$npx skillfedfor your agent

pySigma-backend-elasticsearch

pySigma Elasticsearch backend supporting Lucene, ES|QL (with correlations) and EQL queries

Worth itPyPI SecurityReleased Aug 2026111.8K downloads / moLGPL-3.0-onlyPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — pysigma_backend_elasticsearch-2.1.1-py3-none-any.whl
v2.1.1 · released 2026-08-10 · Python <4.0,>=3.10 · 1 runtime deps: pysigma

Yes. This is a well-maintained, actively released backend with low install friction and no known vulnerabilities. Install it if you author or deploy Sigma rules and need to run them against Elasticsearch. The copyleft license (LGPL-3.0-only) is standard for this ecosystem and poses no barrier to use; it only affects redistribution of modified source code.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later (requires_python: >=3.10,<4.0).
  • The pysigma runtime dependency must be installed.
  • Low friction install with a single runtime dependency (pysigma).

License · maintenance · safety

LGPL-3.0-only (copyleft) — Licensed under LGPL-3.0-only (copyleft). Derivative works and distributions must provide source code access and maintain the same license.

last release 2026-08-10 (4 days)

0 known vulnerabilities (OSV.dev, 2026-08-14) · 111,775 downloads/mo, #12,398 on PyPI

Verify before relying

pip install pysigma-backend-elasticsearch

from sigma.backends.elasticsearch import LuceneBackend
backend = LuceneBackend()
query = backend.convert_rule(rule)
  • Whether the backend supports all Sigma rule types or has known limitations with specific rule constructs.
  • Performance characteristics when converting large rule sets or complex nested conditions.
  • Compatibility guarantees with specific Elasticsearch and Kibana versions.
Same gist for agents: .md · .json

What it is and what it does

This is a backend plugin for pySigma that converts Sigma detection rules into query formats compatible with Elasticsearch and Kibana. It provides multiple output formats—Lucene queries (the default), DSL with embedded Lucene, EQL (Elastic Event Query Language), and Kibana NDJSON—allowing security teams to deploy the same rule logic across different Elasticsearch environments. The package includes processing pipelines that map generic Sigma field names to environment-specific schemas: ECS mappings for Windows events via Winlogbeat, Zeek logs from both Elastic and Corelight, Kubernetes audit logs, and macOS Endpoint Security Framework events. This bridges the gap between rule authoring and operational deployment.

The backend is actively maintained and supports query post-processing via custom YAML pipelines, enabling teams to customize output formats beyond the built-in options. The package depends only on pysigma and supports Python 3.10–3.14.

Use it for

  • Convert Sigma rules to Lucene queries for deployment in existing Elasticsearch SIEM environments.
  • Generate EQL queries for Elastic's event correlation and threat hunting workflows.
  • Export Sigma rules as Kibana NDJSON saved searches or SIEM detection rules for import.
  • Map Windows event logs ingested via Winlogbeat to Sigma rule field names using ECS pipelines.
  • Translate Zeek network logs to Elasticsearch queries using Elastic or Corelight ECS mappings.
  • Customize rule output format via query post-processing pipelines for organization-specific requirements.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

This is a well-maintained, actively released backend with low install friction and no known vulnerabilities. Install it if you author or deploy Sigma rules and need to run them against Elasticsearch. The copyleft license (LGPL-3.0-only) is standard for this ecosystem and poses no barrier to use; it only affects redistribution of modified source code.

Install

pysigma-backend-elasticsearch on PyPI

Before you install

Low friction install with a single runtime dependency (pysigma). Actively maintained with a release 4 days ago, supporting Python 3.10–3.14.

Requires Python 3.10 or later (requires_python: >=3.10,<4.0). The pysigma runtime dependency must be installed.

License in practice

Licensed under LGPL-3.0-only (copyleft). Derivative works and distributions must provide source code access and maintain the same license.

Quickstart

pip install pysigma-backend-elasticsearch

from sigma.backends.elasticsearch import LuceneBackend
backend = LuceneBackend()
query = backend.convert_rule(rule)

Verify before relying

  • Whether the backend supports all Sigma rule types or has known limitations with specific rule constructs.
  • Performance characteristics when converting large rule sets or complex nested conditions.
  • Compatibility guarantees with specific Elasticsearch and Kibana versions.

Package facts

LicenseLGPL-3.0-only copyleft
Python supportSupports the current Python release <4.0,>=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
1 package
pysigma
MaintenanceActively maintained 4 days since the last release
First released
Downloads111,775 / month, #12,398 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Programming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14

Evidence: pysigma_backend_elasticsearch-2.1.1-py3-none-any.whl

Tags

Capabilities
sigma to elasticsearch query translationlucene query generator from sigma ruleseql query backendkibana ndjson exportsecurity rule conversion elasticsearchwindows event log ecs mappingzeek log elasticsearch backend
Topics
sigma-ruleselasticsearch-backendthreat-detection

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “sigma to elasticsearch query translation”

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also pySigma · pysigma-backend-splunk · luqum · sigmatools · django-elasticsearch-dsl · elasticsearch8-dsl · elasticsearch-dsl · elasticsearch-dbapi · langchain-elasticsearch · elasticsearch