SPL

Sigma to Splunk

Paste a Sigma rule, get SPL you can run. Free, no sign-up, and it shows the field map it used.

certutil
Tab indents · Shift+Tab outdents · Esc then Tab leaves the field28 lines · 906 B
Splunk logo An information technology company based in California, United States Splunk

Target not listed? Tell us which →
` Target: Splunk (SPL) — engine 1.0.0 — 2026-08-02 `
` Profile: windows / process_creation → Splunk `
` Coverage: 2/2 conditions `
` Setup (sigma_windows_process_creation): This query opens with the macro 'sigma_windows_process_creation', which you define once in your Splunk instance to select the index and sourcetype for this log source — Splunk's own detection library works the same way, because index naming is per-customer. Define it as a search fragment such as 'index=windows sourcetype=XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'; if you define it as a generating command like '| tstats', remove the leading comment as well. `
` Verify against your own telemetry before deploying. `
` huntrule.com — sigma 7c1e0a34-2b5f-4d18-9a63-0c8b1f4e5a71 — HuntRule Team — DRL-1.1 ` `sigma_windows_process_creation` ((process_path="*\\certutil.exe" OR original_file_name="CertUtil.exe") AND (process="*-encode*" OR process="*/encode*" OR process="*–encode*" OR process="*—encode*" OR process="*―encode*"))

sigma_windows_process_creationThis query opens with the macro `sigma_windows_process_creation`, which you define once in your Splunk instance to select the index and sourcetype for this log source — Splunk's own detection library works the same way, because index naming is per-customer. Define it as a search fragment such as `index=windows sourcetype=XmlWinEventLog:Microsoft-Windows-Sysmon/Operational`; if you define it as a generating command like `| tstats`, remove the leading comment as well.

1 line · 322 B2/2 conditions

Verify this query against your own telemetry before deploying it — a converted rule is a starting point, not a tuned detection.

Conversion reportwindows / process_creation → Splunk3 fields mappedClean

Every condition converted cleanly to Splunk SPL.

Profile

Matched on product + category

Field map

Sigma fieldTarget fieldSource
CommandLineprocessdocs.splunk.com
Imageprocess_pathdocs.splunk.com
OriginalFileNameoriginal_file_namedocs.splunk.com

Coverage

  1. selection_imgexpressed
  2. selection_cliexpressed

2 / 2 conditions expressed

Engine 1.0.02026-08-02Rule licensed DRL-1.1

Worked examples on Splunk

Real published rules run through the same engine as the tool above — including the ones it cannot take whole.

  1. Base64 Encoding Via Built-In Windows Utilitywindows / process_creationClean

    Sigma

    title: Base64 Encoding Via Built-In Windows Utility
    id: 7c1e0a34-2b5f-4d18-9a63-0c8b1f4e5a71
    status: experimental
    description: |
        A sample rule for the huntrule.com converter. Detects a built-in utility being asked to
        base64-encode a file, which is a common way to stage data before moving it off a host.
        It exercises the `windash` modifier, where one flag has to be matched in both its dash
        and slash spellings.
    author: HuntRule Team
    date: 2026-08-01
    tags:
        - attack.collection
        - attack.t1560.001
    logsource:
        category: process_creation
        product: windows
    detection:
        selection_img:
            - Image|endswith: '\certutil.exe'
            - OriginalFileName: 'CertUtil.exe'
        selection_cli:
            CommandLine|contains|windash: '-encode'
        condition: all of selection_*
    falsepositives:
        - Administrative scripts that legitimately encode files
    level: medium
    license: DRL-1.1
    

    Splunk · SPL

    ` huntrule.com — sigma 7c1e0a34-2b5f-4d18-9a63-0c8b1f4e5a71 — HuntRule Team — DRL-1.1 ` `sigma_windows_process_creation` ((process_path="*\\certutil.exe" OR original_file_name="CertUtil.exe") AND (process="*-encode*" OR process="*/encode*" OR process="*–encode*" OR process="*—encode*" OR process="*―encode*"))

    Every condition converted cleanly to Splunk SPL. 2/2 conditions

  2. PowerShell Download Cradle On The Command Linewindows / process_creationClean

    Sigma

    title: PowerShell Download Cradle On The Command Line
    id: 1f9d4c02-6a77-4e5b-8c31-2d0af7b96e48
    status: experimental
    description: |
        A sample rule for the huntrule.com converter. Detects the download-and-run pattern where a
        remote payload is fetched and executed in one command. It exercises a value list under a
        single field, which every backend has to expand into its own OR form.
    author: HuntRule Team
    date: 2026-08-01
    tags:
        - attack.execution
        - attack.t1059.001
    logsource:
        category: process_creation
        product: windows
    detection:
        selection_fetch:
            CommandLine|contains:
                - '.DownloadString('
                - '.DownloadFile('
                - 'Invoke-WebRequest '
                - 'Invoke-RestMethod '
        selection_run:
            CommandLine|contains:
                - '| IEX'
                - 'IEX ('
                - 'Invoke-Expression'
        condition: all of selection_*
    falsepositives:
        - Installers and package managers that fetch and run their own payloads
    level: high
    license: DRL-1.1
    

    Splunk · SPL

    ` huntrule.com — sigma 1f9d4c02-6a77-4e5b-8c31-2d0af7b96e48 — HuntRule Team — DRL-1.1 ` `sigma_windows_process_creation` ((process="*.DownloadString(*" OR process="*.DownloadFile(*" OR process="*Invoke-WebRequest *" OR process="*Invoke-RestMethod *") AND (process="*\| IEX*" OR process="*IEX (*" OR process="*Invoke-Expression*"))

