[syslog-ng] working with Sigma rules?