IDR Integration with Sigma / YARA for standardised log queries

Being able to run Sigma searches against data in Insight would be hugely beneficial. Every single SIEM competitor to Rapid7 has integrated with them, please can we look at integrating with this project! Additional points for allowing YARA queries in IDR.

1 Like

Hi @ben_cuthbert,

thank you so much for your feedback.
We currently are not supporting Sigma in IDR, but thank you for your input, we are going to review it and let you know :slight_smile:

Hi @mirela_smlatic.

Has there been any development here?

Glad to know update on sigma query support

Hi,

Unfortunately, we still don’t have Sigma on our roadmap.
For now, you can always ingest dana as custom logs and from there use our Custom Parser for the ability to create custom parsing rules for log events to extract the data you need.

Thank you so much,
Mirela