Permissions for team-based queues

In Splunk Enterprise Security, team-based queues are how security operations center (SOC) teams organize and act on findings and investigations. Access to these queues is governed by permissions assigned to roles within your organization.

Queue permissions define what a role can do within a specific queue. This gives administrators precise control over each team's capabilities, matching the queue's purpose to the actions that a team is authorized to complete.

This document explains what each permission does, how permissions interact with each other, and how they determine which queues a user sees.

By assigning specific permissions to roles, administrators ensure that:

  • Analysts can work effectively within their assigned queue without accidentally or intentionally modifying items that belong to another team.
  • Escalation paths are clearly defined: a finding moves to the next queue only through an authorized action by a user with the right permissions.
  • Sensitive or high-priority queues can be restricted to senior analysts or administrators, while broader queues remain accessible to all tiers.
Administrators assign permissions for each queue and for each role. A role might have different permissions in different queues. For example, you can have Update access in the primary team queue and only Read access in a queue that you monitor but do not own.
Note: Note: The read permission is a prerequisite for the update permission. You cannot modify items in a queue that you are not permitted to view. Create, delete, and execute permissions can be assigned independently of the read permission, though in practice most roles that can act on a queue, also have the read permission assigned.

The following permissions can be assigned to a role for each queue:

Permission What it allows Needs read permission as prerequisite? Supported?
Create Creating new items in the queue, such as manual findings or investigations, notes, response plans, and so on. No Yes
Read Viewing items in the queue, including findings and investigations, along with related notes, files, and response plans. N/A Yes
Update Modifying items in the queue. Includes editing fields, changing status or disposition, moving items between queues, adding findings to investigations, and managing notes, files, and response plans. Yes Yes
Delete Deleting items in the queue, such as removing notes, files, or response plans. No No
Execute Running response actions on items in the queue. Does not apply to Splunk SOAR actions or playbooks.
Note: You can't run ping, nbtstats, or nslookup response actions with the execute permission.
No Yes

Capabilities based on permissions for team-based queues

You must have the Create permission to add new items to a queue, without requiring a Read permission. However, if you only have Create access, you do not see the queue on the Mission Control page and cannot view or interact with items already in the queue. In most cases, these permissions are assigned together.

You must have Create permission to create a note but not to update a queue. If you have Create permission but not the Update permission, you can create a new note and add new items to the queue such as manually create a finding.

You must have both the Create and Read permissions to add notes, files, response plans, and tasks to a queue.

You only need Read permission to view notes, files, response plans, and attachments.

In Splunk Enterprise Security version 8.6 and higher, you must have both the Delete and Read permissions to remove artifacts such as notes, files, response plans, and tasks from a queue.

The Read permission is a prerequisite for all other queue operations. However, direct API calls don't have a dependency on the Read permission. For example, if you have only the Update permission to a queue, then you can still update a finding using API calls.

If the notes required functionality is turned on by the administrator and a user does not have the Create permission, the user won't be able to update anything.

Manage role-based access for a queue

Follow these steps to choose which roles can access a queue and define exactly what each role is allowed to do:

  1. In Splunk Enterprise Security, select Configure and then Findings and investigations.

  2. Select the Manage queues page.

  3. Expand the queue you want to edit.

  4. Select the Roles tab.

  5. Select Edit.

  6. Select Customize access to view Show advanced configuration options.

  7. If Show advanced configuration options is unchecked, make sure to check it.

  8. Select the check boxes for the roles you want to grant access for.

  9. Select the check boxes for the more granular permissions you want to assign.

  10. Select Save.