How to set up Sigma rules for Elasticsearch SIEM

Got a fresh Sigma release and an Elasticsearch lab, but no clear path from Sigma YAML rules to detection rules in Elasticsearch SIEM? This guide shows how to set up sigma rules for Elasticsearch SIEM so you can turn community content into Elastic Security rules you can actually run.

We will stay focused on Elastic Security with Windows telemetry mapped to ECS, using sigma-cli, the Elasticsearch backend plugin, and the official Sigma rule packages.

By the end of this guide you will:

  • Install sigma-cli with either pip or uv
  • Install the Elasticsearch backend plugin so sigma-cli can output lucene
  • Download Sigma rules from the latest GitHub release
  • Convert Windows and Emerging Threats rules into Kibana compatible NDJSON
  • Import all generated rules into Kibana Detection rules in one go

The official Sigma Getting Started | Sigma Detection Format guide walks through a Splunk focused example. If you want a Splunk specific setup, follow that article. In this post we will do the same pipeline for Elasticsearch (lucene).

If you want to see how these Sigma based detections look for concrete techniques, check out:

1. Install sigma-cli

You can install sigma-cli in two ways, depending on whether you use uv in your environment or not.

sigma-cli is the command line interface built on top of pySigma, the Python library that parses and converts Sigma rules into backend specific queries.

Without uv (standard way)

pip3 install sigma-cli

Using uv

uv tool install sigma-cli --with pip

If you install with uv tool install, sigma-cli is available on your PATH while still being managed in an isolated environment, which is useful on lab boxes where you do not want to pollute the system Python. ⚙️

2. Install the Elasticsearch backend plugin

We need to install our backend plugin through sigma-cli so it knows how to talk to Elasticsearch and Elastic Security.

First, list any backends that are available using:

sigma plugin list -t backend

You should see existing backends similar to the screenshot below.

Now install the Elasticsearch plugin:

sigma plugin install elasticsearch

This pulls the plugin that knows how to translate Sigma rules into Elasticsearch Lucene queries and Elastic Security detection rule formats.

3. Download Sigma rules

You can download the Sigma rules from the latest release page: Releases · SigmaHQ/sigma. There are different rule packages available for download.

Which Sigma rule package should I use?

A detailed explanation can be found in the sigma/Releases.md file.

If you are new, best start with the Core Sigma package. It includes high quality rules of high confidence and relevance and should not produce many false positives.

In this guide I am using Core++ and ET (Emerging Threats) AddOn Rules to get stronger coverage.

Once downloaded, extract the archive so that you have a rules and a rules-emerging-threats directory that matches the repository layout.

Why this step matters for detection: these packages give you a curated, maintained Sigma ruleset instead of random one off rules from the internet.

4. Convert Sigma rules to Elasticsearch Lucene

Our goal is to convert many Sigma rules into NDJSON so we can upload them into Kibana in one go instead of creating each rule manually.

For converting the rules, we need to use sigma convert.

Join for free. Practical security bits you can act on the same day. No theory, no fluff.

No spam. Unsubscribe anytime.

For our case sigma convert needs three things:

  • targets
  • pipelines
  • formats

If you have not installed any backend yet, the targets and pipelines list will be empty.

To see which targets and pipelines are available:

After installing the Elasticsearch plugin, check targets and pipelines again:

sigma list targets
sigma list pipelines

This confirms that the lucene target and the ecs_windows pipeline are available and ready to use.

Because we will import multiple rules in one go and upload them to Kibana, we will use the lucene target and a format that generates Elastic Security detection rules.

For listing formats supported by lucene use:

sigma list formats lucene

I am only converting rules present in sigma_core++.zip (only Windows) and sigma_emerging_threats_addon.zip from Releases · SigmaHQ/sigma.

For Windows rules:

sigma convert -t lucene -p ecs_windows -f siem_rule_ndjson ./rules/windows --skip-unsupported -o windows_rules.ndjson

For Emerging Threats:

sigma convert -t lucene -p ecs_windows -f siem_rule_ndjson ./rules-emerging-threats --skip-unsupported -o emerging_threat_rules.ndjson

What these commands do for elasticsearch backend:

  • -t lucene selects the Elasticsearch Lucene query language.
  • -p ecs_windows applies the ECS Windows pipeline for correct field mappings.
  • -f siem_rule_ndjson outputs Kibana SIEM rules in NDJSON format.
  • --skip-unsupported skips rules that cannot be converted by this backend.
  • -o <file>.ndjson writes all generated rules into a single NDJSON file, ready for import.

At the end of this step you should have two files:

  • windows_rules.ndjson
  • emerging_threat_rules.ndjson

These will be imported into Kibana in the next step. From a defender perspective this means you have turned upstream Sigma content into concrete Elastic Security rules you can enable, tune, and monitor.

5. Upload NDJSON rules to Kibana

Open Kibana and navigate to Security -> Rules -> Detection rules (SIEM).

Click Import Rules and upload the two NDJSON files you generated in the previous step.

For more detail on import and export behavior, see the official Elastic documentation on managing detection rules.

I have not enabled Elastic prebuilt rules in this lab, but you can enable them alongside your Sigma based rules if you want more coverage.

After importing all rules, the Sigma based rules appear in the rules table:

At this point Elasticsearch is running Sigma rules converted by sigma-cli for the Elasticsearch backend, and you can start tuning, disabling noisy rules, and adding environment specific exceptions. ✅

Key takeaways for defenders

  • You now have a repeatable pipeline from upstream Sigma releases to Elastic detection rules.
  • Core++ rules give you broad coverage of common Windows TTPs, while Emerging Threats AddOn Rules track specific actors and exploits that may age faster.
  • The Elasticsearch backend and ecs_windows pipeline ensure field names line up with ECS, so matches are reliable instead of brittle string searches.
  • NDJSON export and bulk import let you treat detection rules as code and re seed a new Elastic lab in minutes.

References

Thanks for reading. Feel free to connect with me on or LinkedIn for any suggestions or comments.

For more updates and exclusive content, subscribe to our newsletter. Stay sharp. Keep defending.😊

Join for free. Practical security bits you can act on the same day. No theory, no fluff.

No spam. Unsubscribe anytime.

keyboard_arrow_up