Delete or deactivate a team queue
You can deactivate a team queue so that the queue doesn't add any new findings or investigations into the queue and you cannot move any findings, investigations, or other artifacts into the queue manually. However, you can create findings and investigations manually within the deactivated queue. Deactivated queues can be deleted if all items in the queue are deleted or moved.
To identify all deactivated queues, go to the Inactive queues section on the Team queues page.
Delete or deactivate a team queue
Follow these steps to delete or deactivate a team queue:
- In Splunk Enterprise Security, select Configure and then Findings and investigations.
- Select Team queues.
- Go to the team queue that you want to deactivate and then select Deactivate.
Note: You can select Reactivate to re-activate a queue. A reactivated queue is appended to the end of the list of active queues regardless of its original position so that its priority is last among the active queues. As an administrator, you can manage queue priority and move a queue back to the desired position in the list.
- Expand the Inactive queues section and expand the queue that you just deactivated.
Note:
You can also view inactive queues in the queues panel of the Analyst queue page with an Inactive badge.
You can continue to working on investigations in inactive queues but must focus on resolving them. New findings cannot be triaged in an inactive queue but can be manually created in inactive queues.
Note: No new incidents get ingested into a deactivated queue and manual moving items into the queue is blocked. - Select Delete queue to delete the queue. You can also delete queues using REST API endpoints. For more information, see API Reference for Queues.