Is It Possible To Import Multiple Sigma Rules from YAML File #14620
Replies: 1 comment
-
https://docs.securityonion.net/en/2.4/sigma.html#custom-sigma-repositories You should be able to create a custom repo on disk and point to that. An example from the above would be |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.120
Installation Method
Security Onion ISO image
Description
configuration
Installation Type
Distributed
Location
on-prem with Internet access
Hardware Specs
Exceeds minimum requirements
CPU
20
RAM
768 GB
Storage for /
200 GB+
Storage for /nsm
1 TB+
Network Traffic Collection
tap
Network Traffic Speeds
Less than 1Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
No, there are no failures
Logs
No, there are no additional clues
Detail
I'm trying to figure out if there's a way to ingest a YAML file with many SIGMA rules, specifically this feed:
https://hijacklibs.net/api/sigma_feed_image.yml
I'm hoping someone has a way of doing that without creating a script that parses and pushed them to a git repo.
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions