Incident Management Group Test 2016 – The Results

This group test is a review of software products and vendors in the ‘Incident Management’ market area. Our remit was to explore how toolsets can support and optimise the Incident Management process.

Incident Management Overview

Incident Management is a key part of the ITSM Software Market – think about it – what organisation doesn’t do Incident Management? Incident Management is one of the most visible processes in the ITIL lifecycle. The aim of Incident Management is to restore usual service to customers as quickly as possible and with as little adverse impact whilst making sure nothing is lost, ignored or forgotten about. Can you imagine what would happen if end users couldn’t raise Incidents or contact the Service Desk in the event of a crisis? I reckon it would be 5 minutes max before total chaos.

When I’m explaining the Service Desk and Incident Management in ITIL training; I refer to them as the superheroes of the ITSM world. Let’s face it; they’re constantly firefighting, at the sharp end of the user community if something’s gone wrong as well as being under targets that would make lesser beings hide under their desk whilst mainlining vodka.

Frontline service desk and incident management, heroes of the ITSM world
Frontline service desk and incident management, heroes of the ITSM world!

Incident Management is a rockstar process and deserves a rockstar tool to support it so without further ado, let’s get started!

Customer Numbers

  • Alemba (UK) – 300+
  • Atlassian (Australia) –  15,000+
  • Cherwell Software (USA) – 1,000+
  • HPE – Hewlett Packard Enterprise (USA) – 1,500+
  • InvGate (Argentina) – 3,000+
  • ManageEngine (India) – 100,000+
  • Marval Software (UK) – 500+
  • Matrix42 (Germany) – 3,000+
  • Nexthink (Switzerland) – 600+
  • Summit Software (India) – 100+

Incident Management Group Test – The Players

Alemba Ltd.

Strong Incident Management offering which puts the end user experience at the heart of the tool.

Funky user interface using bubbles to highlight workflow and orbitor tool that aids the user by highlighting available actions.

Facebook style notifications alert users and technicians if the ticket has been updated with a handy “add me” option for Major Incidents.

Special module for displaying analytics to Service Desk screens – great idea that does away with the need for manual processes and faffing around with USB keys.


Solid Incident Management functionality. Atlassian are Incident Management ninjas; they aim to get customers up and running within one – two weeks of buying the tool.

Integration with Hipchat for easy chat and video calls.

Seamless integration with other JIRA products so that the customer has a consistent user experience.

Cherwell Software

User friendly user interface with Outlook integration to make it easier of users to log tickets.

Xmatters compatibility gives it advanced SMS gateway, telephony stats, monitoring and fault tolerance functionality.

Thriving customer community; FAQ’s, “how to” guides and oodles of free apps.

Hewlett Packard Enterprise (HPE)

Awesome landing page that empowers everyone from end users to senior management to customise and view reports.

Revamped reporting module that completely removes the need for any Crystal Reports faffery. Relationships clear and specific; instead of vague linked records, tool delivers meaningful linkages such as “fixed by Change” or “caused Incident”.

Big data is used to power the Knowledge Base; fixes and workarounds are automatically suggested and hot topics can identify Incident trends and proactively raise Problem records.


Brilliant customer focused ethos: “Service Desks are like snowflakes, no two are alike”.

User interface modelled on common social media platforms making it easy for end users to navigate.

Service Catalogue actively encourages end user to use the self-help route and gives a virtual high five message for every Incident logged.

Market leading gamification; kudos points for adding Knowledge Base article, merit badges for resolving Incidents within SLA and mini quests to encourage healthy competition between Service Desk Analysts.


ManageEngine user their superpowers for good; free PinkVerified Incident & Knowledge Management tools available via the ManageEngine website.

Thriving user community; customers have access to over 90 products and free tools.

User friendly interface; users can chose from raising an Incident or a Service Request and FAQs are on the right hand side of the screen meaning that help and further information is easily accessible.

Impressive use of predefined categories and email integration – tickets can be auto logged and updated without duplication of effort.

Marval Software

Outstanding Incident Management functionality.

Just like Starfleet, Marval have a prime directive, theirs is to enable people to be as productive as possible as quickly as possible.

Special instructions field part of every customer entry.

Each Knowledge entry has a set of work instructions, useful links, tools and diagnostic scripts.

Integrated ITSM process driven solution which is service and customer centric underpinned by a service portfolio.

Brilliant use of Near Field Communications, you can log an Incident simply by zapping a smart tag.

Slick Major Incident process that closely links into Problem, Change and IT Service Continuity Management.

Use their powers for good out in industry, regular contributors to the itSMF and Service Desk Institute.


Initial landing screen is very similar to your standard Microsoft offerings so most users will find the familiarity of the dashboard makes it easier to navigate.

Analyst screen easy to customise.

The tool can be configured to integrate with CTI systems so you can start a phone call and have it added to the audit diary.

Fab use of automation so you can use workflows to schedule routine tasks like server reboots.

Concurrence management is in place so if more than one person is updating the Incident at the same time, the data is merged and nothing is lost.


A vendor that loves talking to customers and end users!

Impressive IT analytics tool to drive proactive Incident Management.

Initial dashboard gives you an immediate, real time view of business critical services.

Automation drives out white noise and focuses on anomalies; enabling Service Desk Analysts to focus on the most important issues to the business.

The end user analytics support asset tracking and licensing monitoring.

As part of the product training, Nexthink advises Service Desk analysts to spend the time saved by automation to go out and talk to users; maximising value and improving the relationship between IT and the rest of the business. Love it when a vendor recognises that the end user is everything!

SUMMIT Software

Easy to navigate user interface – when an end user logs on to raise an Incident they can see their five most recently logged Incidents along with status information.

Analyst view flexible and easy to customise.

Service Request module is directly accessible from the Incident screen and is clear and fully configurable. Up to ten levels of approval can be used which to me covers every possible scenario.

Deep Dives

The Group Test Process

It was really important to me that the group test was fair. Each vendor was asked to fill in a questionnaire and then I had an individual session with each supplier to demo the tool and to ask lots of geeky questions. All the vendor presentations were slick and professional; it really helped me when vendors went out of their way to tailor the session to differentiators and functionality that was value driven.

