export interface HashSample { vendor: string; displayName: string; /** Single truncated line, ready to print. */ line: string; } /** Pull the real log payload out of one event, unwrapping the * transport envelope. SIEM events commonly arrive as the * fluentd/docker shape `{"stream":..,"log":"","docker":..}` * (or a JSON string of it). The `.log`/`.message` field is the actual * log; the wrapper is transport metadata. Unwrapping is more faithful * to "what is this pattern", not less. One level only, defensive. */ export declare function oneLine(ev: unknown, max?: number): string; /** * Resolve the SIEM ONCE, then pull one real event per hash in * parallel. For the top_patterns list: a verbatim sample is the * readable identity of a pattern (the tokenized name degenerates to * field-soup for JSON logs), and it is ground truth, not fabrication. * * Zero-egress consistent: the events + tenx_hash are already in the * user's own SIEM; the agent reads them with the user's creds. No new * data plane, no bucket, no extra forwarder reach. Best-effort and * silent: no SIEM resolved / a hash with no hit / any error -> that * hash is simply absent from the returned map. * * Each hash is bounded by its OWN timeout, not an all-or-nothing batch * timeout. A hash with no events (e.g. a pattern the forwarder drops) * makes the SIEM scan the whole window and is the slowest possible * query; with a batch-level race that one query would sink every other * sample (observed: run-to-run flicker between all samples and none). * Per-hash bounding means a slow/empty hash costs only its own row. * The probe window scales with the requested scan window (short for 1h, * longer for 7d/30d) via computePerHashBudgetMs. See sample-budget.ts * for the piecewise tiers. */ export interface HashSpec { hash: string; /** Constrain the sample to this severity so the example matches the * row it illustrates (a pattern hash is severity-agnostic; without * this an ERROR-tagged row can show an INFO sample, contradicting * its own cut-risk tag). */ severity?: string; service?: string; } export declare function fetchSamplesByHashes(specs: Array, opts?: { scope?: string; window?: string; }): Promise>; /** * Parsed SIEM event used by field-variation analysis. The Python prototype * does this client-side after pulling 250 events per hash via the AWS CLI; * the TS port does it via the same connector that `fetchSamplesByHashes` * uses, so it shares the SIEM auth / scope / retry plumbing. */ export interface ParsedSiemEvent { /** Original SIEM event (whatever the connector returned). */ raw: unknown; /** The unwrapped log line text — same logic as oneLine but un-truncated. */ logLine: string; /** If the log line has a JSON object tail (otelcol envelopes, * structured logs), the parsed object. `null` for plaintext lines * or unparseable bodies (e.g. multi-line JSON `{` openers). */ logJson: Record | null; /** Kubernetes metadata pulled from the transport envelope, if present. */ k8s?: { container?: string; pod?: string; namespace?: string; }; /** Unix-ms timestamp from the SIEM event, if extractable. */ timestampMs?: number; } /** * Pull N events per hash, parsed. Used by field-variation analysis in * `top_patterns` to compute distinct-values-per-field across the events * that match a pattern's hash. Same SIEM auth + scope + per-hash timeout * as `fetchSamplesByHashes`, just returning the underlying events * (parsed) instead of a single line. * * Per-hash timeout is wider than the single-sample case (5s vs 2.5s) * because 250 events is a heavier SIEM query than 1. */ /** Per-hash timeout for the parsed-events batch fetch is computed from * opts.window via computePerHashBudgetMs (see sample-budget.ts). Wider * than the single-sample case because 50-250 events is a heavier SIEM * query; the budget is floored at 15000ms (the batch ceiling) for any * window >= 72h. */ export declare function fetchEventsByHashes(specs: Array, opts?: { scope?: string; window?: string; perHash?: number; }): Promise>; export declare function fetchOneSampleByHash(opts: { hash: string; service?: string; severity?: string; /** SIEM scope (CloudWatch log group, ES index, Splunk index). */ scope?: string; /** Lookback window for the probe. Default 6h. */ window?: string; }): Promise;