I admit I do very little systems/network administration work, so maybe there's something I'm missing.
Also, you say I can query against such database. But does the monitoring
system allow me to query that database? I have no documentation for it.
Most of the time I can't easily fill events generated out of that back to the
database. And at last, current so-called "state of the art" monitoring systems
don't facilitate running custom queries, so I would need to write something
totally external just to run the query.
Graylog2 and Riemann go a little in this way, but they stopped way, way too
soon to be an answer to current state of monitoring systems.