Key Benefits of Incident Management

ITIL defines Incident Management as “the process responsible for managing the lifecycle of all Incidents. Incident management ensures that normal service operation is restored as quickly as possible and the business impact is minimized.” An effective Incident Management tool is a fundamental part of delivering Incident Management to the rest of the organisation.

In general, Incident Management is made up of the following steps with monitoring, communication, ownership and tracking carried out by the Service Desk:

  • Incident detection – something falls over, has performance issues or isn’t as it should be
  • Logging and recording; capturing all the details in an Incident record
  • Categorisation and prioritisation – ensuring that the Incident is categorised against the correct service and has the appropriate priority set by impact and urgency
  • Initial diagnosis -first go at resolving the Incident. If the Incident is resolved by the Service Desk at this point it is known as a first time fix.
  • Escalation -there are two types; Functional, where it goes to the next level of support eg from first line to second line support and Hierarchical, where something gets escalated to a team leader or manager.
  • Investigation and further diagnosis – where we figure out what’s gone wrong and how to fix it.
  • Resolution & Recovery -we’ve fixed the issue – happy days – normal service has been restored!
  • Closure -ensuring the end user is happy and closing off the Incident record with resolution details.

The following are some of the benefits of using a dedicated Incident Management toolset:

  • Models and templates to ensure all Incidents and Service Requests are handled consistently
  • Central point of capture so that nothing is lost, ignored or forgotten about.
  • Better adherence to SLAs, OLAs and UCs due to toolset monitoring.
  • Major Incidents workflow; especially with automated communication workflows.
  • Better results for Availability and Capacity Management; if Incidents are logged and managed effectively; they will also be resolved more effectively meaning that downtime and performance issues are minimised.
  • Increased Configuration Management accuracy; the Service Desk can check and confirm CI data when logging Incidents.
  • Enhanced management information regarding service quality due to reporting dashboards
  • Increased customer satisfaction.

Market Observations

From carrying out this group test, it quickly became clear that the Incident Management toolset game has been well and truly upped. Recent developments have seen a number of technical innovations that have allowed increased automation, faster delivery and quicker benefit realisation. The areas of differentiation in the market are therefore defined in the following terms:

  • End to end approach- the days of silos or everyone working in their own little bubbles are well and truly over. The most effective tools are aligned with other ITSM modules such as Configuration, Change, Problem, Service Level and IT Service Continuity Management.
  • User-friendly navigation -the most effective tools had the user journey modelled on common social media applications such as Facebook, Twitter and LinkedIn. By making it easier to log Incidents and Service Requests not only are we encouraging our customers to buy in to Incident Management, we’re getting them back up and running quicker via self-help and Knowledge Management.
  • Flexible workflow -there is no one size fits all. A start up IT organisation with less than twenty employees will have different requirements than a global financial institution with thousands of employees so flexibility is key.
  • Automation – models, templates and workflows all take the pain out of logging and managing Incidents and anything that makes the Major Incident process less of a nightmare or avoids someone having to get out of bed to reboot a server (automated task management) has got to be a winner!
  • Gamification – we work in IT – we are techies, geeks and engineers saving the world one Windows update at a time so work should absolutely be fun! Not only does gamification drive engagement from both end customers and support personnel; by rewarding people with fun badges and bragging rights in the office, we drive up productivity as well.
  • Big Data – a recent US study estimates that poor data quality costs US organizations over $600 billion a year. Missing, incorrect or out of date information is completely unacceptable in a service driven environment. Enter big data analytics which streamlines the Incident Management process, promotes self-service / self-help via Knowledge Management and allows users to log Incidents via smart tags without a single inbound call to the Service Desk.
  • Value driven approach – ever since the launch of ITIL V3; value has been the name of the game. By doing Incident Management we are committing to our customers. This commitment isn’t applying lip service, talking a good talk or even asking “have you tried switching it off and then on again?” on loop. This is about delivering our customers the service that they deserve. By committing to Incident Management via a solid process and toolset; we’re saying to the business – we care.

Strengths & Weaknesses


Best Overall: Marval Software LimitedIM Best Overall Winner 2016_Marvel

Awesome tool. Everything about it was lovely to use both from an end user and a techie experience. It’s apparent from working with Marval that they’ve spent years sat beside Service Desk analysts and support techies watching them work, seeing the pressures they’re under and figuring out ways in which the tool can make life easier. It’s slick, user friendly and enterprise focused and a fantastic option if you want to take your Service Desk, support teams and Incident Management to the next level.  Some of my favourite things about Marval are the following:

  • The user information: everything from service information and CI data from the CMS to locational info (with Google Maps) and a special instructions section (FYI; my special instructions would be please send coffee and chocolate)
  • Automation: keyword lookups for suggested models and templates
  • The Knowledge Base: each Knowledge entry has a set of work instructions, useful links, tools and diagnostic scripts. The idea behind this according to Marval is that this information can be pre-populated by second and third line techies.
  • Near Field Communication or NFC: if you happen to walk by a jammed printer, you can let the Service Desk know simply by zapping the label – how cool is that?
  • Slick, effective Major Incident process with solid links to Change, Problem and IT Service Continuity Management.

Marval is fantastic option if you need your Incident Management process to be customer and service centric, bulletproof and mature so we’ve given them the Batman award for best overall Incident Management tool for this group test.

Best Innovation: InvGate Inc.

Gamification is used to fantastic effect to make Incident Management easy, scalable and fun whilst the user interface makes for an efficient, positive customer journey. Some of my favourite things about InvGate are the following:

  • IM Best Innovation 2016_InvGateThe login screen can be configured for single sign on, linking into Active Directory / Windows authentication and also works with Mac machines.
  • All the major navigation buttons are placed at the top of the screen and a social interaction log (similar to the Facebook alerts function) can be expanded to view recent interactions between the Service Desk and the end user.
  • If a user goes down the self-service route – they get a really cool “Kudos” message for successfully logging the Incident. It’s a lovely touch that gives a virtual high five to the user for rocking self-help.
  • Market leading gamification: kudos points for adding Knowledge Base article, merit badges for resolving Incidents within SLA and mini quests to encourage healthy competition between Service Desk Analysts.

InvGate is fantastic option to get up and running quickly; not just for ITSM but for other functions such as HR and Facilities. Gamification and a user centric interface makes this effective and fun to use so we’ve given them the Star Wars award for best innovation for this group test.

