Data Pipeline

  • Unified event schema across Suricata and OpenCanary
  • Decision log: JSON lines with rule_id, confidence, action, expiry
  • Export hooks for SIEM / offline forensics