Wazuh in the lab exists so you can see how an alert is born, not so you can pretend it is an enterprise platform.
Before you write a clever rule, answer:
- where the log comes from
- how it reaches the manager
- what survives the decoder
- when an alert fires
- what the analyst sees
- how to replay it or close it as FP
SIEM does not replace triage. The rule-review template is in Resources — an empty field means “do not enable”.