Best Use of Analytics: HPE

IM Best Use of Analytics 2016_HPIndustry leading use of Big Data analytics makes HPE the standout in this area. Some of my favourite things about HPE are the following:

  • Fully configurable landing page and introduction screen
  • The revamped reporting capability: point and click, oodles of config options and no complicated third party reporting software needed
  • The chat functionality: the system will even suggest people that could help resolve the related Incident!
  • The big data powered Knowledge Base with smart task management and keyword lookups
  • Heat mapping to view trends and anomalies

HPE is a fantastic product for large organisations. The tool has a comprehensive engine behind it that can manage any enterprise level ITSM task it encounters. Big Data analytics drive efficiency savings and support a move to more proactive service model without compromising on functionality or management information so we’ve given them the Spiderman award for best use of analytics for this group test.

IM Best For Proactivity 2016_Nexthink (3)Best for Proactivity: Nexthink

A powerhouse of proactivity. Here are some of my favourite things about the tool:

  • A new approach and a proactive way to do Incident Management – can notify users of a fault and work on a fix without a single inbound call to the Service Desk
  • Landing page gives a clear view of the operational status of all business critical services
  • Designed to remove white noise so Service Desk Analysts can focus on “the serious stuff”
  • Part of their training is to encourage analysts to spend the time saved by automation to go out and talk to users; which can only be good right?

Nexthink empowers the Service Desk and makes Incident Management proactive so we’ve given them the Superman award for proactivity for this group test.

Using their powers for good award: ManageEngine

IM Best Using Powers for Good 2016_ManageEngineManageEngine are definitely on the light side of the force with their free PinkVerified Incident & Knowledge Management tool available for free from their website. Here are some of some of my favourite things about the tool:

  • Thriving user community
  • User friendly self Service Portal – users can raise an Incident or Service Request and browse through the FAQs
  • Multifunctional – the tool can also be used for desktop support, the deployment of software upgrades, patch management and the management of mobile devices

ManageEngine pride themselves on having a significant percentage of the functionality of the four biggest ITSM vendors, so by offering their Incident & Knowledge Management tool for free they deserve the Black Widow award for using their powers for good for this group test.

Deep Dives

Disclaimer Scope & Limitations

The information contained in this review is based on sources and information believed to be accurate as of the time it was created. Therefore, the completeness and current accuracy of the information provided cannot be guaranteed. Readers should therefore use the contents of this review as a general guideline and not as the ultimate source of truth.

Similarly, this review is not based on rigorous and exhaustive technical study. The ITSM Review recommends that readers complete a thorough live evaluation before investing in technology.

This is a paid review. That is, the vendors included in this review paid to participate in exchange for all results and analysis being published free of charge without registration. For further information please read the ‘Group Tests’ section on our Disclosure page.

Image Credit

Nexthink V6 Review

nexthink logo N

I reviewed Nexthink earlier in the year, worthy winners of our ITAM Excellence awards for Innovation. Check out a summary of Nexthink below or read the full review on Tools Advisor here:

Nexthink V6.0

Nexthink is a pioneer of end-user IT analytics. This review takes a look at the core capabilities of Nexthink, the route to market for the company, competitive strengths and weaknesses, and market reach.

 A new paradigm in IT Management Tools

Nexthink is perfectly placed to take advantage of the IT industry trend towards end-user centric computing, hybrid IT and analytics. Nexthink provide a sophisticated solution for visualizing IT infrastructure from an end-user perspective in real-time and over time.

This is a next-generation solution for forward thinking organizations focused on transforming the end-user experience, proactive identification of probable causes before end-users flag them as issues and generally increasing service quality.

Key Capabilities Table:

IT Operations Service quality gap between what IT believes its delivering and end-user experience View service quality from an end-user perspective
Majority of incidents are not reported by end-users Proactive Problem Management via end-user analytics
Demand to release applications at faster cadence Measure service quality before, during and after App deployments
IT Projects Stale or incomplete inventory Real-time analysis of IT Infrastructure
Lack of insight into project delivery Real-time visibility during App deployment and baseline service quality before and after
Inaccurate, out of date or failed CMDB implementations Continuous automated relationship and connectivity mapping in real-time
IT Security Poor visibility of IT infrastructure and connectivity CCTV-like experience recording real-time and historical
Zero-day exploits and rogue behavior Real-time monitoring and alerting of unauthorized or abnormal application and connectivity activity
BYOD and end-user centric behavior End-user centric relationship and connectivity mapping

Major Product Components – Nexthink V6

  • Collector – continuous real-time monitoring creates a ‘highlight reel’ of each endpoint and end-user.
  • Engine – continuous real-time analytics and alerting, discovery and dynamic pattern analysis to identify anomalies.
  • Finder – real-time visualization and ability to smart search, pivot on data / findings, look for patterns, and create custom investigations, alerts and actions.
  • Portal – near real-time visualization and historical trend analysis, sophisticated custom dashboards that include metrics, goals, thresholds, and status indicators.

Tools Advisor


Read the full review on Tools Advisor here.

Do you use NexthinkV6?

Please share your opinion for the benefit of others. Leave a customer review on Tools Advisor here.




Nexthink V5 Review for Proactive Problem Management

This is part of a competitive review of software vendors who offer Proactive Problem Management capabilities as part of their IT service management (ITSM) solution.

Other products reviewed:

Commercial Summary – Nexthink V5 Review

Vendor Nexthink
Product Nexthink V5
Version reviewed 5.2
Date of version Release July 2014
Year Founded 2004
Customers +500
Pricing Structure Perpetual and subscription licences for both Nexthink Analytics Platform and Nexthink Analytics Modules. All priced per number of devices/endpoints.

Executive Summary

Elevator Pitch Nexthink V5 is an intelligent and attractive solution.Providing far more than proactive problem management, Nexthink delivers extensive analytics and intelligence capabilities in a user-focused manner.
  • Ability to search in normal non-IT language (natural language, plain English, google-like experience)
  • Ability to compare objects and contextual situations in order to troubleshoot
  • Robust visual impact analysis
  • No ticketing facility within the solution but has API and connectors to integrate with
Primary Market Focus Based on the information provided, Nexthink is primarily a large-market solution

Independent Review

nexthink-logoNexthink V5 is a highly sophisticated solution yet still manages to look clean and simple. In contrast to the other solutions reviewed within this group test Nexthink does not contain any ticketing functionality and is wholly an analytical tool. However, it does have the necessary API and connectors to integrate with ticketing tools to create proactive alerts and track actions taken upon its analytics.

