Jevops: SRE log triage with Jev
Jev triages streaming logs into page, digest or resolve, cutting alert noise and paging humans only for high-confidence incidents. About $1–3 for 1M events a month.
# Jevops
SRE log tool built on **TypeSafe Jev** (typed decision model) with Elasticsearch, Logstash, Kibana, and Grafana integration — two coexisting approaches:
- **Mode A — real-time triage:** streams logs and decides page / digest / resolve (see below).
- **Mode B — investigative query:** answers *"what's important from 8am to now?"* by hierarchically drilling chunks of logs with Jev, then having an LLM explain the exact lines with citations and tool calls (`docs/hierarchical-query.md`).
Jev answers typed questions against a state (`choice` probabilities, `score` levels, `noul` 0–1 likelihoods) with calibrated confidence, ~70–500 ms, $0.042/M input tokens (output free). Jevops turns that into pages, digests, and resolved incidents instead of log-sprawl — or into a cited timeline when you ask a question.
```
┌──────────────┐ HTTP /ingest
app logs ──► Logstash├─► Elasticsearch ──► poll-es ──┐
(tcp :5000) └─► Jevops intake ───────────────┤
▼
prefilter (free) ──► burst rank (1 Jev call / window)
▼
triage fan-out (severity, category, urgency, needs_human,
novelty, recovery — all parallel)
▼
policy (confidence floor, cooldown, composite score)
├─► page ──► PagerDuty / Slack / webhook
├─► resolve ──► PagerDuty (dedup_key)
└─► digest ──► SQLite + Elasticsearch ◄── Grafana dashboard
```
## Why Jev here
- **Burst ranking:** up to 255 log lines in one request (`choice` over line IDs + `page_worthy` `nou