It would be nice if you could create custom alerts for the SIEM. Basically create a query and if something meets the criteria send a alert. A few things that you would probably want for this feature:
  1. I don't think these alerts should go to SOC. As otherwise the SOC might get overwhelmed by custom alerts.
  2. Allow the custom alert to have a threshold before activated. For example set a threshold of 50 failed logins on user bob2 before triggering.
  3. While the alerts should not go directly to the SOC it probably would be helpful if visible to the SOC if something does happen.