    Every condition converted cleanly to Splunk SPL. 2/2 conditions

  3. Registry Import With A Suspicious Pathwindows / process_creationClean

    Sigma

    title: Registry Import With A Suspicious Path
    id: 5b3a8e91-4c26-4f70-b1d8-6e97c30a2f5d
    status: experimental
    description: |
        A sample rule for the huntrule.com converter. Detects a registry import whose argument does
        not look like an ordinary file path. It exercises a regular expression alongside a `not`
        filter, so the report has both a regex to check against the target's engine and a negated
        branch to place.
    author: HuntRule Team
    date: 2026-08-01
    tags:
        - attack.defense-evasion
        - attack.t1112
    logsource:
        category: process_creation
        product: windows
    detection:
        selection_img:
            - Image|endswith: '\regedit.exe'
            - OriginalFileName: 'REGEDIT.EXE'
        selection_cli:
            CommandLine|contains: '.reg'
            CommandLine|re: ':[^ \\]'
        filter_flags:
            CommandLine|contains|windash:
                - ' -e '
                - ' -a '
        condition: all of selection_* and not filter_flags
    falsepositives:
        - Scripted registry maintenance
    level: high
    license: DRL-1.1
    

    Splunk · SPL

    ` huntrule.com — sigma 5b3a8e91-4c26-4f70-b1d8-6e97c30a2f5d — HuntRule Team — DRL-1.1 ` `sigma_windows_process_creation` ((process_path="*\\regedit.exe" OR original_file_name="REGEDIT.EXE") AND process="*.reg*" AND (NOT (process="* -e *" OR process="* /e *" OR process="* –e *" OR process="* —e *" OR process="* ―e *" OR process="* -a *" OR process="* /a *" OR process="* –a *" OR process="* —a *" OR process="* ―a *")))
    | regex process=":[^ \x5c]"

    Every condition converted cleanly to Splunk SPL. 3/3 conditions

  4. File Copy Through The Print Utilitywindows / process_creationClean

    Sigma

    title: File Copy Through The Print Utility
    id: 3e6c17b8-9f40-4a2d-85e1-7b4d0c9a6f23
    status: experimental
    description: |
        A sample rule for the huntrule.com converter. Detects the print utility being used to copy an
        executable rather than to print. It exercises `startswith` together with `contains|all`, where
        several substrings must all appear in one field.
    author: HuntRule Team
    date: 2026-08-01
    tags:
        - attack.defense-evasion
        - attack.t1218
    logsource:
        category: process_creation
        product: windows
    detection:
        selection:
            Image|endswith: '\print.exe'
            CommandLine|startswith: 'print'
            CommandLine|contains|all:
                - '/D'
                - '.exe'
        filter_self:
            CommandLine|contains: 'print.exe'
        condition: selection and not filter_self
    falsepositives:
        - Printing a file whose name ends in .exe
    level: medium
    license: DRL-1.1
    

    Splunk · SPL

    ` huntrule.com — sigma 3e6c17b8-9f40-4a2d-85e1-7b4d0c9a6f23 — HuntRule Team — DRL-1.1 ` `sigma_windows_process_creation` (process_path="*\\print.exe" AND process="print*" AND process="*/D*" AND process="*.exe*" AND (NOT process="*print.exe*"))

    Every condition converted cleanly to Splunk SPL. 2/2 conditions

What to know about Splunk SPL

SPL is forgiving in the place that matters most for a converted rule: fields are resolved at search time, so a field name the profile could not map is passed through rather than rejected. That means a Splunk conversion almost always produces something that runs — and it is exactly why the report below matters. A query that runs is not the same as a query that matches, and a Sigma field carried through unchanged only fires if your index happens to use that name.

Wildcards are the other place Sigma and SPL disagree quietly. Sigma's `*` is a substring wildcard anywhere in a value; SPL's is too, but only inside quoted terms and only after the search-time field extraction has run. The converter emits quoted wildcards and escapes backslashes for Windows paths, which is the single most common way a hand-written Splunk translation of a Sigma rule silently matches nothing.

The default profile assumes a CIM-normalised index — `process_path`, `process`, `parent_process_path` — because that is what most Splunk estates running Sysmon actually have. If yours is raw, change the profile in the report and convert again; the runners-up are listed with what each matched on.

Splunk SPL reference →

How it works

  1. Step 1

    Paste the rule

    Drop a Sigma rule into the left pane, or open a .yml file. The tool says what it thinks you pasted before anything is sent.

  2. Step 2

    Pick your SIEM

    Choose the target dialect. Every shipped target is free and none of them are behind a sign-up.

  3. Step 3

    Read the report

    The query comes back with the log-source profile that was used, every field it renamed, and anything the target could not express.

  4. Step 4

    Verify, then deploy

    Run it against your own telemetry in audit mode before it alerts on anything.

Questions

Paste the Sigma rule into the tool on this page and press Convert. It returns SPL for Splunk, the log-source profile it matched, the field map it applied, and anything Splunk cannot express. Free, no sign-up.

By default, yes — CIM Endpoint field names are what most Splunk estates running Sysmon have. The report names the profile it used and lists the alternatives, and you can convert again against any of them.

Usually a field name. SPL resolves fields at search time, so an unmapped Sigma field is passed through and the clause only matches where that exact name exists. The report flags every passed-through field for this reason.

It will run if your field names match the profile shown in the report. Whether it matches the right events depends on your own telemetry, so verify it before deploying. The coverage figure tells you how much of the rule made it into the query.

The other pair

The same tool, with a different target preselected.

Every rule in the detection catalog is written in Sigma, so any of them converts to Splunk here.