Proactive problem management is provided by monitoring the end-user experience and reporting back on real-time events. Dependencies and relationships are recorded without the need to install additional monitoring tools.

Nexthink is about discovering what you don’t know by learning and detecting what is different to the norm. In a time when event notification overload can cause more harm than good, Nexthink uses context to ensure that only pertinent info is alerted…

i.e. If you leave your car unlocked a normal monitoring tool would send an alert regardless, however if you were parked within a locked garage Nexthink would be able to apply context to recognise that this is not alert worthy (or less critical).

My impression of the solution is that it would be suitable for all medium to large enterprise organisations of medium to high proactive problem management maturity.

I believe that this highly developed solution could provide organisations with the visibility and insight into not only proactive problem management but also big data generally by only collecting summary activity data and related issues rather impractically expecting IT departments to mine through everything or make decisions on what is, and what is not important.


User configuration possible for:





N.B. every form and workflow can be customized through the admin module

  • Nexthink is a standalone analytics and intelligence solution which integrates with ticketing tools. It does not contain it’s own ticketing capabilities
  • Full integration toolkit. Data can be imported into and out of Nexthink in various ways to serve many different purposes. More info:
  • Templates and pre-filled forms and structure available for basic starting point from Nexthink library, a cloud based platform for collective intelligence
  • Web API
  • Existing standard integrations with Service Desk solutions such as LANDESK, ServiceNow, BMC Remedy, EasyVista and PMCS Helpline.


The integration of end-user IT analytics for incident and problem management is driven from the service desk. Nexthink helps align incidents and problems and enables the service desk to identify outage-problems in real-time and configuration-change-problems faster. In other words Nexthink can fast track incident to problem identification and help provide probable cause to solve problems and/or provide suitable workarounds before (further) incidents recur.

Nexthink’s internal technology assists in the identification of potential proactive problems via

Self-learning, topological relationships, base lining, benchmarking, statistics & heuristics.

Nexthink states that their solution, without configuration or definition of a potential problem can discover what’s in-use, understand the dependencies (process, devices, ports, services, server, cloud domain, etc.) and profile a baseline to further identify deviations e.g. connection is getting slower or failing for a specific group of users.

Information about the context of any identified proactive problem is displayed on Nexthink user interfaces (Finder and Portal). Portal is a web-based dashboard platform where specific widgets can be added to see the past, current and potential future impact of a change, a growing issue or an outage, including break-ups by departments, and type of problems (devices, network/infra, web requests, servers, etc.).

Nexthink specify that integration with network and server monitoring solutions is not necessary for their analytics to perform and deliver but welcome such integrations to create a full end-to-end visibility with both user-centric (outside-in) and server-centric (inside-out) visibility and analysis. They maintain that the solution is able to identify anomalies in data patterns resulting from configuration changes without the aid or knowledge of those changes and that it’s more efficient and effective to use the many diagnostic tools available within the solution to do root cause analysis.

Assessment and Alerting

Nexthink calculates an objective risk assesment via the end-user perspective. Their argument is that this positions users to compute an impact analysis from a business point of view because they will already have information such as the department, job role, location of affected users and are therefore using business language rather than IT speak i.e. you are not saying x router interface was flapping for 10min, dropping xxx packets, but rather 15 users from our Finance department attempted to use SAP without success for 10 minutes (while the 45 users from sales didn’t have any issues).

Nexthink also provides the ability to compute based on current activity, e.g. if we shut down these 10 servers now, 120 users currently connected to these servers with these 10 applications will suffer and this equals, based on each application business criticality, a business loss of £££. Based on feedback we receive from readers this functionality is highly sought after yet sadly lacking from many solutions. We believe that this functionality provides solid value to potential customers. Analytics provides the ability to push the concept of proactive problem management to preemptive and predictive.

Although there is no ticketing tool available within Nexthink, by analyzing all end-users’ activity collectively and centrally the solution is able to apply mechanisms and algorithms to understand if the problem is on the device, user, application, network/infrastructure or server side enabling the problem to be routed to the most appropriate group using the integration interface or finding the solution looking at the Nexthink Portal or Finder.


Tracking and management of the lifecycle of a proactive problem would have to be provided by an integration with a third party ticketing tool. However, new/updated information can be fed into the third party tool to notify about a situational change, i.e. the problem has increased in severity.

Auditing and Accountability

Nexthink gives the option to visually display an impending breach/breach of an SLA by colouring the issue yellow/red within the widget, building a history trends graph, triggering an alert or exporting context (what, when, where, what, how long, how badly) to a third party tool. Gives the context and impact of the breach (what, when, where, what, how long, how badly).

In Summary

Nexthink provides a comprehensive analytics and intelligence solution which provides far more than Proactive Problem Management capabilities. What’s more it provides them in a user-focused way which is quite different to the majority of other solutions on the market that are all data centre focused.

I believe that this solution would create huge value to any organisation looking for real-time end-user analytics.

In Their Own Words:

Nexthink is the innovator of End-user IT Analytics for security, ITSM and transformation. Our software uniquely provides enterprise-wide, real-time: analytics covering all endpoints, users, applications and network connections; and visualization of IT infrastructure and service delivery. Nexthink helps IT departments connect, communicate and collaborate to achieve their major goals and to optimize endpoint security, operations, support and workplace transformation projects. Nexthink’s real-time analytics and visualization extend help desk, server monitoring, APM (application performance management) and PCLM (PC lifecycle management) tools and provide essential visibility for IT governance.

Nexthink pro-actively monitors IT networks and reports on important end-user related events, such as changes in the IT infrastructure, application usage and bandwidth, error messages and crashes, as well as potential security risks, ensuring that the performance of IT services is recorded and uniquely visualized from the end-user perspective.


Assessment Criteria: Proactive Problem Management Product Review

In August of this year, we will be kicking off our product review dedicated to “Proactive Problem Management”, the use of ITSM technology that enables organizations to practice proactive or pre-emptive problem management.

Which vendor will win when it comes to proactive problem management?
Which vendor will win when it comes to proactive problem management?


