> For the complete documentation index, see [llms.txt](https://docs.cloudcyte.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.cloudcyte.com/getting-started/agent-based-deployment/7.-reviewing-and-enabling-sigma-rules.md).

# 7. Reviewing and Enabling Sigma Rules

Once the sysmon data is collected, go to "Rules & Policies" -> "SIGMA/YARA Rules" -> "SIGMA Rules". Click on the three dots left side of the grid, select "Enable All Rules Displayed" and then select "Force Run All Rules Displayed". It is recommended to enable the rules after one day of sysmon collection.

Go to "Analysis & Investigation" -> "Hunting Settings" -> "Asset & Threat Analysis Settings" -> "Threat Detection Rules Run Interval (Hour)". Users can change the run interval and edit the next run time. Be sure to click the save button after editing.

<figure><img src="/files/9v6o8ICmtibszbnVGnHd" alt=""><figcaption></figcaption></figure>
