I was wondering if anyone is importing the sigma ruleset into the alerting plugin of odfe? (https://github.com/Neo23x0/sigma). Is there something like the sigma2elastalert.py that you know of?
I am just trying to figure out if it’s worth testing while doing a PoC. Online research hasn’t turned up much information so far.