The aim of this review is to showcase best of breed ITSM software in use outside the IT department, highlight key competitive differentiators and provide readers of The ITSM Review with impartial market intelligence to enable informed purchasing decisions.

Previously published product reviews include:

Also coming soon: Outside IT.

Assessment Criteria 

This review will support prospective buyers with their selection process by providing features to consider when selecting ITSM systems and highlighting key competitive differentiators between suppliers.

Proactive Problem Management – if problem management is concerned with addressing the root cause of incidents, then proactive problem management is the systems and techniques to address these incidents before they occur and cause service disruption, or reduce or eliminate recurring incidents.

This review looks at the technology to assist organizations take a proactive step towards managing incidents and problems and explore problems before they results in incidents.

A problem is a problem, whether it has caused an incident yet or not” – Rob England, “Proactive Problem Management

Main Topic Areas

  • Managing the lifecycle of problems
  • Identifying problems
  • Solving problems, root causes and problem solving methodologies
  • Known errors / managing work in progress / CSI
  • Integrations, monitoring and triggers

Solutions that do not include all of the criteria above will not necessarily score badly – the criteria simply define the scope of areas will be covered. The goal is to highlight strengths and identify differences, whilst placing every vendor in the best light possible.

Please note: The assessment criteria are just a starting point; they tend to flux and evolve as we delve into solutions and discover unique features and leading edge innovation. Identifying key competitive differentiators is a higher priority than the assessment criteria.

Confirmed Participants

Vendors who wish to participate in this “Proactive Problem Management” product review should contact us directly. We also welcome feedback from readers on their experience with their use of ITSM tools and proactive problem management (although this feedback will not directly impact the review).

Image Credit

Review: Nexthink for Integrations

This independent review is part of our Integrations 2013 Group Test.

Executive Summary

Elevator Pitch In the emerging IT management category ITOA (IT Operations Analytics) Nexthink provides a very different view and, when integrated into ITSM, can provide a real-time analytical interface into processes for proactive, rather than reactive management.
  •  Offers a completely different view of information within an enterprise
  • Everything is displayed in real-time and with the integration options to key ITSM tools, the combination really lends itself to larger organisations and those running complex migration/transformation projects
  • As ITOA is a new category, it requires financial commitment from other departments to cover this level of end-to-end management and analytical capability – Probably not for the very small organisations.
Primary Market Focus Based on the information provided, Nexthink’s customer base is more focussed on larger companies.They are classified for this review as:Specialised tooling, requiring integration to ITSM.

Commercial Summary

Vendor Nexthink
Product Nexthink V4
Version reviewed V4.4
Date of version release May 2nd, 2013
Year founded 2004
Customers 450+
Pricing Structure # of Physical and Virtual Endpoints/Desktops# of Citrix UsersPerpetual and SubscriptionDiscount for volumeMSP/SaaS pricing is available to partners that want to deliver End-user IT Analytics as a service
Competitive Differentiators
  1. Nexthink provide End-User IT Analytics – the tool analyses data from all the endpoints and extrapolates information from that perspective to identify trouble spots.
  2. The analysis is in real-time – patterns and any anomalies detected are constantly being evaluated.
  3. They turn the end-user and endpoint data into a level of intelligence and insight to sit alongside IT Service Management and offer a level of integration with known vendors to complement them in a number of areas.

Independent Review

thumbnailThere is something always beguiling when products talk of heat-maps and show dynamic visions of where network paths are failing, and to see it in real-time brings out the magpie in technical reviewers.

Starting at the top, they provide a customisable dashboard that would catch the eye of CIOs and the review got to examine a little more breadth to the product.

In essence a driver agent is sent to all target endpoints and it sends the real-time data back to their own engine where the information can be shown in a dashboard display of high level information about the number of issues. The collector can even send back information when the endpoint’s CPU is overwhelmed.

Applications for end-points can be profiled before a rollout – for example testing out builds on particular hardware to see how effective the build is for machines.

Once you come away from the high level dashboard, there are detailed “heat-maps” that begin to show you where issues are building up, and specific trouble area can be drilled into. These lower level graphics are typically what operations centre staff and advanced technical support will get the real value from.

The level of intelligence to extrapolate information, purely from the end-point perspective is what makes the product stand out.

Whilst the product can stand on its own merits, its real value is when it is integrated with ITSM and their partnership framework opens up the right doors for the company. Nexthink have integrated with leading ITSSM tools including BMC/Remedy, LANDesk and ServiceNow.

Their value is to help organisations to see the big picture and enlightened organisations are realising that they need this more holistic view.

Integration and specific recognised criteria

Nexthink have worked to develop an ITSM Solution Pack that maps their capabilities with 17 of the 28 ITIL 2011 processes.

They are not an ITSM tool, but they recognise that the real value of their product comes with integration into key ITIL processes.

Security Controls

They have also developed a Nexthink Security Solution Pack and have mapped the product with leading security standards.

Asset and Configuration Information

Their integration partners include: Microsoft SCCM, Symantec/Altiris, LANDesk, Matrix42

They bring in the information to help build up their picture of the end-point interactions.

Additional Areas of Integration

  • Event Correlation

Nexthink have integrated with Event Correlation Engines with companies such as BMC, CA/Nimsoft, HP and IBM).

Because they report the global end-user events, they can correlate those to show in real time which server is affected (the Nexthink collector is only placed on endpoints).

  • Security

Nexthink can also add an extra measure of vulnerability assessment and can assist with compliance testing.

  • Transformation

An ideal area for consideration is the use of Nexthink for large, complex Transformation projects – combined with standard ITSM tooling the combination can provide much better guidance on what is going to be involved with a large transformation project.

Nexthink Service Management Customers

From the Nexthink Brochure

  • Innovator of End-user IT Analytics for security, ITSM and workplace transformation.
  • Self-learning and artificial intelligence constructs meaningful patterns and IT analytics – patterns are analysed in real time (every minute), enterprise wide.
  • What makes Nexthink unique is the real-time analytics of all executions and all network connections and the corresponding visualisation that provides new visibility and insight at that moment in time.

