rsigma rule validate
rsigma rule validate
rsigma rule validate
Added in v0.12.0Parse a Sigma rule file, or all Sigma rules in a directory (recursive), and report results.
Synopsis
rsigma rule validate [OPTIONS] <PATH>
Description
Parses a single Sigma file, or walks a directory and parses every *.yml/*.yaml Sigma file, with rsigma-parser, optionally applies one or more processing pipelines, and compiles each rule with the evaluator’s compiler. Reports the counts on stdout (human summary by default). Pass --output-format json|ndjson|table|csv|tsv for a structured envelope or PATH,STATUS,ERRORS rows. Exits with code 2 if any rule fails to parse or compile. See Output Formats.
Correlation references are checked as compile errors too. A correlation fails validation when it references a rule id or name that no detection or correlation rule carries. A reference that resolves to more than one rule also fails validation, which happens when rules share the referenced id or name, or when one rule’s name equals another rule’s id.
Added in v0.24.0
This is the cheapest CI gate: no events are evaluated, just rules and pipelines. Wire it as the first step of every detection-as-code pipeline before rule lint and engine eval fixture tests.
For narrative coverage see Linting Rules and CI/CD.
Flags
| Flag | Description |
|---|---|
<PATH> |
A Sigma YAML file, or a directory searched recursively for Sigma YAML files. Single files are accepted. Added in v0.24.0 |
-v, --verbose |
Show details for each file, not just the summary. |
-p, --pipeline <PIPELINES> |
Processing pipeline(s) to apply. Builtin names (ecs_windows, fibratus_windows, sysmon) or YAML file paths. Repeatable. |
--source <FILE_OR_DIR> |
External source file(s) or directory of source files. Repeatable. Same standalone sources: YAML shape as the daemon’s --source. Required for meaningful --resolve-sources runs after the v1.0 removal of pipeline-embedded sources:. |
--resolve-sources |
Resolve and fetch every loaded dynamic source during validation. Sources must be reachable for validation to pass. |
Examples
Plain validation
rsigma rule validate rules/
Output:
Parsed 24 documents from rules/
Detection rules: 22
Correlation rules: 2
Filter rules: 0
Parse errors: 0
Pipeline applied: 0 pipeline(s)
Compiled OK: 24
Compile errors: 0
Validate a single file
Added in v0.24.0rsigma rule validate rules/windows/proc_creation_whoami.yml
A YAML syntax error in the file counts as a parse error and exits with code 2, the same as a broken file inside a directory.
Validate with a pipeline applied
rsigma rule validate rules/ -p pipelines/ecs.yml
Catches rules that reference fields the pipeline drops or renames in an incompatible way.
Strict CI: also exercise dynamic sources
rsigma rule validate rules/ -p pipelines/dynamic.yml --source sources.yml --resolve-sources
The job fails with exit 3 if any HTTP, file, or command source is unreachable. Use this on PR builds for repos that ship dynamic pipelines.
Verbose per-file output
rsigma rule validate rules/ -v
Shows one line per file with its parse/compile status.
Exit codes
| Code | Meaning |
|---|---|
0 |
Every rule parsed and compiled cleanly. |
2 |
At least one parse or compile error. |
3 |
Pipeline file could not be loaded, --source load failure, --resolve-sources failed on a dynamic source, or the binary lacks the daemon feature needed for source resolution. |
See also
rule lintfor the spec-conformance gate (90 lint rules, auto-fix).rule parsefor a single-file AST dump.- Linting Rules and Processing Pipelines.
- CI/CD for the validate/lint/eval pipeline pattern.