The paper’s significant research contribution is the proposal of DataLex, an offline, agentic, evidence-grounded Graph-RAG framework for SIEM log analysis. Its key novelty is integrating query-intent routing (alert vs. normal telemetry), graph-based evidence retrieval, TOON-based evidence compression, hallucination/grounding validation, and sandbox-assisted triage into a unified privacy-preserving architecture for investigating both known and potentially unknown threats. The paper also establishes an empirical baseline using 500 manually labeled responses, providing a foundation for future controlled evaluation of the proposed components.
