/** * log10x_poc_from_siem — async MCP tool pair. * * The submit tool kicks off the pull + analyze + render pipeline in the * background and returns a `snapshot_id`. The status tool reports progress * and returns the final markdown once done. * * This mirrors the retriever_query / retriever_query_status async shape so * callers can track a long-running pull without blocking the MCP loop. */ import { z } from 'zod'; import { type SiemConnector, type CredentialDiscovery, type SiemId as RegistrySiemId } from '../lib/siem/index.js'; import type { SiemId } from '../lib/siem/pricing.js'; import { renderPocReport, type RenderInput } from '../lib/poc-report-renderer.js'; import type { McpServer } from '@modelcontextprotocol/sdk/server/mcp.js'; declare const SIEM_ENUM: readonly ["cloudwatch", "datadog", "sumo", "gcp-logging", "elasticsearch", "azure-monitor", "splunk", "clickhouse"]; export declare const pocFromSiemSubmitSchema: { siem: z.ZodOptional>; window: z.ZodDefault; scope: z.ZodOptional; query: z.ZodOptional; target_event_count: z.ZodDefault; max_pull_minutes: z.ZodDefault; analyzer_cost_per_gb: z.ZodOptional; total_daily_gb: z.ZodOptional; total_monthly_gb: z.ZodOptional; total_annual_gb: z.ZodOptional; auto_detect_volume: z.ZodDefault; ai_prettify: z.ZodDefault; enrich_with_host_agent: z.ZodDefault; enrich_max_tokens: z.ZodDefault; environment: z.ZodOptional; target_percent_reduction: z.ZodOptional; exception_services: z.ZodOptional>; pin_services: z.ZodOptional>>; pin_patterns: z.ZodOptional>>; clickhouse_table: z.ZodOptional; clickhouse_timestamp_column: z.ZodOptional; clickhouse_message_column: z.ZodOptional; clickhouse_service_column: z.ZodOptional; clickhouse_severity_column: z.ZodOptional; }; export declare const pocFromSiemStatusSchema: { snapshot_id: z.ZodString; view: z.ZodDefault>; pattern: z.ZodOptional; top_n: z.ZodOptional; }; type Status = 'pulling' | 'analyzing' | 'rendering' | 'complete' | 'failed'; interface Snapshot { id: string; status: Status; progressPct: number; stepDetail: string; partialPatternsFound?: number; /** Live counters surfaced during the pull so status polling shows real work. */ partialEventsPulled?: number; partialBytesPulled?: number; /** * Saturation indicator computed across pull progress slices. Each * value is the number of distinct patterns newly observed in the * preceding ~100k events. When the trailing average drops below 2% * of the running pattern count for 3 consecutive slices, the * pipeline self-terminates the pull and proceeds to render — the * long tail has been covered. */ partialNewPatternsByChunk?: number[]; /** Reason the pull stopped: `target_reached`, `time_exhausted`, `saturation_reached`, `source_exhausted`. */ partialStopReason?: string; startedAt: string; startedAtMs: number; finishedAt?: string; reportMarkdown?: string; reportFilePath?: string; /** * The full RenderInput the report was built from. Stored so status * calls can render alternate views (`summary`, `yaml`, `configs`, * `top`, `pattern`) on the fly without re-running extraction. */ renderInput?: RenderInput; summary?: RenderInput extends unknown ? ReturnType['summary'] : never; error?: string; partialReportMarkdown?: string; retryHint?: string; /** * Host-agent enrichment result, computed once at the end of * runPipeline. Read by the status path when building the v2 * envelope so we don't re-call the host LLM on every status poll. */ hostAgentEnrichment?: import('../lib/poc-host-agent-enricher.js').AgentEnrichmentResult; /** * Customer-specified reduction target (0-100) carried from submit * through to the v2 envelope builder so the status path can emit a * feasibility verdict + commitment artifact stub. */ targetPercentReduction?: number; /** * Services pinned to action=pass on the envelope outputs. Same * lifecycle as targetPercentReduction. */ exceptionServices?: string[]; /** * Per-service action overrides (pin_services). Carried from submit * through to the v2 envelope builder. */ pinServices?: Record; /** * Per-pattern action overrides (pin_patterns). */ pinPatterns?: Record; /** * What this POC actually read. Carried so the completed envelope can offer * the fenced re-run with MATCHING arguments — same analyzer, same window, * same scope and filter — instead of handing the agent an empty form and * hoping it remembers the submit call it made twenty minutes ago. */ pull?: { siem: SiemId; window: string; scope?: string; query?: string; targetEventCount: number; }; } /** * Test-only seam, same convention as `_internals` in `lib/siem/datadog.ts`. * * The snapshot store is process-local and only ever populated by a real pull, * so without this there is no way to assert what a COMPLETE run puts in its * envelope short of holding real analyzer credentials in CI. Nothing in the * product reads it. */ export declare const _internals: { SNAPSHOTS: Map; }; export interface PocSubmitArgs { siem?: (typeof SIEM_ENUM)[number]; window: string; scope?: string; query?: string; target_event_count: number; max_pull_minutes: number; analyzer_cost_per_gb?: number; total_daily_gb?: number; total_monthly_gb?: number; total_annual_gb?: number; auto_detect_volume?: boolean; ai_prettify: boolean; enrich_with_host_agent?: boolean; enrich_max_tokens?: number; environment?: string; /** Customer-specified target reduction (0-100). Triggers feasibility + commitment artifact emission. */ target_percent_reduction?: number; /** Services pinned to action=pass on the envelope outputs. */ exception_services?: string[]; /** Service-level action overrides (map of service → action). */ pin_services?: Record; /** Per-pattern action overrides (map of pattern_hash → action). */ pin_patterns?: Record; clickhouse_table?: string; clickhouse_timestamp_column?: string; clickhouse_message_column?: string; clickhouse_service_column?: string; clickhouse_severity_column?: string; /** * Optional MCP server handle — wired by index.ts at registration time. * Used ONLY by the AI-prettify path (MCP sampling via createMessage). * When absent, prettify skips with a clear note in the report appendix; * the report still renders with raw identities. */ _mcpServer?: McpServer; } export declare function executePocSubmit(args: PocSubmitArgs): Promise; export interface PocStatusArgs { snapshot_id: string; view?: 'summary' | 'full' | 'yaml' | 'configs' | 'top' | 'pattern'; pattern?: string; top_n?: number; } export declare function executePocStatus(args: PocStatusArgs): Promise; export declare function runPipeline(connector: SiemConnector, snapshot: Snapshot, args: PocSubmitArgs): Promise; export declare function _resetSnapshots(): void; export declare function _getSnapshot(id: string): Snapshot | undefined; export type { SiemConnector, CredentialDiscovery, RegistrySiemId };