{"categories":[{"label":"Security","url":"https://skillfed.io/packages/category/security/3"}],"enrichment":{"capability":"Translates Sigma security rules into Elasticsearch query formats including Lucene, EQL, and Kibana NDJSON, with processing pipelines for Windows, Zeek, Kubernetes, and macOS event log mappings.","skillfed_tags":["sigma-rules","elasticsearch-backend","threat-detection"],"use_cases":["Convert Sigma rules to Lucene queries for deployment in existing Elasticsearch SIEM environments.","Generate EQL queries for Elastic's event correlation and threat hunting workflows.","Export Sigma rules as Kibana NDJSON saved searches or SIEM detection rules for import.","Map Windows event logs ingested via Winlogbeat to Sigma rule field names using ECS pipelines.","Translate Zeek network logs to Elasticsearch queries using Elastic or Corelight ECS mappings.","Customize rule output format via query post-processing pipelines for organization-specific requirements."],"what_it_does":"This is a backend plugin for pySigma that converts Sigma detection rules into query formats compatible with Elasticsearch and Kibana. It provides multiple output formats\u2014Lucene queries (the default), DSL with embedded Lucene, EQL (Elastic Event Query Language), and Kibana NDJSON\u2014allowing security teams to deploy the same rule logic across different Elasticsearch environments. The package includes processing pipelines that map generic Sigma field names to environment-specific schemas: ECS mappings for Windows events via Winlogbeat, Zeek logs from both Elastic and Corelight, Kubernetes audit logs, and macOS Endpoint Security Framework events. This bridges the gap between rule authoring and operational deployment.\n\nThe backend is actively maintained and supports query post-processing via custom YAML pipelines, enabling teams to customize output formats beyond the built-in options. The package depends only on pysigma and supports Python 3.10\u20133.14.","worth_installing":"Yes. This is a well-maintained, actively released backend with low install friction and no known vulnerabilities. Install it if you author or deploy Sigma rules and need to run them against Elasticsearch. The copyleft license (LGPL-3.0-only) is standard for this ecosystem and poses no barrier to use; it only affects redistribution of modified source code."},"id":"pysigma-backend-elasticsearch","links":{"html":"https://skillfed.io/packages/pysigma-backend-elasticsearch","md":"https://skillfed.io/packages/pysigma-backend-elasticsearch.md","pypi":"https://pypi.org/project/pysigma-backend-elasticsearch/"},"maintenance":{"status":"active"},"meta":{"latest_release":"2026-08-10","license_spdx":"LGPL-3.0-only","license_treatment":"copyleft","name":"pySigma-backend-elasticsearch","python_support":"supports_current","summary":"pySigma Elasticsearch backend supporting Lucene, ES|QL (with correlations) and EQL queries"},"popularity":{"monthly_downloads":111775,"position":12398,"tier":"top_15000"},"security":{"n_vulnerabilities":0},"version":"2.1.1"}
