I have two separate tenants with two different siems. There is some overlap with logs but they're not all the same. If an alert fires in one tenant, I am trying to recreate the case with all the alerts grouped under it, case details, etc into the other tenant to have it worked by a separate team. I need to include each alert in the case along with the case wall comments.
Has anyone done this successfully with a playbook or is there a better way? Are the current api endpoints enough to do this? Worried about creating alert and get case alert because they use the post request