/** * Field-variation analysis for `log10x_top_patterns`. * * Given N parsed events that match the same hash, count distinct values * per top-level field in the events' JSON tail. This answers the * Reader's core question for a pattern: "what does this hash actually * group, beyond just the tokenized name?" * * Three buckets: * - **varying** — 2 to <80% distinct values. These are real dimensions * the pattern groups over. Worth drilling for the Reader. * - **noise** — ≥80% distinct values relative to N. Per-event values * (timestamps, durations, request IDs); not actionable. * - **constant** — exactly one distinct value across N. Defines the * pattern's identity; same for every event. * * Nested objects (the otelcol `resource` block, for example) flatten * one level so `resource.service.instance.id` becomes a flat key the * Reader can read without descending into JSON in their head. */ import type { ParsedSiemEvent } from './siem/sample.js'; export interface FieldVariationEntry { /** Flat field name. */ field: string; /** Distinct values seen across the sample. */ distinct: number; /** True if distinct count is ≥80% of N — treat as continuous/noise. */ isNoise: boolean; /** First few distinct values, in insertion order from the underlying * Set. Lets the renderer show concrete examples so the Reader can * tell "17 distinct rejected_items" is `100, 250, 500…` (real * counts) vs `a8f3-, 9d2e-, …` (opaque IDs). Capped at 3 to keep * cards skim-able. */ sampleValues: string[]; } export interface FieldVariation { /** Number of events that contributed (had a parsed JSON tail). */ totalEvents: number; /** Fields with 2..(<80%) distinct values — drill candidates. */ varying: FieldVariationEntry[]; /** Fields with ≥80% distinct values — per-event noise. */ noise: FieldVariationEntry[]; /** Fields with exactly 1 distinct value — define the pattern's identity. */ constants: FieldVariationEntry[]; } /** * Compute field variation across a set of events. Caller is expected * to have pulled the events with `fetchEventsByHashes` so each event's * `logJson` is populated (when parseable). */ export declare function fieldVariation(events: ParsedSiemEvent[]): FieldVariation;