In Their Own Words:

Nexthink is the innovator of End-user IT Analytics for security, ITSM and transformation.  Nexthink turns end-user and endpoint data into intelligence and insights. Our software uniquely provides enterprise-wide, real-time analytics covering all endpoints, all users, all applications and all network connections with visibility into your IT infrastructure and service delivery.  Nexthink helps IT Departments connect, communicate and collaborate to achieve their major goals and to optimize endpoint security, operations, support, and workplace transformation projects.  Nexthink real-time analytics and visualization extend help desk, server monitoring, APM (application performance management) and PCLM (PC lifecycle management) tools and provides essential visibility for IT Governance.

Nexthink serves mid-size and enterprise companies utilizing a leveraged partner model.  Nexthink is a registered trademark of Nexthink SA. To learn more, visit


Further Information

This independent review is part of our Integrations 2013 Group Test.

Review: Nexthink

This independent review is part of our 2013 Incident and Problem Review. See all participants and terms of the review here.

Executive Summary

Elevator Pitch If systems management monitoring takes care of servers, Nexthink presents you all you need to know about the end-user side of the coin.

Nexthink sits apart from the nuts and bolts of Service Management tooling, but offer guidance to analysts to help expedite resolution with real-time End-user IT Analytics, integrated into major ITSM tools to significantly reduce problem diagnosis times.

  • Lightweight, non-invasive kernel-driven footprint on end-user targets helps define trouble spots in real time
  • Complements and integrates with existing IT Service Management deployments
  • With so much technical capability, it needs a very strong balancing hand of strategy to get the best of a combination of this product, a service management suite, and server monitoring collaboration.
Primary Market Focus Based on the information provided, Nexthink’s customer base ranges from Small (100 end users) to Very Large (250,000+)They are classified for this review as:Specialised tooling, requiring integration to ITSM.

Commercial Summary

Vendor Nexthink
Product Nexthink V4
Version reviewed V4.3
Date of version release February 19 2013
Year founded Founded in 2004.Turnover is not disclosed but 100% yearly growth. Today 2 million users’ licenses sold
Customers 400
Pricing Structure # IT users with perpetual or subscription license. On premise Enterprise product and Cloud/SaaS offering (Q2 2013)
Competitive Differentiators Nexthink provides unique real-time end-user IT analytics across the complete infrastructure.This perfectly complements existing performance monitoring systems to drive better ITSM initiatives; end-user IT analytics are used to:

  • 1) Diagnose and isolate problems in real-time for service desk to become more effective and responsive for higher customer satisfaction
  • 2) Continuously compute metrics and KPIs for proactive actions so IT operations can improve service quality for higher business agility and productivity
  • 3) Configuration and change management is fully under compliance control.
Additional Features Nexthink’s product does real-time discovery, dependency and relationship mapping, real-time activity monitoring, alerting and reporting on all object and data analytics available.

It doesn’t rely on any external product or data to function. However integration methods exist to enrich Nexthink data with external data sources (E.g. Active Directory, Event database, CMDB), to export Nexthink data/analytics to other tools to create end-to-end correlated views/results (CMDB, ITSM, Security Events Management).See an example here:

Independent Review

Credit should be given to Nexthink for putting themselves up against “traditional” ITSM Vendors, as their product does not do traditional Incident Management and Problem Management.

What it can do, however, is significantly shorten the amount of time it takes to resolve an incident and/or problem, by showing end user data in real time.

Nexthink have established major partners and product integrators with companies like BMC, HP and ServiceNow and provide a button on their ITSM consoles to allow analysts to view the data when required.

It almost presents itself as the super-hero of incident and problem diagnosis.

But following that super-hero position for just a moment, it is easy to get carried away with the technical potential of a shiny mapping, real-time toy.

It is much more than that, and it needs a sharp strategic mind to position it – remembering the key drivers of any ITSM related deployment.

The potential to drive down incident resolution time, and more importantly problem root cause analysis time makes it a compelling accompanying tool alongside an ITSM tool, to achieve tangible business efficiency benefits.

Widening the scope to look at the effects of IT Transition projects, and again the potential business benefits of understanding what specifications end user machines need to be to ensure speedier access to services, for example, could reap significant rewards.

Systems Monitoring vs. Real Time End User Monitoring

Nexthink acknowledge that infrastructure monitoring is an established discipline.

There are all manner of event and systems management tools that can also integrate into service management tools to present an organisation with enterprise level management.

What Nexthink do is focus on the end user perspective.

A kernel driver that is deployed out to end user machines, and loads into memory on boot-up.

Real-time data is then loaded up to a central server which can then be interrogated as and when required.

Incident & Problems Scope

Forrester research has shown that 80% of the time during the lifecycle of an incident is spent trying to isolate the problem itself.

Source: Forrester (

Nexthink offer a way of shortening that timeframe, mapping out relationships between failing components to see where the problem has occurred.

For example, a user may ring with a general issue of a slow response time.

Ordinarily, a support analyst would then have to drill down through applications, servers, configuration mapping to see what may be affected and how.

Nexthink can demonstrate where the issue lies and could isolate the failing link in the chain a lot more rapidly.

Nexthink’s own interface can even be used to directly query the user’s asset to assist with the diagnosis.

The information gathered can also be used to supplement the CMDB in the ITSM tool.

All this could then be used to drive more accurate logging and categorisation, and linking to any subsequent processes to resolve the situation.

The knock-on benefit is improved resolution times, potential workarounds and knowledge-base material, not to mention improved reporting.

When Nexthink is integrated with an ITSM tool, the support analysts will work off the ITSM console, but they will have a Nexthink button to be able to access the real-time analytics data.

Looking in the context of incidents and problems, whether major or otherwise, the ability to have multiple teams looking at the related end user data in terms of applications and services is invaluable.


There is a lot to appeal to the technical heart, looking at the depth of analytical data possible.

Key points to remember though – it takes everything from the end user point of view, and is not geared to sit on servers themselves to do that level of monitoring.

Taking just Incident and Problem Management, it is easy to see how the investigation can be shortened as an incident call comes in.

But looking at Problem, it can take proactive root cause analysis to another level.

If that is then combined with ITSM tools and their own abilities to manage multiple records (in the case of Major Incidents or Problems) then it is a powerfully complementary part of a company’s overall ITSM strategy.

Nexthink Customers


Click on the thumbnails to enlarge.

In Their Own Words:

Nexthink provides unique real-time end-user IT analytics across the complete infrastructure. This perfectly complements existing application performance monitoring systems to drive better ITSM initiatives.

End-user IT analytics are the path to better IT quality, security and great efficiency and cost savings.

