SIEM Detection and Alerting
In this hands-on lab, you will learn the basics of SIEM-based detection and alerting. You will practice using the Wazuh SIEM to create, modify, and test custom rules and alerts.

Course Content
Upon completing this lab, you should be able to:
- Define and describe the difference between an alert from source instrumentation and a SIEM-created alert/rule.
- Create a SIEM-based detection rule.
- Modify a SIEM-based detection rule.
- Test a SIEM-based detection rule to verify that it triggers.















