Sigma is a open and vendor-agnostic signature format for logs. Official sigma repository includes rule format definition, a public ruleset, and python tooling for converting rules into various SIEM ...
Validate that Splunk is receiving the syslog messages from all the Vaults/Components Once you have validated Splunk is reciving the messages, for you will need to define the Field names for the values ...