/** * Per-hash SIEM fetch budget computation. * * The SIEM query budget (race timeout + maxPullMinutes) is tuned to the * requested scan window. A 1h probe can return in 2.5s; a 7d scan needs * more time because the SIEM must scan more index shards / log-group * partitions before finding a hit for a low-volume pattern. * * Piecewise constants (not sqrt) — simpler to reason about and tune * per-tier than a continuous formula. * * Single-sample budget (fetchSamplesByHashes, one event per hash): * <= 1h → 2500ms * <= 6h → 4000ms * <= 24h → 6000ms * <= 72h → 10000ms * > 72h → 15000ms (hard ceiling) * * Batch budget (fetchEventsByHashes, N events per hash) uses the same * tiers but always returns the batch ceiling (MIN_BATCH_MS floor) because * fetching 50-250 events per hash is inherently heavier than 1. */ /** Default single-sample budget (matches the historic hardcoded 2500ms). */ export declare const DEFAULT_PER_HASH_MS = 2500; /** Hard ceiling for single-sample and batch budgets (ms). */ export declare const MAX_PER_HASH_MS = 15000; /** * Compute the per-hash race-timeout budget (ms) for a single-sample fetch, * scaled to the requested SIEM scan window. * * If window is missing or unparseable, returns DEFAULT_PER_HASH_MS (2500ms) * so the fallback behaviour is identical to the pre-defect-12 constant. */ export declare function computePerHashBudgetMs(window: string | undefined): number; /** Default maxPullMinutes when window is missing/unparseable (historic value). */ export declare const DEFAULT_MAX_PULL_MINUTES = 0.25; /** * Compute a scaled maxPullMinutes for pullEvents, given the scan window. * Returns DEFAULT_MAX_PULL_MINUTES (0.25) if window is missing or unparseable. */ export declare function computeMaxPullMinutes(window: string | undefined): number;