Most of those tools exist to check boxes. 80% of cyber stuff is bullshit or snake oil.
Yup. I spent some months working on a product in this space, and the most surprising takeaway I had was that there's a risk that by buying such a product, you're exposing yourself to legal problems - e.g. when a product tells you about some potential security issue, you can no longer claim ignorance. This apparently informs buying decisions, so product makers need to take it into account.
A good SIEM can search terabytes of logs quickly and aggregate interesting things like least common values. Good luck doing that with grep.
Which is great if you have terabytes of logs, but GP's point is that the majority don't have that problem. Simple solutions are, well, simpler.