/** * Elasticsearch / OpenSearch export-plan emitter. * * Mirrors `lib/siem/elasticsearch.ts`: 24 stratified sub-windows, the same * per-bucket cap, a `range` query on `@timestamp`, `search_after` paging * sorted by `@timestamp` ascending, and `track_total_hits: false`. OpenSearch * speaks the same dialect on all of it, so one emitter serves both and the * only thing that changes is the label on the report. * * Two read-only endpoints: `_cat/indices` to resolve the index pattern into * concrete indices (so the report can attribute bytes per index), and * `_search` for the events. * * Request bodies are built with `jq -n`, never by pasting values into a JSON * string. The user's scope and filter reach the cluster as JSON values, so a * filter containing a quote is a filter, not a broken request. */ import { type SamplePlan, type SamplePlanOptions } from './_shared.js'; type Flavor = 'elasticsearch' | 'opensearch'; export declare function emitElasticsearchPlan(opts: SamplePlanOptions, flavor?: Flavor): SamplePlan; export {};