SIEM Search Expressions
In this hands-on lab, you will learn the basics of using search expressions in a SIEM. You will practice creating a series of search expressions in the Wazuh SIEM.

Course Content
Upon completing this lab, you should be able to:
- Define "search expression".
 - List and describe common types of expression formats usable in common SIEMs.
 - List common DQL expression operators and their function.
 - Construct and run simple DQL search expressions from within Wazuh.
 - Construct and execute an appropriate search expression in Wazuh, given a natural language request.
 















