Security

Inadvertently edited 4000+ ES notable events - please help me undo them

DanAlexander
Communicator

Hello folks!

That is my first post here and I hope you guys help me with my issue.

I have inadvertently selected 4000+ notes and closed them all with the same note. 

Is there any script or anything on the ES Splunk UI I miss that can undo my mistake?

Your help is much appreciated!

Thank you all. 

0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @DanAlexander 

Following is the lookup maintains the state of notables having status ( numbers ) and comments. You could filter based on comments and findout them and update lookup back to the status you wish to. Should be very careful have a backup before!

| inputlookup incident_review_lookup

From UI you could try -> try filter by providing the notes/comments you have provided and Urgency to closed. Should filter all the notables that have been modified.

Then 'Edit selected' and update the status.. etc or comments. I haven't tried myself these options be cautious and having enough backup to restore.

0 Karma

DanAlexander
Communicator

Thanks for the reply @venkatasri 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...