Multiple Splunk Cloud Instances vs Rules
Im at a job that handles multiple instances of splunk cloud enterprise security per each tenant. And we need a solution to syncronize or ship out detection rules and versioning from 1 splunk cloud to the others... we were thinking to develop a local tool that connects all API keys from each splunk cloud instance and handle actions from there to push(post) new rules and also update or modify current ones? Any else had encountered this type of scenario, any solutions on how to achieve this? Thankyou