/** * log10x_siem_connector — emit the SIEM <- S3 connector config (Datadog * Forwarder Lambda / Splunk Add-on SQS-based S3 input) for a log10x offload * bucket. The destination/ingest side of the offload story: log10x lands NDJSON * in the customer's bucket; this tells the customer exactly how to make their * SIEM pull it. See src/lib/siem-s3-connector.ts for the verified contracts. */ import { z } from 'zod'; import { type StructuredOutput } from '../lib/output-types.js'; export declare const siemConnectorSchema: { siem: z.ZodEnum<["datadog", "splunk", "both"]>; bucket: z.ZodString; region: z.ZodDefault; account_id: z.ZodString; prefix: z.ZodOptional; datadog_forwarder_arn: z.ZodOptional; sqs_queue_name: z.ZodOptional; sourcetype: z.ZodOptional; index: z.ZodOptional; }; export interface SiemConnectorArgs { siem: 'datadog' | 'splunk' | 'both'; bucket: string; region?: string; account_id: string; prefix?: string; datadog_forwarder_arn?: string; sqs_queue_name?: string; sourcetype?: string; index?: string; } export declare function executeSiemConnector(args: SiemConnectorArgs): Promise;