drop elastic security alert export · parse rule + host + severity · runs locally
drop elastic security alert export · local only
heuristic screener · vendor schema varies · not definitive proof