I would like to see the SIEM receive its own reporting management.
Example
from logs | where event.code == 4625
From previous 7-days
Email to blah@blah.com
It could be as simple as just a PDF with all the events in which you can click on the view to login then view the event.