/** * log10x_pattern_examples — return recent live events for a pattern with * template-extracted slot values per match. * * Orchestration primitive, not user-callable in practice. Intended to be * called by `log10x_investigate` (or another orchestrator) after a metric * tier identification when the chain needs event evidence to form a * hypothesis. * * Design contract: * - Inputs: Symbol Message (pattern name) OR pasted log line. * - Bounded to 24h window, log analyzer retention. * - For the offloaded cohort of a pattern (events the Receiver routed to * the overflow bucket) use log10x_retriever_query. * - Mechanism: SIEM phrase-search probe, group by template, content-token * shape-match to discriminate, top 3 buckets by event count. * - Honest output: per-bucket template labels, recall counts, parseFailed * markers when slot extraction fails per event. * - Multi-line group templates: head-line-only with explicit warning, * detected via input_line_count vs encoded.log_row_count delta. */ import { z } from 'zod'; import type { EnvConfig } from '../lib/environments.js'; import type { SiemId } from '../lib/siem/pricing.js'; export declare const patternExamplesSchema: { pattern: z.ZodOptional; pattern_hash: z.ZodOptional; vendor: z.ZodOptional>; service: z.ZodOptional; severity: z.ZodOptional; timeRange: z.ZodDefault>; limit: z.ZodDefault; scope: z.ZodOptional; slot_filter: z.ZodOptional>; view: z.ZodDefault>; bucket_id: z.ZodOptional; environment: z.ZodOptional; }; interface PatternExamplesArgs { pattern?: string; pattern_hash?: string; vendor?: 'splunk' | 'datadog' | 'elasticsearch' | 'cloudwatch'; service?: string; severity?: string; timeRange?: string; limit?: number; scope?: string; slot_filter?: { name: string; value: string; }; view?: 'summary' | 'detail'; bucket_id?: string; environment?: string; } export declare function executePatternExamples(rawArgs: PatternExamplesArgs, env: EnvConfig): Promise; /** Build a vendor-specific phrase-AND query from the pattern tokens. */ declare function buildVendorQuery(vendor: SiemId, tokens: string[], service?: string, severity?: string): string; /** * Extract content-only alphanumeric tokens from a template body. * * Strips JSON envelope keys via the same field-priority list coerceToLine * uses (`.log`, `.message`, `attributes.message`, `_raw`). When the body * is bare (no envelope), uses it directly. Tokenizes on non-alphanumeric * runs ≥ 2 chars, deduped, matches the 10x engine's symbol tokenization. */ declare function contentTokens(templateBody: string): Set; /** Compute Jaccard similarity between two token sets. Returns 0..1. */ declare function jaccardSimilarity(a: Set, b: Set): number; export declare const __testables: { buildVendorQuery: typeof buildVendorQuery; contentTokens: typeof contentTokens; jaccardSimilarity: typeof jaccardSimilarity; }; export {};