Skip to content

File Upload

The File Upload feature in Realm allows you to securely bring your external business data, detection rules, and configuration files directly into the Realm platform. By uploading these files, you unlock advanced use cases like custom enrichments, enhanced business context, and deep detection engineering workflows.

File Upload primarily powers the Detection Integrity workflow, allowing you to validate, translate, and optimize your existing SIEM detection rules within Realm.

Use Case: Detection Integrity

Maintaining visibility across your security footprint requires ensuring that your detection rules are accurate, optimized, and free of gaps. The Detection Integrity workflow allows you to upload your legacy or active SIEM rules into Realm to see how they map, translate, and perform against your actual log volume.

Core Features & Technical Specifications

  • Supported File Formats: Explicitly supports .csv, .json, .yaml, .jsonl, .yml, .zip, .tgz, and .py file types.
  • Size Restrictions: Maximum file upload limit of 100MB per file.
  • SIEM Vendor Compatibility: Realm supports rules exported from any SIEM vendor for this workflow.

Step-by-Step Guide: Uploading Files for Detection Integrity

Follow these steps to upload your detection rules and begin the Detection Integrity process.

Step 1: Access the File Upload Interface

  1. Log into your Realm Console.
  2. Navigate to Settings > File Uploads via the left-hand navigation menu.

file uploading

Step 2: Upload Your Detection Rules

  1. Click the Upload File button in the top right corner.
  2. Drag and drop your rules file into the upload zone, or click Browse to select it from your local machine.
  3. Select Detections as your intended Type from the dropdown menu.
  4. Select the Destination that your detections apply to.
  5. Click Submit.

file submit

What Happens Next?

Once your file is successfully uploaded, Realm begins processing and translating your rules into the platform.

1. Translation Timeline

It takes up to 48 hours for your uploaded detections to be fully translated, parsed, and populated into your Realm Console.

2. Reviewing Rules in "Pending" Status

Once the translation timeline is complete, your rules will appear in the Exception Rules section of your console.

  • All newly ingested rules are automatically placed in a Pending state.
  • Action Required: You can review, modify, and fully edit these rules to ensure accuracy before moving them to Active.

activate rule

3. Log Optimization & Detection Integrity Report

To assist with your broader log optimization efforts, Realm generates a comprehensive Detection Integrity Report analyzing your rules against your environment.

  • Delivery Method: Currently, this report is delivered asynchronously via your dedicated Realm Account Team.
  • Reach out to your account representative after the 48-hour processing window to review your optimization insights and rule efficacy analytics.

Need Help?

If you encounter any issues uploading your files, or if your files exceed the 100MB limit, please contact Realm Support or reach out directly via your Account Team.