/** * log10x_overflow_contents — the contents view of the customer's S3 * offload bucket. * * The offload bucket is the OVERFLOW QUEUE, not a search target. The * customer wants to REVIEW what's accumulating, not query it. * * What this tool does: * - Queries `all_events_summaryBytes_total{routeState="drop"}` grouped * by (pattern_hash, service, k8s_container) over the requested * time window. * - Joins the result to the cap-CSV the MCP wrote (via * `log10x_configure_engine`) so ONLY patterns whose action is * `offload` surface. Patterns whose action is `drop` are NOT in S3 * and don't belong in the contents view; `compact` and `tier_down` * are routed in-engine / to the SIEM cheap tier and also aren't in * the offload bucket. * - Computes growth rate per pattern as the percent change between * the FIRST half and the SECOND half of the window (simple, * deterministic; matches the shape doc's * `growth_rate_pct_per_week` field when window=30d). * * What this tool does NOT do: * - Scan S3. The contents view is a TSDB query, not a bloom-index * scan — see metric_surface_owns_overflow_visibility.md. * `log10x_retriever_query` is the only tool that touches the * archive; this one points to it as the rehydration path. * - Estimate dollars. The whole point of offload is that overflow * bytes have negligible storage cost; the dollar number is * misleading if framed as "savings" without the SIEM-tier * comparison `log10x_savings` does. * * When no cap-CSV is fetchable: the tool degrades to "all dropped * bytes" with a caveat — the agent sees `cap_csv_status` and can warn * the user that the offload-vs-drop split is unverified. */ import { z } from 'zod'; import type { EnvConfig } from '../lib/environments.js'; import { type StructuredOutput } from '../lib/output-types.js'; export declare const overflowContentsSchema: { timeRange: z.ZodDefault>; service: z.ZodOptional; limit: z.ZodOptional>; environment: z.ZodOptional; view: z.ZodOptional>>; }; export declare function executeOverflowContents(args: { timeRange?: string; service?: string; limit?: number; view?: 'summary'; }, env: EnvConfig): Promise;