Got a fresh Sigma release and an Elasticsearch lab, but no clear path from Sigma YAML rules to detection rules in Elasticsearch SIEM? This guide shows how to set up sigma rules for Elasticsearch SIEM so you can turn community content into Elastic Security rules you can actually run.
We will stay focused on Elastic Security with Windows telemetry mapped to ECS, using sigma-cli, the Elasticsearch backend plugin, and the official Sigma rule packages.
By the end of this guide you will:
- Install
sigma-cliwith eitherpiporuv - Install the Elasticsearch backend plugin so
sigma-clican output lucene - Download Sigma rules from the latest GitHub release
- Convert Windows and Emerging Threats rules into Kibana compatible NDJSON
- Import all generated rules into Kibana Detection rules in one go
The official Sigma Getting Started | Sigma Detection Format guide walks through a Splunk focused example. If you want a Splunk specific setup, follow that article. In this post we will do the same pipeline for Elasticsearch (lucene).
If you want to see how these Sigma based detections look for concrete techniques, check out:
1. Install sigma-cli
You can install sigma-cli in two ways, depending on whether you use uv in your environment or not.
sigma-cli is the command line interface built on top of pySigma, the Python library that parses and converts Sigma rules into backend specific queries.
Without uv (standard way)
pip3 install sigma-cli
Using uv
uv tool install sigma-cli --with pip
If you install with uv tool install, sigma-cli is available on your PATH while still being managed in an isolated environment, which is useful on lab boxes where you do not want to pollute the system Python. ⚙️
2. Install the Elasticsearch backend plugin
We need to install our backend plugin through sigma-cli so it knows how to talk to Elasticsearch and Elastic Security.
First, list any backends that are available using:
sigma plugin list -t backend
You should see existing backends similar to the screenshot below.
Now install the Elasticsearch plugin:
sigma plugin install elasticsearch
This pulls the plugin that knows how to translate Sigma rules into Elasticsearch Lucene queries and Elastic Security detection rule formats.
3. Download Sigma rules
You can download the Sigma rules from the latest release page: Releases · SigmaHQ/sigma. There are different rule packages available for download.
Which Sigma rule package should I use?
A detailed explanation can be found in the sigma/Releases.md file.
If you are new, best start with the Core Sigma package. It includes high quality rules of high confidence and relevance and should not produce many false positives.
In this guide I am using Core++ and ET (Emerging Threats) AddOn Rules to get stronger coverage.
Once downloaded, extract the archive so that you have a rules and a rules-emerging-threats directory that matches the repository layout.
Why this step matters for detection: these packages give you a curated, maintained Sigma ruleset instead of random one off rules from the internet.
4. Convert Sigma rules to Elasticsearch Lucene
Our goal is to convert many Sigma rules into NDJSON so we can upload them into Kibana in one go instead of creating each rule manually.
For converting the rules, we need to use sigma convert.
Join for free. Practical security bits you can act on the same day. No theory, no fluff.
No spam. Unsubscribe anytime.
For our case sigma convert needs three things:
- targets
- pipelines
- formats
If you have not installed any backend yet, the targets and pipelines list will be empty.
To see which targets and pipelines are available:
After installing the Elasticsearch plugin, check targets and pipelines again:
sigma list targets
sigma list pipelines
This confirms that the lucene target and the ecs_windows pipeline are available and ready to use.
Because we will import multiple rules in one go and upload them to Kibana, we will use the lucene target and a format that generates Elastic Security detection rules.
For listing formats supported by lucene use:
sigma list formats lucene
I am only converting rules present in sigma_core++.zip (only Windows) and sigma_emerging_threats_addon.zip from Releases · SigmaHQ/sigma.
For Windows rules:
sigma convert -t lucene -p ecs_windows -f siem_rule_ndjson ./rules/windows --skip-unsupported -o windows_rules.ndjson
For Emerging Threats:
sigma convert -t lucene -p ecs_windows -f siem_rule_ndjson ./rules-emerging-threats --skip-unsupported -o emerging_threat_rules.ndjson
What these commands do for elasticsearch backend:
-t luceneselects the Elasticsearch Lucene query language.-p ecs_windowsapplies the ECS Windows pipeline for correct field mappings.-f siem_rule_ndjsonoutputs Kibana SIEM rules in NDJSON format.--skip-unsupportedskips rules that cannot be converted by this backend.-o <file>.ndjsonwrites all generated rules into a single NDJSON file, ready for import.
At the end of this step you should have two files:
windows_rules.ndjsonemerging_threat_rules.ndjson
These will be imported into Kibana in the next step. From a defender perspective this means you have turned upstream Sigma content into concrete Elastic Security rules you can enable, tune, and monitor.
5. Upload NDJSON rules to Kibana
Open Kibana and navigate to Security -> Rules -> Detection rules (SIEM).
Click Import Rules and upload the two NDJSON files you generated in the previous step.
For more detail on import and export behavior, see the official Elastic documentation on managing detection rules.
I have not enabled Elastic prebuilt rules in this lab, but you can enable them alongside your Sigma based rules if you want more coverage.
After importing all rules, the Sigma based rules appear in the rules table:
At this point Elasticsearch is running Sigma rules converted by sigma-cli for the Elasticsearch backend, and you can start tuning, disabling noisy rules, and adding environment specific exceptions. ✅
Key takeaways for defenders
- You now have a repeatable pipeline from upstream Sigma releases to Elastic detection rules.
- Core++ rules give you broad coverage of common Windows TTPs, while Emerging Threats AddOn Rules track specific actors and exploits that may age faster.
- The Elasticsearch backend and
ecs_windowspipeline ensure field names line up with ECS, so matches are reliable instead of brittle string searches. - NDJSON export and bulk import let you treat detection rules as code and re seed a new Elastic lab in minutes.










