/**
* ClickHouse connector.
*
* Schema detection:
* 1. Probe `DESCRIBE TABLE
` to read columns
* 2. Match against OpenObserve schema (columns: _timestamp, log, stream)
* 3. Match against SigNoz schema (columns: timestamp, body, resources_string_key,
* resources_string_value, severity_text)
* 4. Otherwise require explicit schemaOverride to map columns
*
* `scope` is the database name; `query` is an SQL WHERE clause.
*/
import type { SiemConnector, SiemSchemaOverride } from './index.js';
type DetectedSchema = {
kind: 'openobserve';
mapping: ColumnMapping;
} | {
kind: 'signoz';
mapping: ColumnMapping;
} | {
kind: 'custom';
mapping: ColumnMapping;
} | {
kind: 'unknown';
columns: string[];
};
interface ColumnMapping {
timestamp: string;
message: string;
service?: string;
severity?: string;
}
export declare function detectSchema(columns: string[], override?: SiemSchemaOverride): Promise;
export declare const clickhouseConnector: SiemConnector;
export {};