SIEM Search Expressions
In this hands-on lab, you will learn the basics of using search expressions in a SIEM. You will practice creating a series of search expressions in the Wazuh SIEM.

Course Content
Upon completing this lab, you should be able to:
- Define "search expression".
- List and describe common types of expression formats usable in common SIEMs.
- List common DQL expression operators and their function.
- Construct and run simple DQL search expressions from within Wazuh.
- Construct and execute an appropriate search expression in Wazuh, given a natural language request.















