/** * log10x_retriever_query reads the offloaded cohort from the customer-owned S3 overflow bucket. * * Call when an agent needs the events the Receiver held back from the SIEM for a * pattern (the offload action) and routed to S3. Surfaces the down-tiered or * dropped cohort the SIEM never received, scoped by a Bloom-filter search * expression or a Reporter-named pattern. Not a mirror of what the SIEM ingested. * * Engine contract: POST returns a queryId; results land in S3 as JSONL files * under {bucket}/tenx/{target}/qr/{queryId}/. The client polls the marker * prefix for stability, then reads and merges the JSONL result files. * * Requires __SAVE_LOG10X_RETRIEVER_URL__ and __SAVE_LOG10X_RETRIEVER_BUCKET__ to be set. Falls * back gracefully with a "not configured" message otherwise. * * SQS fallback: when the HTTP POST to the query-handler URL fails with a * transport-level error (ENOTFOUND, ECONNREFUSED, ETIMEDOUT — typical when the * helm probe resolved a ClusterIP address unreachable from outside the cluster), * the tool automatically retries via the Quarkus ingress queue. Requires: * - LOG10X_RETRIEVER_QUERY_QUEUE_URL — the Quarkus ingress queue URL * (same as TENX_QUARKUS_QUERY_QUEUE_URL in the retriever pod env) * - sqs:SendMessage IAM permission on the queue for the MCP process's credentials * Response delivery is identical regardless of transport — results land in S3 * under the same qr/{queryId}/ prefix. The transport used is recorded in * data.source_disclosure.transport ("http" | "sqs"). */ import { z } from 'zod'; import type { EnvConfig } from '../lib/environments.js'; import { type StructuredOutput } from '../lib/output-types.js'; export declare const retrieverQuerySchema: { pattern: z.ZodOptional; pattern_hash: z.ZodOptional; search: z.ZodOptional; from: z.ZodString; to: z.ZodDefault; filters: z.ZodOptional>; target: z.ZodOptional; result_target: z.ZodOptional; limit: z.ZodDefault; format: z.ZodDefault>; bucket_size: z.ZodDefault; environment: z.ZodOptional; view: z.ZodOptional>>; debug: z.ZodOptional; }; /** * Marker prefix for the unscoped-query error. Classified as `schema_invalid` * (caller input), not a backend fault, so it is not retried. */ export declare const UNSCOPED_QUERY_PREFIX = "Unscoped query:"; /** * Reject a query that carries no Bloom scope, before anything is dispatched. * * The engine's IndexQueryWriter rejects a blank search outright: * * could not launch pipeline: 'run' / search cannot be blank * error initializing pipeline unit #7: 'streamOutput(IndexQueryWriter)' * * That failure lands ~12s in, before any worker runs, so no _DONE marker is * written. The caller then waits out the full marker timeout (380s observed) and * gets NO_MARKER with a diagnostic blaming a stale S3 index and the index-inducer * CronJob: wrong subsystem, six minutes late, and indistinguishable from a * genuinely empty archive to anyone without CloudWatch access. * * Exported so the invariant is testable without a backend. */ export declare function assertScopedQuery(args: { search?: string; pattern?: string; pattern_hash?: string; }): void; export declare function executeRetrieverQuery(args: { pattern?: string; pattern_hash?: string; search?: string; from: string; to: string; filters?: string[]; target?: string; result_target?: string; limit?: number; format?: 'events' | 'count' | 'aggregated' | 'ephemeral_series'; bucket_size?: string; environment?: string; view?: 'summary'; debug?: boolean; }, env: EnvConfig): Promise; /** * Three-sentence plain-prose distillation of a successful retriever_query * run. No markdown syntax, no dollar figures. Mirrors the canonical * buildHumanSummary pattern in src/tools/find-skew.ts:216. */ export declare function buildRetrieverQueryHumanSummary(s: { eventsMatched: number; eventsReturned: number; from: string; to: string; target: string; truncated: boolean; partialResults: boolean; completenessBasis?: 'marker_count_confirmed' | 'quiet_window_inferred'; pattern?: string; search?: string; wallTimeMs: number; offloadedHashCount: number; zeroReason?: string; /** queryId of the completed query — used to surface the dispatcher-failure * diagnostic when scanned=0 + submittedTasks>0. */ queryId?: string; /** Scan/dispatch stats from the _DONE.json equivalent (diagnostics object). */ diagnosticsScanned?: number; diagnosticsSubmittedTasks?: number; /** Part A: eventsMatched came from engine summaries (excludes dropped). */ countFromSummaries?: boolean; /** Part A: the preview/return is a sampled subset (download capped). */ sampledPreview?: boolean; }): string; export declare function retrieverNotConfiguredMessage(): string;