Nexthink provides IT organizations with a real-time view of the IT activity and interaction across the complete enterprise, from the end-user perspective. This unique visibility and analytics give IT the capability to truly evaluate and understand how organizations are performing and rapidly diagnose problems or identify security risks. Nexthink uniquely collects in real time millions of events and their respective dependencies and relationship to IT services from all users, all their applications, all their devices, all workloads, and all network connections patterns (server accessed, ports, response time, duration, failure, timeouts, etc.).

Nexthink helps IT connect, communicate and collaborate to achieve their major initiatives and improve their business end-user’s IT experience. Nexthink is complimentary hence integrates well with traditional application performance management (network and server), help desk, operations management, and security tools and eases ITIL change and release management processes.

Further Information

Group Test Index

This independent review is part of our 2013 Incident and Problem Review. See all participants and terms of the review here.

2013 Incident and Problem Tools Review

Tools Reviewed:

Download Review

(Free PDF, No Registration Required – 601kb, 7 Pages)


Incident and Problem Management are such mainstays of an ITSM tool, it is quite hard to find a way to dig through the differentiators.

The process and the related workflows themselves are so seemingly straight forward, are there really any ways to improve?

Not only that, but it has to be looked at in the context of the trends in the industry to focus on the end-user’s experience. That’s all fine when we take a look at the options available to an end-user logging an incident from a self-service portal.

But in reality, people still call service desks.

The answer is – there are ways to improve, and in many ways they are subtle features that make tools stand out.

This review bought out nuances and features to help make a couple of mature processes look exciting again.

  • Stylish use of forms, questions and linkage to knowledge bases
  • Resourcing and task planning
  • Real-time end-user analytics

These tools do more than just provide a mechanism to move an incident or a problem from A to B.

It looks to improve the lifecycle, and practice the points of the Process Certification that vendors put themselves through.

A word should be said, though, about the knowledge levels of the people who market these products day in, day out.

I would like to share an insightful tweet from Forrester’s Stephen Mann


In both the reviews I have done, it is always good to work from qualified consultants who have a very good understanding of balancing what the tool can do, functionally, against what the real world sometimes requires.

The devil for all these tools is in the detail of the customisation – any tool, with dedicated customisation, and knowledge, pragmatic consultancy can get the best out of any record-pushing mechanism.

Having replaced many a tool in large-scale ITSM deployments, I often recognised shortcomings in both the outgoing and the incoming tool-set.

But the key remains – can the vendor impart a sense of comfort that they not only understand their tool, the processes that need to be translated to workflow, but can they identify ways to improve?

Having people who not only understand the tool, but also recognise the need to encompass evolving best practices goes a long way to make a tool stand out from its peers in the crowd.


For the purposes of this review, vendors were classified based on their primary market focus, and product capabilities.


Target Market Size Specialist ITSM Functions Discovery Own Tool/Third Party Integration Event Management & Monitoring Own Tool/Third Party Integration

Real-Time End-User Analytics

Axios assyst Large Very Large Own Third Party Integration
BMC FootPrints Medium Large Own Own (via Integration)
Cherwell Service Management Small Medium Large Very Large Own Third Party Integration
Nexthink Small Medium Large Very Large Own Third Party Integration

TOPdesk Small Medium Large Own Third Party Integration


The table below shows a high level overview of the competitive differences between the tools

  • Elevator Pitch – An independent assessment of what this module has to offer
  • Strengths – key positive points, highlighted during the review
  • Weaknesses – areas perceived to be lacking, during the review
Vendor Elevator Pitch Strengths Weaknesses
Axios assyst A tidy interface, driven by product hierarchies, and backed up with a potentially powerful CMDB.Work put in to customise the Info Zone, Guidance and FAQs can make the job of the Service Desk, Analysts, and even the end user interaction easier
  • Crisp and clean interface, with not much clutter
  • From a self-service point of view, a nice touch in walking end users through investigation before logging a ticket
  • For those logging directly with the service desk, pulls in pre-populated forms and guidance to make that role easier/more efficient
  • Very much rooted in the technical – with the product hierarchy very comprehensive.  Would be nice to see perhaps an incorporation of more business language
  • The ability to record an analysts time against a charge code also seems to drive a specific cost as well – whilst this could just be a notional cost, some form of correlation between the two, removing the need for the analysts to know financials as well as resolving an incident, might be more beneficial
  • There are some elements of earlier ITIL iterations in the tool, as nothing is taken out which could be cumbersome to customise out
BMC FootPrints An improved interface and comprehensive coverage of Incident and Problem Management, with some added innovation to make scheduling work a little easier for Service Desks and support staff alike.
  • Logging by Type, Category and Symptom adds a meaningful level of granularity
  • Incorporates an availability of resource’s view by integrating to Outlook Exchange
  • Subscription function for end users for major incidents, as well as pop ups for potential SLA breaches
  • Design elements behind the scenes are still largely text based
Cherwell Service Management Cherwell use intelligent interfaces and well constructed forms to automate the basics of the processes in a comprehensive and informative way
  • Core stages of process management as part of the user interface
  • In-context configuration mapping that makes handling concurrent incident and problem mapping very easy
  • Potential depth of customisation in terms of use of forms (Specifics) lends itself to improving/ enhancing investigation and first-time fix
  • While promotion to a Major Incident, automatic raising of a Problem, linkage to the Global Alerts feature and the ability for users to indicate they are affected too from Self Service is great, that indication is linked to the automatically linked problem record, not the Major Incident
  • Customers seem to have indicated interest in linkage to the Major Incident as an out-of-the-box capability and it would make sense to provide it.
Nexthink If systems management monitoring takes care of servers, Nexthink presents you all you need to know about the end-user side of the coin.Nexthink sits apart from the nuts and bolts of Service Management tooling, but offers guidance to analysts to help expedite resolution with real-time End-user IT Analytics, integrated into major ITSM tools to significantly reduce problem diagnosis times
  • Lightweight kernel-driven footprint on end-user targets helps define trouble spots in real time
  • Complements existing IT Service Management deployments
  • With so much technical capability, it needs a very strong balancing hand of strategy to get the best of a combination of this product, a service management suite, and server monitoring collaboration
TOPdesk TOPdesk adds Kanban-type resource scheduling to add a new dimension onto Incident and Problem Management
  • The Plan Board incorporates a Kanban style approach to scheduling tasks to help drive efficient resourcing
  • Keywords trigger standard solutions, linking into a two-tire Knowledge base (for Analysts and End Users)
  • Task Board for individual support staff can be sliced and diced by the most time critical events
  • Sometimes “over-customisability” can rear its head in reviews – just because it is possible to have 7 different priorities, it does not mean it is a good practice to do so.
  • Some terminology (which can be changed with a little more detailed knowledge) can be a little cumbersome – For Objects for Assets


