/** * Vendor-specific exclusion config snippets per pattern. Used by the * v2 envelope's `actions.forwarder_exclusion` and `actions.siem_exclusion` * fields. Each helper takes the pattern's identity + template and * returns a paste-ready config string for the target vendor. * * The original renderer (poc-report-renderer.ts) has per-vendor full- * report renderers that produce a config FILE; these helpers produce * a per-pattern fragment suitable for embedding in a structured field * the agent can quote. */ /** * Datadog log exclusion filter — JSON-shaped, paste-ready into the * Logs Configuration → Exclusion Filters surface. */ export declare function datadogExclusionForPattern(identity: string, _template: string): string; /** * Splunk props.conf nullQueue routing — drops events matching the * pattern's literal phrase at index time. */ export declare function splunkExclusionForPattern(identity: string, template: string): string; /** * CloudWatch Logs subscription filter (negated): keep everything NOT * matching the pattern's literal phrase. Drop-at-source isn't * supported by CloudWatch natively; this requires a Lambda forwarder * with the filter pattern applied. */ export declare function cloudwatchExclusionForPattern(identity: string, template: string): string; /** * Fluent-bit Lua filter that drops events matching the pattern's * literal phrase. Paste into the forwarder config. */ export declare function fluentBitForPattern(identity: string, template: string): string;