All the use cases, raw logs, and PCAPs Echo uses are stored in a local SQLite database called usecases.db. LogRhythm maintains this database and keeps it under version control. The latest version is provided with each release of Echo. All changes to the master go through the LogRhythm Engineering and SE teams. As with the Knowledge Base, only validated, vetted, and tested use cases are added to the master and distributed.
Users can load their own use cases into their local copy of the use case DB, and export use cases from their local copy. These exported use cases can be shared with other users, who can import those use cases into their local use case databases. Exported use cases can be submitted to LogRhythm for evaluation and considered for inclusion in the master use case DB.