Move a finding or investigation to a different queue

Move a finding, finding group, or investigation to a different team-based queue. You have the option to move items between queues only if all of the following are true:
  • Your role has assigned visibility to both queues

  • Moving is allowed in the queue settings

  • The item has not been added to an investigation or finding group

  1. In Splunk Enterprise Security, select Mission Control to open your team queue.
    If you can't see your team queue, open the left-side panel to navigate to the correct one.
  2. Using the check boxes in the table, select the items you want to move to a different queue. Or, if you only want to move one item, select the more icon ( three dots ) for that item.
  3. Select Move to new queue.
  4. In the dialog box, select the queue you want to move the items to.
  5. Select Move to queue.