/** * Parsers for the Log10x dev CLI's output files. * * The CLI (and the paste Lambda that wraps it) produces four files: * - templates.json NDJSON, one template per line * - encoded.log per-event lines: ~templateHash,val1,val2,... * - aggregated.csv per-pattern statistics (count, bytes, severity, ...) * - decoded.log losslessly reconstructed events (ignored) * * This module parses those strings into in-memory structures the rest of * Defensive on format: some CLI versions emit slightly different column * names, so lookup is by header name rather than index. */ export interface Template { templateHash: string; /** Human-readable template body with `$` marking variable slots. */ template: string; /** Optional: structured slot list. Present in newer CLI versions. */ variableSlots?: VariableSlot[]; /** Optional: static tokens flanking the slots. */ staticTokens?: string[]; /** Optional: explicit symbolMessage field-set string. */ symbolMessage?: string; /** Optional: severity reported by the CLI at template discovery. */ severity?: string; /** Optional: whether this is a group template (regex-joined variants). */ isGroup?: boolean; } export interface VariableSlot { position: number; type?: string; /** The static text immediately before this slot — used for semantic naming. */ precedingToken?: string; /** Name assigned by the CLI (if any) — typically only for structured logs. */ name?: string; } export interface EncodedEvent { templateHash: string; /** Variable values in slot order. */ values: string[]; /** * UTF-8 byte length of the `~hash,val1,val2,...\n` line as it would * ship to a compaction-aware SIEM. Optional for back-compat with older * parser callers. Includes the trailing newline so the sum matches the * on-wire payload. */ lineBytes?: number; /** * Reporter-tier symbol-lookup name (`message_pattern`) emitted by the * engine via `apps/mcp/stdout`'s `pattern=` anchor. Present only on * engine builds that include the anchored encoded layout; undefined * otherwise. */ symbolMessage?: string; /** * Engine-emitted xxHash64 (base64url, 11 chars) of `symbolMessage`, * carried on the `patternHash=` anchor of the encoded line. Same key * that the engine writes into the `tenx_hash` field of the summary * row, so it joins the encoded event to its aggregated summary * deterministically. */ tenxHash?: string; } export interface AggregatedRow { /** Pattern identifier — either templateHash or symbolMessage depending on CLI version. */ pattern: string; count: number; totalBytes: number; severity?: string; /** Raw row by header name — anything the specific CLI version emitted. */ raw: Record; } /** Parse NDJSON `templates.json` content into a hash-keyed map. */ export declare function parseTemplates(text: string): Map; /** * Parse encoded-event lines into per-event records. * * Two layouts are accepted (auto-detected per line): * * 1. **Anchored (apps/mcp current)** — caller already stripped the * `encoded=,` prefix in the demux, so what arrives here is: * * ~,,,…,pattern=,,patternHash=, * * The `pattern=` and `patternHash=` literals act as section * anchors, carrying the engine-emitted Reporter-tier name and * the matching xxHash64 per event. * * 2. **Legacy** — older engines / configs without the anchors: * * ~,,,… * * No symbolMessage / tenxHash on the EncodedEvent. * * Commas inside variable values are escaped as `\,`. Leading `~` on the * hash is the templater's marker; templates.json stores the hash without * it, so the leading `~` is normalized away here. */ export declare function parseEncoded(text: string): EncodedEvent[]; /** * Parse `aggregated.csv` into rows. * * Header names vary across CLI versions. Common column names: * pattern | templateHash | symbolMessage → identity * count | events → event count * bytes | total_bytes | totalBytes → total bytes * severity | severityLevel → dominant severity */ export declare function parseAggregated(text: string): AggregatedRow[];