/** * Semantic excerpt of one sample log line for the new `top_patterns` * card. Instead of left-to-right truncation (which buries the * discriminative content past the resource metadata envelope), we pull * the key=value pairs that distinguish ONE matched event from another: * - error / reason / exception * - endpoint / url / path / method * - status / status_code / http_status / duration * - retry / attempt * - the otelcol component triplet (id / kind / signal) as one line * * Everything else (resource UUIDs, service version, instance IDs) is * suppressed — it's the same on every event matching this hash, so it * doesn't help the Reader recognize the pattern. * * Input is the unwrapped log line (from `ParsedSiemEvent.logLine`) plus * the optional parsed JSON tail. Output is a list of lines to print, * one per discriminator surfaced. * * The header line (`timestamp\tlevel\tsource\tmessage`) is always * preserved when present — it carries the verb of the event and the * source location, both useful for recognition. */ export interface ExcerptLine { /** Tag identifying which kind of content this line carries * (`header` / `error` / `endpoint` / `otelcol` / etc.). Mostly * diagnostic; callers can ignore it. */ tag: string; /** The rendered line, already string-formatted. */ text: string; } /** * Build the semantic excerpt. If `logJson` is null (no parseable JSON * tail), we just return the header line and let the Reader read it * as-is. * * `maxLines` caps the returned list (default 6) so a wildly structured * event can't blow up the card body. */ export declare function semanticExcerpt(logLine: string, logJson: Record | null, maxLines?: number): ExcerptLine[];