/** * Datadog Logs connector. * * Uses the Logs API `searchLogs` (v2) endpoint with cursor pagination. * `DD_SITE` (or `DATADOG_SITE`) routes between US/EU/… endpoints; we * rely on the SDK's built-in site configuration so US1/EU1/US3/US5/AP1 * all work without code changes. * * Credential discovery: `DD_API_KEY` + `DD_APP_KEY` (also accepts * `DATADOG_*` variants) — both are required by the Logs API. */ import type { SiemConnector } from './index.js'; /** * Stratified-sampling bucket count for Datadog pulls. Exported for the * offline export-plan emitter, which must draw the same sample this * connector draws. See CLOUDWATCH_BUCKET_COUNT. */ export declare const DATADOG_BUCKET_COUNT = 24; /** Page size per cursor step. Datadog's own ceiling on this endpoint is 5000. */ export declare const DATADOG_PAGE_LIMIT = 1000; /** * Pull a usable message body off a Datadog log event. * * The standard shape is `attributes.message` (string). Custom-format * ingests can populate `attributes.attributes.` instead, with * the original message buried under a customer-chosen key. Fall * through: * 1. attributes.message — happy path, ~95% of events. * 2. attributes.attributes.message — common custom-format aliasing. * 3. attributes.attributes.log / .body / .raw — vendor variants. * 4. JSON.stringify(attributes.attributes) — last resort, gives the * the 10x engine something to fingerprint instead of `undefined`. * * Returns null when every path is empty, so the caller can skip the * event and surface the count in metadata. The prior `?.message` * shortcut returned `undefined`, which then became the literal string * "undefined" after `events.join('\n')` in pattern-extraction and got * fingerprinted as a phantom pattern. */ declare function extractMessage(ev: unknown): string | null; export declare const datadogConnector: SiemConnector; /** Test-only surface; not part of the public connector API. */ export declare const _internals: { extractMessage: typeof extractMessage; }; export {};