/** * Per-pattern `first_seen` discovery. * * For each of the top-N hashes, scan the engine's metric backwards in * time to find the earliest non-zero data point. That's the moment the * engine started observing the pattern — a load-bearing signal for the * Reader's "is this new or stable?" question. * * Implementation: a single batched PromQL range query per hash, covering * 30 days, at 1-hour step. Returns the earliest timestamp where the * metric was non-zero. Costs one round-trip per hash; in parallel. * * Formatting follows the locked rule: * < 60 min → "47m ago" * 60 min – 48h → "21h ago" * ≥ 48h → "7d ago" */ import type { EnvConfig } from './environments.js'; export interface FirstSeenResult { /** Seconds since the earliest non-zero timestamp. `null` if no data found. */ ageSeconds: number | null; /** Unix-seconds timestamp of the first event, if found. */ firstSeenUnix: number | null; } /** * Format an age (in seconds) per the locked time-bucket rule. * Returns "(unknown)" if `ageSeconds` is null. */ export declare function fmtAge(ageSeconds: number | null): string; /** * Find `first_seen` for one hash. Returns `{ageSeconds: null}` on * any failure (network, malformed response, no series) — never throws, * so callers can safely await N of these in parallel without one * failure poisoning the whole batch. */ export declare function fetchFirstSeen(env: EnvConfig, hash: string, metric?: string, lookbackSeconds?: number): Promise; /** * Batched parallel lookup — one Prom query per hash. The returned map * is keyed by hash. Missing entries (failures, no data) are simply * absent from the map; callers should treat absence as "(unknown)". */ export declare function fetchFirstSeenBatch(env: EnvConfig, hashes: string[], metric?: string, lookbackSeconds?: number): Promise>;