Writing Detection Rules
detection rules can be written in any query language available but not.SH prefers Sigma for its flexibility and expression. to write a detection rule head to the detection page and click create detection up the top right. from there you can add all the meta data about your detection as well as the detection itself.Correlating Events
Scheduling Detections on SIEMs
Different Detection Rules can be deployed out to different SIEM instances, according with where your data lives. Certain detection languages will only be able to be run on certain SIEM products, for example Splunk Query Language can only run on Splunk servers.Selecting Logsources
When you attach a SIEM to noth.sh via asiem-agent, logsources are analysed to determine what log types are present on the instance.