Sigma rules

The Sigma rules page lets you manage the Sigma rules for Threat Intelligence that are applicable in an Arc deployment.

Figure 1. Sigma rules page

Sigma rules page

Sigma rules are versatile and generic rules written in the Sigma language. Primarily employed in threat detection and security information and event management (SIEM) systems, Sigma rules aim to standardize and offer a uniform method for describing log patterns across diverse security devices, applications, and platforms.

Live / refresh

The Live icon lets you change live view on, or off. When live mode is on, the page will refresh approximately every five seconds.

Add

This lets you add a new Sigma rule.