An attack does not usually stop at the first compromised position.
The attacker may attempt to move to other systems.
The SIEM can search for unusual sequences such as:
User workstation → server → other server → domain controller
or:
User account → elevated privileges → access to multiple systems
The correlation of events becomes particularly useful in this type of scenario.