/** * ClickHouse connector. * * Schema detection: * 1. Probe `DESCRIBE TABLE ` to read columns * 2. Match against OpenObserve schema (columns: _timestamp, log, stream) * 3. Match against SigNoz schema (columns: timestamp, body, resources_string_key, * resources_string_value, severity_text) * 4. Otherwise require explicit schemaOverride to map columns * * `scope` is the database name; `query` is an SQL WHERE clause. */ import type { SiemConnector, SiemSchemaOverride } from './index.js'; type DetectedSchema = { kind: 'openobserve'; mapping: ColumnMapping; } | { kind: 'signoz'; mapping: ColumnMapping; } | { kind: 'custom'; mapping: ColumnMapping; } | { kind: 'unknown'; columns: string[]; }; interface ColumnMapping { timestamp: string; message: string; service?: string; severity?: string; } export declare function detectSchema(columns: string[], override?: SiemSchemaOverride): Promise; export declare const clickhouseConnector: SiemConnector; export {};