/** * Disk caching for POC pipeline phases. * * The local POC pulls live events from a SIEM, runs them through the * templater, builds a v2 envelope. Each phase is independently * expensive — a 1h CloudWatch pull is 10-30s, a templater run on * 100k events is 30-90s. Iterating on envelope shape or downstream * enrichment shouldn't re-trigger either. * * Cache key is the tuple of (siem, scope, window, target_event_count, * query). Two phases: * * //events.jsonl — pulled SIEM events * //templater/templates.json — templater output * //templater/encoded.log * //templater/aggregated.csv * * Default cache root is /tmp/log10x-poc-cache; override with * LOG10X_POC_CACHE_DIR. Caches persist until manually cleared — the * caller invalidates by removing the directory or changing any * key-contributing arg. * * Never throws — every read/write degrades to "no cache" on error. */ export interface CacheKeyArgs { siem: string; scope?: string; window: string; target_event_count: number; query?: string; } export interface CacheEntry { key: string; dir: string; /** True when the cache dir existed before this call. */ preExisted: boolean; /** Seconds since the dir's mtime (only meaningful when preExisted). */ ageSeconds: number; } /** * Stable 16-char hex key over the user-visible cache-contributing * args. Excludes auth-style fields (analyzer_cost_per_gb) * that don't affect the events or engine output. */ export declare function computeCacheKey(args: CacheKeyArgs): string; export declare function getOrCreateCacheDir(key: string): CacheEntry; export declare function hasCachedEvents(dir: string): boolean; export declare function writeCachedEvents(dir: string, events: unknown[]): void; export declare function readCachedEvents(dir: string): unknown[]; export interface CachedTemplaterOutput { templatesJson: string; encodedLog: string; aggregatedCsv: string; } export declare function hasCachedTemplaterOutput(dir: string): boolean; export declare function readCachedTemplaterOutput(dir: string): CachedTemplaterOutput | null; export declare function writeCachedTemplaterOutput(dir: string, out: CachedTemplaterOutput): void; /** * Summarize what's cached at a given cache dir for telemetry in the * v2 envelope (so the report header can say "events: cache hit (47s * old) / templater: cache miss"). Never throws. */ export interface CacheStatus { key: string; dir: string; events_cached: boolean; events_age_seconds: number | null; templater_cached: boolean; templater_age_seconds: number | null; } export declare function inspectCache(key: string): CacheStatus;