2018 and renamed it Splunk On-Call. The concepts are unchanged: teams, rotations, escalation policies and routing keys, which is why a VictorOps alternative and a Splunk On-Call alternative are the same search.

How long does it take to migrate off Splunk On-Call?

Most teams migrate in two to three weeks of calendar time. The work is an inventory, rebuilding rotations and escalation policies, re-pointing integrations service by service and a parallel run of one to two weeks. The parallel run takes the most time and is the part you should not skip.

Will engineers still get paged if Slack is down?

Yes. IncidentBot pages by mobile push, SMS, voice and email independently of Slack. Slack is where the incident is coordinated, not the only way to reach the on-call engineer.

Do we pay for people who only follow incidents?

No. Only responders are billed. Support leads, account managers and executives are read-only viewers, included in every plan.

Can we see it before we migrate?

Yes. The incident simulator runs a sample incident in your browser: an alert from a monitoring tool, escalation through a policy you build, a Slack channel, a status page draft and a postmortem skeleton.

Move off Splunk On-Call before your next renewal

Create your account, rebuild one team's rotation and run both tools side by side until the pages match.

Run a sample incident