Security

Inadvertently edited 4000+ ES notable events - please help me undo them

DanAlexander
Communicator

Hello folks!

That is my first post here and I hope you guys help me with my issue.

I have inadvertently selected 4000+ notes and closed them all with the same note. 

Is there any script or anything on the ES Splunk UI I miss that can undo my mistake?

Your help is much appreciated!

Thank you all. 

Labels (1)
0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @DanAlexander 

Following is the lookup maintains the state of notables having status ( numbers ) and comments. You could filter based on comments and findout them and update lookup back to the status you wish to. Should be very careful have a backup before!

| inputlookup incident_review_lookup

From UI you could try -> try filter by providing the notes/comments you have provided and Urgency to closed. Should filter all the notables that have been modified.

Then 'Edit selected' and update the status.. etc or comments. I haven't tried myself these options be cautious and having enough backup to restore.

0 Karma

DanAlexander
Communicator

Thanks for the reply @venkatasri 

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...