# SIEM prebuilt rules

**URL:** https://discuss.elastic.co/t/siem-prebuilt-rules/274724
**Category:** SIEM
**Created:** [June 2, 2021, 9:12am UTC](https://discuss.elastic.co/t/siem-prebuilt-rules/274724 "2021-06-02T09:12:30Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![tarekilani](https://avatars.discourse-cdn.com/v4/letter/t/54ee81/32.png) [@tarekilani](https://discuss.elastic.co/u/tarekilani)
#### Post date: [June 2, 2021, 9:12am UTC](https://discuss.elastic.co/t/siem-prebuilt-rules/274724/1 "2021-06-02T09:12:30Z")

</div>

Hello,

I'm searching for prebuild rules for elastic SIEM, i found that i can use elastic provided rules :

> **[elastic/detection-rules](https://github.com/elastic/detection-rules)**
>
> Rules for Elastic Security's detection engine. Contribute to elastic/detection-rules development by creating an account on GitHub.

But i would like to know if there is any other source to get pre build rules for elastic SIEM, for example rules for fortigate, sophos firewalls and other network devices.  
Thanks in advance.

---

<div class="post-metadata">

### Author: ![devonkerr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/devonkerr/32/56711_2.png) [@devonkerr](https://discuss.elastic.co/u/devonkerr)
#### Post date: [June 2, 2021, 11:54am UTC](https://discuss.elastic.co/t/siem-prebuilt-rules/274724/2 "2021-06-02T11:54:36Z")

</div>

Tarek, I'm not aware of any third-party provider of rules for our detection engine and we encourage community and industry members to contribute to the detection-rules repository. This project is open to the community, which enables anyone to submit rules. If you've developed rules for network appliances, consider a pull request using our accessible process. Each release, I consider community feedback like yours to help address needs of members - we don't have plans to integrate Fortigate or Sophos data sources in a near-term release.

---

<div class="post-metadata">

### Author: ![Felix\_Roessel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felix_roessel/32/41623_2.png) [@Felix\_Roessel](https://discuss.elastic.co/u/Felix_Roessel)
#### Post date: [June 2, 2021, 2:43pm UTC](https://discuss.elastic.co/t/siem-prebuilt-rules/274724/3 "2021-06-02T14:43:17Z")

</div>

Here you can find prebuilt rules based on SIGMA

> **[Elastic SIEM detection rules | Download now at elastic content share](https://elastic-content-share.eu/downloads/category/kibana/siem-detection-rules/)**
>
> Download pre build detection rules like Sigma rules for Elastic SIEM and Elastic Endpoint Security.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [June 30, 2021, 2:43pm UTC](https://discuss.elastic.co/t/siem-prebuilt-rules/274724/4 "2021-06-30T14:43:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
