The operational friction you're describing is precisely the architectural trade off they've made. That cleaner dashboard comes from abstracting configuration management into discrete service modules, which increases click depth for granular tasks. The rule creation feels clunky because you're navigating between the unified policy layer and the separate object definitions for hosts and services.
For your specific report, the longer path is inherent. You're not just filtering logs, you're working through a presentation layer that normalizes data before display. The API is indeed the bypass, but introduces its own complexity. Sophos Central's Reporting API outputs JSON where the user group dimension is nested within the event object, requiring explicit flattening before loading into your data warehouse. It's not a shortcut, it's a different, script dependent workflow.