Splunk SOAR

Assigning Alerts/Cases Across Teams with Restricted Label Access in Splunk SOAR

mushknizamoffic
Engager

Hello,

I’m working on a use case in Splunk SOAR where I’ve structured alerts using labels to separate visibility between teams. This allows each team to focus only on their own alerts, avoiding confusion and overlap. The access is controlled through roles, so a user/team only sees alerts tied to their specific label.

The challenge I’m facing is with cross-team assignments. If a user from Team A (with Label A) wants to assign or escalate an alert to someone in Team B (with Label B), this isn’t possible because they don’t have access to that other label.

I’d like to know:

  1. Is there any supported method or workaround to allow cross-team assignment while still preserving restricted visibility?

  2. If such a transfer/escalation is possible, can the alert be hidden from the original team’s view once it has been reassigned to the new team?

The goal is to maintain clean separation of alerts per team while still allowing escalation paths between them.

Any guidance or best practices would be greatly appreciated.

Thank you!

Labels (2)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...