drop splunk search csv / json export · parse + pivot indexed events · runs locally
_raw · sourcetype · index · local export only
heuristic screener · vendor schema varies · not definitive proof