/** * SIEM ← S3 connector recipes: how the customer wires Datadog or Splunk to * PULL 10x's offload output from their own S3 bucket. * * This is the destination/ingest side, the mirror of offload-recipes.ts (which * generates the forwarder->S3 side). log10x deliberately never pushes to a SIEM * — it lands data in the customer's bucket and the SIEM pulls — so "ship my * offload to Datadog/Splunk" is a customer-applied connector, not a vendor * re-ingest (which would collide with Datadog Rehydration billing, Splunk HEC * permissions, Elastic _bulk limits). * * Contracts are primary-source-verified (Datadog Forwarder Lambda; Splunk * Add-on for AWS, SQS-based S3 input) and matched to 10x's actual offload * output: uncompressed NDJSON (one event/line), Hive-partitioned keys * (dt=YYYYMMDD/hr=HH/node/file.txt), same-account customer bucket. * * KEY GOTCHA baked into every recipe: the offload bucket usually ALREADY has an * S3 ObjectCreated notification (the 10x indexer's SQS). S3 allows only ONE * notification config per overlapping prefix+suffix, so a second consumer must * be fanned out via SNS or EventBridge — never a second raw bucket notification. */ export type SiemTarget = 'datadog' | 'splunk'; export interface SiemConnectorParams { /** The offload bucket the SIEM should read. */ bucket: string; region: string; accountId: string; /** Offload prefix (where the NDJSON lands). Default "app/". */ prefix?: string; /** Existing Datadog Forwarder Lambda ARN, if one is already deployed. */ datadogForwarderArn?: string; /** Name for the SQS queue the Splunk input drains. Default derived. */ sqsQueueName?: string; /** Splunk sourcetype / index for the input. */ sourcetype?: string; splunkIndex?: string; } export interface SiemConnectorBlock { title: string; language: 'terraform' | 'ini' | 'json' | 'bash'; body: string; } export interface SiemConnectorRecipe { target: SiemTarget; summary: string; /** How the SIEM discovers new objects (the design fact that drives setup). */ discovery: string; /** Ordered, human-readable setup steps. */ steps: string[]; /** Paste-ready config / infra blocks. */ blocks: SiemConnectorBlock[]; /** The single biggest footgun for this offload bucket. */ notificationNote: string; /** Verified, honest caveats — what this path does NOT do. */ caveats: string[]; } export declare function siemS3ConnectorRecipe(target: SiemTarget, p: SiemConnectorParams): SiemConnectorRecipe;