/** * log10x_investigate — single-call root-cause investigation. * * Orchestration tool. Takes a polymorphic starting point (raw log line, * pattern identity, service name, or the literal "environment") and * returns a complete markdown report by composing: * * 0. Environment selection * 1. Anchor resolution (pattern / service / env mode) * 2. Trajectory shape detection (acute vs drift vs flat) * 3. Acute-spike correlation with lag analysis (Phase 3) * — OR — * Drift slope-similarity cohort analysis (Phase 3-D) * 4. Causal chain construction (acute only) * 5. Confidence scoring * 6. Two-stage Retriever fallback (graceful degradation) * 7. Verification command generation * * Intelligence lives in the tool, not the model. Any MCP-aware client * should be able to call this one tool and get a coherent investigation. */ import { z } from 'zod'; import type { EnvConfig } from '../lib/environments.js'; import type { StructuredOutput } from '../lib/output-types.js'; export declare const investigateSchema: { starting_point: z.ZodString; window: z.ZodOptional; timeRange: z.ZodOptional; baseline_offset: z.ZodOptional; depth: z.ZodDefault>; environment: z.ZodOptional; use_bytes: z.ZodDefault; }; /** * Top-level call status. Agent branches on this before reading anything else. * - `success`: investigation produced a usable narrative. Read `findings` * and `human_summary`. Whether to ACT on the findings depends on * `threshold_basis` and the agent contract. * - `no_signal`: anchor resolved but no co-movers crossed the noise * floor. Stop searching. * - `insufficient_data`: anchor couldn't be resolved, window too short, * or backend returned too few buckets. Re-anchor or widen the window. * - `error`: structural failure. Read `data.error`. */ export type InvestigateStatus = 'success' | 'no_signal' | 'insufficient_data' | 'error'; /** * Threshold provenance. Calibration honesty: investigate's thresholds * (clean-chain confidence floor, acute noise floor, drift slope, etc.) * are hand-picked SPEC_DEFAULTS unless the operator points * LOG10X_THRESHOLDS_FILE at a calibrated config. Agents MUST NOT * auto-mitigate when threshold_basis === 'unvalidated_default'. */ export type ThresholdBasis = 'unvalidated_default' | 'config_file' | 'caller_override'; export interface ParsedReport { shape: string | null; mode: string | null; investigationId: string | null; /** Resolved anchor pattern name (from `**Anchor**: \`name\`` line). Null * when the rendered report didn't carry an anchor header (e.g., * pre-resolution failure path). Used by buildHumanSummary so the * no_signal prose can name the real pattern instead of falling back * to the literal hash from starting_point. */ anchorPattern: string | null; leadPattern: string | null; leadService: string | null; leadConfidence: number | null; leadLagSeconds: number | null; chainLength: number; coMoverCount: number; hasNoSignalMarker: boolean; } /** * Best-effort extraction of structured signals from the rendered * markdown. Used to populate the agent-facing envelope without * refactoring the rendering pipeline. Regex-fragile by design — if a * template changes, the agent gets `null` for that field and falls * back to reading `data.report_markdown`. */ export declare function parseReport(md: string): ParsedReport; export declare function detectThresholdBasis(): ThresholdBasis; export declare function buildHumanSummary(starting_point: string, window: string, status: InvestigateStatus, parsed: ParsedReport, thresholdBasis: ThresholdBasis): string; /** * Offload-status hint shape surfaced on the envelope. One entry per * pattern (by name) that the env-mode top-N or the acute-spike chain * reports as in the receiver's drop/offload cohort (routeState="drop"). Best-effort; * the field is absent on lookup failure. routeState="drop" does not distinguish * offload-to-S3 from hard-drop, so fetchability is conditional, not implied. */ export interface TopOffloadedPattern { pattern: string; service: string | null; tenx_hash: string; /** Null when the kept-cohort scan timed out — share math suppressed. */ dropped_share_pct_24h: number | null; last_seen_dropped_ts: number | null; /** True when the kept-cohort PromQL scan timed out on a heavy pattern. */ kept_timed_out?: boolean; } export declare function executeInvestigate(args: { starting_point: string; window?: string; timeRange?: string; baseline_offset?: string; depth: 'shallow' | 'normal' | 'deep'; environment?: string; use_bytes: boolean; effective_ingest_per_gb?: number; }, env: EnvConfig): Promise;