drop zeek conn.log · parse session metadata + duration anomalies · runs locally
conn.log tsv · conn_state · orig/resp bytes · local only
heuristic screener · vendor schema varies · not definitive proof