LAYER 1 · AT THE NODETrigger, then windows
A low-power detector runs in the ground and sends triggers with buffered waveform windows up the fibre. The line does not stream raw waveforms, and that choice sets the power budget.
LAYER 2 · AT THE HEAD-ENDCoincidence, class, position
Triggers are correlated across nodes, classified against a library, and solved for position on confirmed events. A single-node trigger is a health event, not an alarm.
LAYER 3 · AT THE CONSOLETrack, confidence, history
A confirmed, classified, localized event becomes a track with its confidence and its history, and a cue proposal beside it. A person takes it or leaves it.
Multi-node coincidence is the first and best false-alarm filter, because a real source moves plausibly and shows up on its neighbours while a sensor fault and a patch of local noise do not. The classification library carries reject classes alongside target ones, and the reject list decides whether anyone trusts the fence: rain, thunder, traffic, trains, animals and frost action. That list is won with data from the site itself.
A fixed line in fixed ground is well placed to collect it. The head-end is designed to learn this site's daily and seasonal rhythm node by node, so that anomalous is measured against this line's history instead of a generic threshold, to grow the classification library with every labelled event, and to keep a per-node ledger of trigger-rate drift, sensitivity against calibration thumps and battery draw-down, so nodes are revisited on data rather than on failure.