/** * CloudWatch Logs export-plan emitter. * * Mirrors `lib/siem/cloudwatch.ts`: DescribeLogGroups to resolve scope, then * FilterLogEvents per (sub-window × log group) with the same 24-bucket * stratified sample and the same per-bucket cap. Both read-only. * * One file per log group (rolled into parts), so the report's sample- * composition table still says which log group each slice of bytes came * from — the question the prospect has to answer before the savings number * means anything. */ import { type SamplePlan, type SamplePlanOptions } from './_shared.js'; export declare function emitCloudwatchPlan(opts: SamplePlanOptions): SamplePlan;