drop logrhythm case export · parse evidence items + analyst actions · runs locally
case evidence · analyst actions · alarms · local only
heuristic screener · vendor schema varies · not definitive proof