/** * Shared helper: resolve a pattern's authoritative tenx_hash from the 10x metrics. * * The local tenxHash(canonicalPattern) hashes the snake_case pattern NAME — * but the engine's emitted tenx_hash (the value present in both Prometheus AND * the 10x-forwarded SIEM events) is PatternHashEncoder.encode(), a different input. They never match, so a hash-probe * built from the local hash silently falls back to fuzzy phrase-match. * * Resolving the hash from the metrics label (same value the forwarder writes to * the SIEM) is what makes the exact-hash cross-pillar probe actually hit. * Returns undefined when the metrics don't carry the pattern (caller falls back * to the local hash, then to phrase tokens). */ import type { EnvConfig } from './environments.js'; export declare function resolvePatternHashFromMetrics(env: EnvConfig, canonicalPattern: string): Promise; /** * Result of {@link resolvePatternRefInMetrics}. * - `exists`: true when the metrics backend carries this pattern over the * probed window. `null` when the probe could not be issued (no env, RPC * failure, etc.) — caller distinguishes "not checked" from "checked, * absent". * - `hash`: the canonical tenx_hash when known. Echoed back when the * caller passed a hash; resolved from `LABELS.pattern` when caller * passed a name. * - `name`: the canonical Symbol Message name when known. Resolved from * `LABELS.hash` when caller passed a hash; echoed back when caller * passed a name. May be `null` even when `exists=true` if the metrics * row carries the opposite-side label only (rare). * - `ref_kind`: which side the input shape matched. `hash` when input * matched `PATTERN_HASH_REGEX`, else `name`. */ export interface PatternRefResolution { exists: boolean | null; hash?: string; name?: string; ref_kind: 'hash' | 'name'; } /** * Canonical "does this pattern exist in the metrics backend" probe. * * Mirrors the per-tool resolution paths used by `pattern_examples`, * `pattern_detail`, and `event_lookup` — same metric (`all_events_summaryBytes_total`), * same labels (`LABELS.hash` when input is hash-shaped, `LABELS.pattern` * otherwise), same env scoping (`resolveMetricsEnv`). Use this instead of * a bespoke probe whenever a tool only needs to confirm pattern existence * by either form (hash OR name) the user pasted in. * * Window is fixed at 24h to match the resolution path the other tools use. * Callers needing a wider window should call the lower-level helpers * directly. * * Behavior: * - Hash-shaped input (`PATTERN_HASH_REGEX`): queries by `LABELS.hash`, * returns the dominant `LABELS.pattern` value as `name` if any row hits. * - Name-shaped input: queries via `resolvePatternHashFromMetrics` * (exact-match then prefix fallback), returns the dominant * `LABELS.hash` value as `hash` if any row hits. * - Network / parse failures collapse to `exists: null` (not checked), * so callers can disclose "could not verify" rather than "absent". */ export declare function resolvePatternRefInMetrics(env: EnvConfig, ref: string): Promise;