---
title: "SOC Queue FAQ"
slug: "soc-queue-faq"
updated: 2024-05-22T11:29:48Z
published: 2024-05-22T11:29:48Z
canonical: "docs.hunters.ai/soc-queue-faq"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hunters.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# SOC Queue FAQ

**What happens if I mark an Alert as "Done"?**

Marking an alert as done will remove it from the default SOC Queue view.

**Can I delete leads if they are incorrect or benign?**

Use [Ignore](/v1/docs/define-custom-scoring-rules) Rules to ignore and prevent new and existing matching activity from generating leads and retroactively remove any previous leads generated.

**If I delete leads, what happens to any related stories?**

Stories will change when leads are deleted, for more information click [here](/v1/docs/about-stories).

**What happens if I apply Custom scoring? Does it modify existing leads or just affect new leads?**

Custom scoring will only affect leads that were generated after the custom rule was created, custom scoring rules **are not** retroactive.

**What happens when I enable or disable alerts for a specific Lead?**

Alerts are added and removed from the SOC queue retroactively, excluding custom scoring changes which are not retroactive, and config changes made to alerting config will affect the alert population in the SOC queue.

**Why can’t I delete/share/edit a tab?**

Limitations on the SOC Queue tabs are a result of your assigned user role. Contact your Hunters platform administrator to learn more.

An alert refers to a notification generated by a security system or tool that indicates a potential security incident or threat. Alerts can be triggered by a variety of security events, such as unauthorized access attempts, malware infections, network anomalies, and other suspicious activity.

Custom scoring rules are a set of user-defined criteria used to assign risk scores to security events or incidents based on their severity, priority, and other factors.

A lead refers to a potential security incident or threat that has been identified through security monitoring activities or other sources of security intelligence.
