Hello folks!
That is my first post here and I hope you guys help me with my issue.
I have inadvertently selected 4000+ notes and closed them all with the same note.
Is there any script or anything on the ES Splunk UI I miss that can undo my mistake?
Your help is much appreciated!
Thank you all.
This might be a bit late but I actually did the same and would like to offer solution for others in same situation.
You just need to delete the entries from the incident_review lookup which should be a kv store.
I would test first to ensure that you don't accidentally delete your other legitimate updates because they can easily be wiped out.
I used the lookup editor to do this. I would carefully test out first before trying any bulk deletes though.