/** * Export-plan registry. * * Step 2 of the fenced POC: the server emits a shell script, the user reads * it, the user runs it OUTSIDE the container with their own credentials, and * it lands a log sample on disk. Nothing here contacts anything — the module * renders text. * * Adding a SIEM: * 1. Write an emitter under this directory that mirrors the connector's * query grammar and imports its bucket constants rather than retyping * them. * 2. Register it in `EMITTERS` below and add its id to `EXPORT_PLAN_SIEMS` * in `_shared.ts`. * 3. Add a golden file under `test/fixtures/export-plan/`. */ import { DEFAULT_TARGET_EVENT_COUNT, EXPORT_PLAN_FOLLOW_UPS, EXPORT_PLAN_SIEMS, type ExportPlanSiemId, type SamplePlan, type SamplePlanOptions } from './_shared.js'; export declare class UnsupportedExportSiemError extends Error { constructor(siem: string); } /** True when an export script exists for this SIEM id. */ export declare function hasExportPlan(siem: string): siem is ExportPlanSiemId; /** * Render the export script for one SIEM. * * The bucket draw happens here, once, so the returned script carries literal * timestamps. Two calls produce two different samples, which is the same * property the live connectors have and the reason a prospect re-running a * POC does not re-read the same slice of their logs. */ export declare function emitSamplePlan(opts: SamplePlanOptions): SamplePlan; export { DEFAULT_TARGET_EVENT_COUNT, EXPORT_PLAN_FOLLOW_UPS, EXPORT_PLAN_SIEMS, }; export type { ExportPlanSiemId, SamplePlan, SamplePlanOptions };