drop fortigate traffic log export · parse policy id + utm refs + action · runs locally
drop fortigate traffic log export · local only
heuristic screener · vendor schema varies · not definitive proof