Monitoring Splunk

Edit All Matching Notable Events - Can we undo this?

DanAlexander
Communicator

Hello folks!

That is my first post here and I hope you guys help me with my issue.

I have inadvertently selected 4000+ notes and closed them all with the same note. 

Is there any script or anything on the ES Splunk UI I miss that can undo my mistake?

Your help is much appreciated!

Thank you all. 

0 Karma

tah7004
Path Finder

This might be a bit late but I actually did the same and would like to offer solution for others in same situation. 

You just need to delete the entries from the incident_review lookup which should be a kv store. 

I would test first to ensure that you don't accidentally delete your other legitimate updates because they can easily be wiped out.

I used the lookup editor to do this.  I would carefully test out first before trying any bulk deletes though.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...