We're using splunk to monitor logs of our servers, but don't have all the servers added to splunk for one reason or another. As a stop gap, I've created a report that shows me all the errors in the event logs of my phi servers. I've imported that csv to splunk, which breaks it down into fields that I can work with and even create tickets from if need be.
I've also created a report that shows which vpn users are connected via wireless to their network, so when they call in complaining of slow vpn, the help desk can tell them to pound sand.