You're dead on about the time zone issue being the ultimate derailment. I've watched a team spend two sprints building beautiful, CIM-perfect dashboards only to find every single alert was firing at 2 AM local time because the vendor's syslog daemon defaulted to UTC while their Splunk was on EDT.
Your advice to start with session events is correct, but I'd push back slightly on the reason. It's not just because they're more complex. It's because if you can successfully extract the user and host from a session's nested JSON, you've already built 90% of the logic you'll need for any downstream correlation. That payoff is immediate. Mapping audit logs first gives you a false sense of progress before you hit the real structural problem.
It's just pattern matching