working with Sigma rules?

"Peter Czanik (pczanik)" <[email protected]> Wed, 9 Aug 2023 06:55:49 +0000
Newsgroups gmane.comp.syslog-ng
Message-ID <DM6PR19MB2986DC2E5D23C5384C509AEE8B12A@DM6PR19MB2986.namprd19.prod.outlook.com>
Hi,

Recently I was asked if Sigma rules (https://github.com/SigmaHQ/sigma) are supported by syslog-ng. Syslog-ng has message parsing, filtering, and can be used for alerting. But I'm not aware of any tools that could turn Sigma rules into PatternDB and syslog-ng.conf

Syslog-ng can send logs to Splunk, ElasticSearch / OpenSearch or Graylog, all which already have sigma rules integrations. Of course, many users use/abuse syslog-ng as a kind of SIEM-lite as it is very good at real-time alerting. However, as far as I can see, Sigma rules are better suited for threat hunting on the SIEM side.

If you already Sigma rules with syslog-ng or any other way: please share your experiences!

Thanks,
Peter

Peter Czanik (CzP) <[email protected]>
Balabit (a OneIdentity company) / syslog-ng upstream
https://syslog-ng.com/community/
https://twitter.com/PCzanik

______________________________________________________________________________
Member info: https://lists.balabit.hu/mailman/listinfo/syslog-ng
Documentation: http://www.balabit.com/support/documentation/?product=syslog-ng
FAQ: http://www.balabit.com/wiki/syslog-ng-faq