There is the finding API in ES 8.2:
https://help.splunk.com/en/splunk-enterprise-security-8/api-reference/8.2/splunk-enterprise-security...
which allows retrieve finding and Create a manual finding.
Does anybody knows if Splunk has plan to support update findings via API ?