Have you read through the SIEM Foundation documentation?
There are references to correlation rules there for some basic concepts. I often take existing correlation rules and use them for a foundation, modifying the rule to suit my particular environment's needs or requirements. Try making some copies of existing rules, rename them, and modify the rule. Sit back and watch how it works and if you get the expected results. While it's not perfect, it will give you some experience with rules and seeing the effects of the variables you add/remove.