After a while we want to restart the blog series. Today we want to show how to recover data in splunk which had been deleted using the "| delete" command.
Even if “| delete” is not a very common command, it’s used from time to time to clean up unwanted events. So what happens if you delete data by mistake? How to recover those events when the docs say it’s not possible?