Splunk is self-hosted SIEM software: you license it, run it, and staff the ongoing work of maintaining log sources and tuning alerts yourself. Managed SIEM is that same security monitoring function delivered as an ongoing service by a provider instead, which is usually evaluated once a self-run platform's licensing and staffing cost has outgrown the security team actually available to run it.