There should be a way to configure alerting for ingested firewall logs. We can connect the firewalls via syslog ingestion, but it feels like that data isn't being utilized to its fullest potential. There should be options to configure alerting based on activity. Some good prebuilt alerts would be common items like firewall admin creations, deletions, changes and similar activities that pose a high threat if the actions are not legitimate.