drop qradar offense export · parse magnitude + contributing events · runs locally
offense magnitude · source/dest ip · local export only
heuristic screener · vendor schema varies · not definitive proof