Sigma Rules

Sigma rules provide a standardized format for describing detection logic based on event logs. Use this page to manage Sigma rules that identify suspicious activity across log sources. These rules support consistent threat detection across heterogeneous environments.

Figure 1. Sigma Rules page

Screenshot of the Sigma Rules page listing detection rules and available management actions.

Refresh

The Refresh icon lets you immediately refresh the current view.

Live

The Live toggle lets you change live view on, or off. When live mode is on, the page will refresh periodically.

Add

The Add button lets you add new content.