Learn how to import Sigma rules for conversion into TrendAI Vision One™ custom filters.
Important
|
Procedure
- Go to .
- Click Add filters and select Import from computer from the drop-down menu.
- On the Import custom filters window, click ZIP or YAML tab and click Select file.
- Select the ZIP or YAML file containing Sigma rules from your local computer.
- On the Unable to import tab, edit and validate files with supported formats. Remove files with unsupported formats.
- On the Edit Sigma rules and convert to TrendAI Vision One™ format window, edit the Sigma rule and click Convert to convert the format.

Note
-
Metadata fields such as
author,references, andfalsepositivesare preserved in the converted YAML file for reference but do not affect detection logic. -
Complex modifier chains such as
contains|allandwindashmight require manual adjustment. -
Rules from other repositories such as SOCPRIME and Elastic might successfully convert the format if the standard Sigma format and supported
logsourcecategories are used.
-
- Click Save.
- After editing or removing all files unable to import, click Import (number) files to begin the file import.TrendAI Vision One™ saves and enables the custom filter. This action might require a few minutes before taking effect.
