Question
A security team currently runs a nightly batch model to detect suspicious login patterns. New requirements call for alerting within minutes as events arrive, while still writing predictions to a governed Delta table. Which migration is most appropriate?