Hello folks!
That is my first post here and I hope you guys help me with my issue.
I have inadvertently selected 4000+ notes and closed them all with the same note.
Is there any script or anything on the ES Splunk UI I miss that can undo my mistake?
Your help is much appreciated!
Thank you all.
Following is the lookup maintains the state of notables having status ( numbers ) and comments. You could filter based on comments and findout them and update lookup back to the status you wish to. Should be very careful have a backup before!
| inputlookup incident_review_lookup
From UI you could try -> try filter by providing the notes/comments you have provided and Urgency to closed. Should filter all the notables that have been modified.
Then 'Edit selected' and update the status.. etc or comments. I haven't tried myself these options be cautious and having enough backup to restore.
Thanks for the reply @venkatasri