Security

Inadvertently edited 4000+ ES notable events - please help me undo them

DanAlexander
Communicator

Hello folks!

That is my first post here and I hope you guys help me with my issue.

I have inadvertently selected 4000+ notes and closed them all with the same note. 

Is there any script or anything on the ES Splunk UI I miss that can undo my mistake?

Your help is much appreciated!

Thank you all. 

Labels (1)
0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @DanAlexander 

Following is the lookup maintains the state of notables having status ( numbers ) and comments. You could filter based on comments and findout them and update lookup back to the status you wish to. Should be very careful have a backup before!

| inputlookup incident_review_lookup

From UI you could try -> try filter by providing the notes/comments you have provided and Urgency to closed. Should filter all the notables that have been modified.

Then 'Edit selected' and update the status.. etc or comments. I haven't tried myself these options be cautious and having enough backup to restore.

0 Karma

DanAlexander
Communicator

Thanks for the reply @venkatasri 

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...