Approximate number of customers for each vendor:

  • Axios assyst – 1000+
  • BMC FootPrints – Approximately 1000 customers across Europe and 5000 worldwide
  • Cherwell Service Management – 400+
  • Nexthink – 400
  • TOPdesk – 3150 approximate TOPdesk Enterprise customers, >5000+ unique customers in total


Vendor Functionality Innovation Analysis
Axios assyst A tidy interface with a lot of focus on driving the product hierarchies for categorisation. Pre-populated forms and scripted guidance for the service desk.Chat function for support staff to collaborate. Axios focus on ways to automate as much as possible.Backed up with a very comprehensive CMDB structure at its core, work put into the configuration of a system up front will reap rewards in efficiency down the line.
BMC FootPrints Great to see a vendor improve from customer (and analyst) feedback and the result is a modern looking tool that handles the “bread and butter” tasks of Incident and Problem efficiently FootPrints links to Microsoft Exchange to display a view of the support staff resources and allocation of repetitive tasks.Logging by Type, Category and potentially Symptom adds an appealing level of granularity. BMC FootPrints is not alone in exploring and incorporating a view of the support staff resources, and it is evolving to be a very smart looking, mid-market offering that can punch above its weight.
Cherwell Service Management Cherwell add a number of features that make the process speedier – and their Specifics forms provide a great touch in terms of initial investigation. Cherwell get the balance right, with customisable features (forms and macros) and include a breadcrumb trail throughout the lifecycle of the record. Cherwell recognise that it is not just IT functions that need to use the tool – the Impact and Urgency in business language (Incident) and their other features all make it a roundly comprehensive tool to appeal to organisations of all sizes.
Nexthink Nexthink is not a traditional ITSM tool.  Instead it offers a chance for support analysts to proactively resolve issues faster by means of End-User real-time analytics It’s power comes from being able to assess elements from an end-user perspective, and integrates with existing ITSM tools to provide a comprehensive view of an end-user’s machine. There are a number of ways that Nexthink and ITSM tools can co-exist – Nexthink is a powerful enabler for much more proactive incident and problem resolution.
TOPdesk TOPdesk use wizards and key word matching to help drive efficient Incident and Problem logging and resolution TOPdesk takes resource planning to another level, planning shift patterns, and operating a Kanban style method of dragging and dropping tasks to less loaded support staff. The whole combination of the resource board, the way their task board can focus on the most pressing first, and their links to Knowledge Management made this a very attractive tool to review,There were some configuration niggles which can all be customised (some more easily than others) but it is certainly heading in the right direction.


Vendor End-User Base Product Characteristics
Axios assyst
  • Specialised Service Management Suite
  • Integration for Event Monitoring
BMC Footprints
  • Specialised Service Management Suite
  • Integration for Event Monitoring
Cherwell Service Management
  • Specialised Service Management Suite
  • Integration for Event Monitoring
  • Specialised tooling, requiring integration to ITSM
  • Specialised Service Management Suite
  • Integration for Event Monitoring

Best in Class (Small-Med-Large) – BMC FootPrints

BMC FootPrints have taken on board customer feedback, and even observations from previous reviews to make subtle but very noticeable adjustments to their interface.

The result is a tool that offers more intuitive investigation diagnostics as calls are being logged, and is continually looking to improve.

FootPrints is getting a real benefit from being part of the larger BMC brand, but is fast establishing itself as a tool to appeal across the entire market-place.

Best in Class (Small-Med-Large-V Large) – Cherwell

As with FootPrints, the inclusion of diagnostic forms, within records, linked to the categories makes Cherwell stand out when logging Incidents, in particular.

Best in Class (All Tools):TOPdesk

The inclusion of the Kanban-style resourcing board, but also the way in which tasks can be placed and moved about really made this stand out, in terms of the way that innovation within a tool can really make processes less cumbersome.

Honourable Mention: Nexthink

This tool deserves to stand apart from its Service Management cousins.

It adds a unique element, which can truly help drive efficiencies, especially where Problem Management is concerned.

With the right business drivers and strategic vision, not to mention strong partnership with some of the ITSM industry big-hitters, Nexthink’s real-time end-user analysis can help in so many more service management disciplines.  I feel we have only scratched the surface of its potential.

Deep Dive

Further details for each vendor can be found by using the links below:


The information contained in this review is based on sources and information believed to be accurate as of the time it was created. Therefore, the completeness and current accuracy of the information provided cannot be guaranteed. Readers should therefore use the contents of this review as a general guideline and not as the ultimate source of truth.

Similarly, this review is not based on rigorous and exhaustive technical study. The ITSM Review recommends that readers complete a thorough live evaluation before investing in technology.

This is a paid review. That is, the vendors included in this review paid to participate in exchange for all results and analysis being published free of charge without registration. For further information please read the ‘Group Tests’ section on our Disclosure page.

Coming Soon: Axios, BMC, Cherwell, NetSupport, TOPdesk & Nexthink Slog it out

Incident and Problem Product Review
Axios, BMC, Cherwell, NetSupport, TOPdesk & Nexthink slog it out for our Incident and Problem Management review

Axios, BMC, Cherwell, NetSupport, TOPdesk and Nexthink are confirmed participants for our upcoming ‘Incident and Problem Management’ review.

Our assessment Criteria at a Glance:

  • Logging & Categorization
  • Tracking
  • Lifecycle Tracking
  • Prioritisation
  • Escalations
  • Major Incidents and Problems
  • Incident and Problem Models
  • Incident and Problem Closure

Full details of the assessment criteria can be found here.

Reviewer: Ros Satar 

Confirmed Participants:

All results will be published free of charge without registration on The ITSM Review. You may wish to subscribe to the ITSM Review newsletter (top right of this page) or follow us on Twitter to receive a notification when it is published.