Security

Inadvertently edited 4000+ ES notable events - please help me undo them

DanAlexander
Communicator

Hello folks!

That is my first post here and I hope you guys help me with my issue.

I have inadvertently selected 4000+ notes and closed them all with the same note. 

Is there any script or anything on the ES Splunk UI I miss that can undo my mistake?

Your help is much appreciated!

Thank you all. 

Labels (1)
0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @DanAlexander 

Following is the lookup maintains the state of notables having status ( numbers ) and comments. You could filter based on comments and findout them and update lookup back to the status you wish to. Should be very careful have a backup before!

| inputlookup incident_review_lookup

From UI you could try -> try filter by providing the notes/comments you have provided and Urgency to closed. Should filter all the notables that have been modified.

Then 'Edit selected' and update the status.. etc or comments. I haven't tried myself these options be cautious and having enough backup to restore.

0 Karma

DanAlexander
Communicator

Thanks for the reply @venkatasri 

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...