Splunk SOAR

Assigning Alerts/Cases Across Teams with Restricted Label Access in Splunk SOAR

mushknizamoffic
Engager

Hello,

I’m working on a use case in Splunk SOAR where I’ve structured alerts using labels to separate visibility between teams. This allows each team to focus only on their own alerts, avoiding confusion and overlap. The access is controlled through roles, so a user/team only sees alerts tied to their specific label.

The challenge I’m facing is with cross-team assignments. If a user from Team A (with Label A) wants to assign or escalate an alert to someone in Team B (with Label B), this isn’t possible because they don’t have access to that other label.

I’d like to know:

  1. Is there any supported method or workaround to allow cross-team assignment while still preserving restricted visibility?

  2. If such a transfer/escalation is possible, can the alert be hidden from the original team’s view once it has been reassigned to the new team?

The goal is to maintain clean separation of alerts per team while still allowing escalation paths between them.

Any guidance or best practices would be greatly appreciated.

Thank you!

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...