Overview
Founded in 2012 and headquartered in Boulder, CO, VictorOps was acquired by Splunk in 2018 and has since been integrated as Splunk On-Call, serving as the incident management component of the Splunk observability platform. VictorOps combines alert management, on-call scheduling, and incident response to help DevOps teams handle critical events efficiently.
VictorOps' signature feature is the Timeline visualization, which captures every action during incident response—who did what, when alerts escalated, and when incidents were resolved. As of 2026, VictorOps as a standalone product has ceased development; all new features are released through the Splunk observability platform.
Key Strengths
- Timeline Visualization: Complete chronological timeline of the entire incident response process, automatically recording 6 stages—alert triggers, notifications, acknowledgments, escalations, resolutions, and postmortems. Timeline data can be exported for compliance audits and post-incident analysis—a distinguishing feature versus PagerDuty and Opsgenie.
- Deep Splunk Ecosystem Integration: As Splunk's native incident management component, it seamlessly connects with 3 products—Splunk ITSI, Splunk Observability Cloud, and Splunk Enterprise. Alerts from Splunk services flow into VictorOps automatically with minimal configuration.
- Structured Postmortems: Built-in postmortem templates auto-link incident Timeline data to generate reports with timelines, participants, and action records across 4 review stages. Reports can be stored in Splunk for audit and compliance review; see Incident Postmortem Template.
- Automated On-Call Scheduling: Flexible scheduling with daily/weekly rotations, 3-layer escalation, and holiday configuration. Schedules sync with calendars.
Product Ecosystem
Timeline
VictorOps' core innovation. Every alert and incident automatically generates a complete chronological record including alert source, notification delivery, personnel acknowledgment, escalation triggers, response actions, and resolution timestamps. The Timeline supports search and filtering for quick navigation to specific action nodes.
Splunk On-Call Integration
Now rebranded as Splunk On-Call, VictorOps deeply integrates with the Splunk observability platform. Alerts can be ingested directly from Splunk ITSI (IT Service Intelligence), Splunk Observability Cloud, and Splunk Enterprise. Integration enables unified alert, on-call, and incident management within the Splunk interface.
On-Call Scheduling
Supports flexible rotation modes: timed rotations, manual scheduling, and temporary overrides. Multi-layer escalation ensures alerts escalate when primary on-call does not acknowledge. On-call personnel can manage status and swaps via the mobile app.
Incident Response & Communication
VictorOps provides an incident response console with a centralized view of all active incidents. Supports response notes, file attachments, manual actions, and communication bridges. Incident data can be correlated with other observability data through Splunk integration.
Limitations
- Standalone Product Discontinued: VictorOps as an independent product is no longer iterated; new features are only available through the Splunk platform. For standalone incident management, evaluate PagerDuty or Opsgenie.
- Splunk License Required: VictorOps/Splunk On-Call has no independent pricing—it must be purchased as a Splunk license add-on, increasing procurement complexity.
- Limited Value Outside Splunk: Teams not using the Splunk observability platform cannot leverage VictorOps' integration advantages. Standalone experience is less feature-rich than PagerDuty.
- Acquisition Uncertainty: With Cisco's acquisition of Splunk, the long-term product direction of Splunk On-Call remains unclear.
Use Cases
- Splunk Ecosystem Users (★★★★★): Teams deeply invested in the Splunk observability platform—VictorOps/Splunk On-Call is the natural incident management choice.
- Timeline Audit Needs (★★★★☆): Organizations with strict compliance requirements for incident response audit trails. The Timeline feature provides complete operational records.
- Standalone Incident Management (★★☆☆☆): For teams without Splunk, PagerDuty or Opsgenie offer better standalone product experiences.
Pricing
| Edition | Pricing | Notes |
|---|---|---|
| Splunk On-Call | Bundled with Splunk license | Component of Splunk Observability Cloud; requires Splunk procurement |
VictorOps/Splunk On-Call does not offer standalone pricing. Cost depends on Splunk license tier and scale.
FAQ
- Does VictorOps still exist as a standalone product? No. VictorOps has been rebranded as Splunk On-Call and is now a component of the Splunk observability platform. New features are released through Splunk.on-call and alert management practice
- What is the relationship between VictorOps and Splunk On-Call? Same product. VictorOps is the original name; after Splunk's acquisition it was renamed Splunk On-Call. Both names are used interchangeably in documentation.incident postmortem template
- Can non-Splunk users use VictorOps? Technically yes, but the integration advantages are only fully realized within the Splunk ecosystem. For standalone use, evaluate PagerDuty or Opsgenie.
- Is the Timeline feature still available in Splunk On-Call? Yes. The Timeline feature has been integrated into Splunk On-Call with the same functionality.incident response playbook
- How does Cisco's acquisition of Splunk affect this product? Splunk On-Call continues to operate, but the long-term product roadmap has not been officially announced. Monitor Splunk official communications for updates.monitoring and alerting guide