/** * log10x_preview_filter — L3b surface. * * Shows the list of patterns that would be affected by applying a given * enforcement mode to a service — BEFORE any action is taken. * * Output: * data.patterns[] — structured per-pattern array for agent consumption. * must_render_verbatim — fixed-width plain-text table (NOT a markdown table). * Columns: #, Descriptor (36 chars), Volume, %, * Service, Severity, First seen, Trend (sparkline). * must_ask_user — "Drill into a pattern (give number)", "Apply", * "Pick different mode". * forbidden_next_actions — apply tools locked until user commits. * * Side effect: writes the full data as CSV to * /tmp/log10x-preview--.csv * (overwrite-in-place each call). * * Data source routing: * - Reporter/Receiver/Retriever tier (TSDB available): top_patterns scoped * to service. * - Dev / no-TSDB tier: poc_from_siem path via log10x_poc_from_siem. * Customer sees the same output shape either way. * * routes_to drill: log10x_pattern_detail with the selected tenx_hash. */ import { z } from 'zod'; import { type StructuredOutput } from '../lib/output-types.js'; import { type ExplainMode } from './explain-mode.js'; export declare const previewFilterSchema: { service: z.ZodString; mode: z.ZodEnum<["compact", "offload", "tier_down", "sample", "drop", "observe_only"]>; top_n: z.ZodDefault; environment: z.ZodOptional; }; export interface PreviewPatternRow { rank: number; /** Descriptor truncated to 36 chars for table display. */ descriptor: string; /** Full descriptor (un-truncated) for agent use. */ descriptor_full: string; tenx_hash: string; bytes_per_month: number; percent_of_service: number; service: string; severity: string; /** Human-readable relative age, e.g. "3 days ago". Null when unknown. */ first_seen_relative: string | null; /** Raw trend data (bytes/sec) for sparkline rendering. */ trend_data: number[]; /** 8-char sparkline string. */ trend_sparkline: string; } export interface PreviewFilterEnvelope { service: string; mode: ExplainMode; patterns: PreviewPatternRow[]; total_service_bytes_per_month: number; must_render_verbatim: string; must_ask_user: { question: string; options: string[]; }; forbidden_next_actions: string[]; csv_path: string | null; data_source: 'tsdb' | 'poc_siem'; /** * Pattern-universe count (all distinct patterns with nonzero bytes in the 30d * window, not just top_n shown). Null when the TSDB query failed or not available. */ pattern_count_total: number | null; /** * Provenance of the bytes data — allows an agent to explain why two tools * show different numbers when called with different windows or cohorts. */ bytes_source: { metric: string; observation_window: string; cohort: 'kept'; scope_filter: string; } | null; /** * Summing the per-row .percent_of_service column drifts vs the * byte-derived ratio (e.g. 71.92 vs 72.43%) because per-row values are * pre-rounded to 2dp before the table renders. This field is the * authoritative byte-derived share so neither agents nor humans need to * sum rounded column values. Computed as: * round(shown_bytes / total_service_bytes_per_month * 100, 2) * Null when total_service_bytes_per_month is zero. */ shown_share_of_service_pct: number | null; } export declare function executePreviewFilter(args: { service: string; mode: ExplainMode; top_n?: number; environment?: string; }): Promise;