/** * CloudWatch Logs connector. * * Uses FilterLogEvents for scoped retrieval across one or more log groups. * Supports wildcard log-group patterns via DescribeLogGroups (`/aws/ecs/*`). * * Credential discovery: * - `env`: explicit AWS_* env vars present (AWS_ACCESS_KEY_ID + AWS_REGION, etc.) * - `ambient`: defaultProvider() resolves credentials from the chain * (instance metadata, ~/.aws/credentials, SSO cache, etc.) * - `none`: nothing resolvable * * Pagination: FilterLogEvents returns nextToken; we paginate until * targetEventCount reached, time exhausted, or the API says "no more". * * Rate limiting: AWS throttling exceptions are retried with exponential * backoff. Transient 5xx errors are retried up to 3× per request. */ import type { SiemConnector } from './index.js'; /** * Default stratified-sampling bucket count for CloudWatch pulls. * * Exported because the offline export-plan emitter * (`lib/siem/export-plan/cloudwatch.ts`) renders a shell script that must * draw the SAME sample this connector draws — same bucket count, same * per-bucket cap — or a fenced POC and a live POC over the same window * would report different pattern mixes for reasons that have nothing to do * with the logs. One constant, two callers. */ export declare const CLOUDWATCH_BUCKET_COUNT = 24; /** Per-request event ceiling CloudWatch's FilterLogEvents accepts. */ export declare const CLOUDWATCH_PAGE_LIMIT = 10000; export declare const cloudwatchConnector: SiemConnector;