SIgma rules for Elastic SIEM

You can start here