Hi there!
Please allow me to admit, I'm newbie to splunk + sigma rules for detection.
In my test environment, I have imported windows sysmon event logs. I understand that using sigmac, I can create rules for splunk. My Q is how would I use those sigma rules for use with splunk for detection ?
My understanding is that when I ingest new logs, splunk would auto run those rules against newly ingested logs ? Thank you