drop palo alto traffic log export · parse app-id + rule + session end reason · runs locally
drop palo alto traffic log export · local only
heuristic screener · vendor schema varies · not definitive proof