drop cisco stealthwatch flow export · parse flows + behavior · runs locally
netflow · behavior alarms · local export only
heuristic screener · vendor schema varies · not definitive proof