{"categories":[{"label":"Security","url":"https://skillfed.io/packages/category/security/3"}],"enrichment":{"capability":"Translates Sigma detection rules into Splunk search queries, supporting both plain queries and savedsearches.conf format output.","skillfed_tags":["sigma-rule-compiler","splunk-integration","detection-as-code"],"use_cases":["Convert detection rules to Splunk queries for automated deployment in security operations centers","Generate Splunk savedsearches.conf files from rules for scheduled detection workflows","Accelerate Splunk searches on Windows logs using Sysmon keyword optimization","Integrate rule libraries into Splunk environments without manual query rewriting","Build detection-as-code pipelines that translate security logic across SIEM platforms"],"what_it_does":"pySigma Splunk Backend is a compiler that converts detection rules into native Splunk search queries. It acts as a bridge between the Sigma ecosystem and Splunk, allowing security teams to author detections once and deploy them to Splunk without manual translation.\n\nThe package provides processing pipelines for Windows log detection and Sysmon acceleration, plus support for multiple output formats (plain queries and savedsearches.conf). It depends solely on pysigma and supports Python 3.10 through 3.14. The repository is actively maintained with no known security vulnerabilities.","worth_installing":"Yes, if you use Sigma rules and deploy to Splunk. The package is actively maintained, has low install friction, and fills a clear gap in the workflow. The copyleft LGPL-2.1-only license is standard for the Sigma ecosystem; verify it aligns with your distribution model. No known vulnerabilities."},"id":"pysigma-backend-splunk","links":{"html":"https://skillfed.io/packages/pysigma-backend-splunk","md":"https://skillfed.io/packages/pysigma-backend-splunk.md","pypi":"https://pypi.org/project/pysigma-backend-splunk/"},"maintenance":{"status":"active"},"meta":{"latest_release":"2026-03-22","license_spdx":null,"license_treatment":"copyleft","name":"pysigma-backend-splunk","python_support":"supports_current","summary":"pySigma Splunk backend"},"popularity":{"monthly_downloads":114386,"position":12296,"tier":"top_15000"},"security":{"n_vulnerabilities":0},"version":"2.1.0"}
