---
title: "Cost options"
description: "Outcome-first action menu: presents the 6 enforcement modes led by the keep-everything levers (compact / offload / tier_down), then the lossy opt-ins (sample / drop), then observe_only, gated by detected tier."
icon: material/format-list-checks
---

Called after the user picks option 1 from [log10x_start](start.md). Returns the menu of 6 enforcement modes, one line each: what happens to the events, and which layer enforces it.

Which modes appear depends on tier and destination. All 6 at Receiver tier, 2 at Reporter-only or Dev tier. Compact appears on Splunk and self-hosted Elasticsearch only, the destinations that read the compact form back at search time.

Three compliance levers (same shape as log10x_start):

- **must_render_verbatim**: pre-rendered markdown surfaced as-is
- **must_ask_user**: numbered question the agent must ask before routing
- **forbidden_next_actions**: tools blocked until the user picks

## :material-code-braces: Example

!!! tenx-ask "You"

    what are my options?

!!! tenx-answer "Log10x"

    ### How do you want to handle the cost?

    **SIEM detected: `splunk`.**

    Pick a mode:
      1. **drop**: stop events at the forwarder. Nothing reaches the SIEM.
      2. **sample**: keep 1 in N events. Trends stay valid.
      3. **compact**: minify events losslessly (Splunk, self-hosted Elasticsearch). All events still land in the SIEM.
      4. **tier_down**: SIEM stores events at a cheaper storage tier.
        _(not available: tier_down maps to billing reductions only on Datadog/CloudWatch/Azure Monitor. Detected SIEM: splunk.)_
      5. **offload**: events route to your S3 bucket instead of the SIEM.
      6. **observe_only**: 10x marks patterns in metrics; nothing is dropped.

    _(Pick a number. After you pick, I'll run the savings estimate.)_

## :material-check-decagram-outline: Prerequisites

Requires Receiver tier for modes 1–5. Mode 6 (observe_only) works at all tiers. See [log10x_start](start.md) for tier detection.

Dollar figures downstream of this menu use each destination's published per-GB price where there is one, and a modeled rate where there is not.

## :material-code-json: Schema and samples

??? tenx-input-schema "Input schema"

    Agent-facing JSON Schema (the canonical shape the MCP server publishes via `tools/list`):

    ```json
    {
      "type": "object",
      "properties": {
        "target_percent": {
          "type": "number",
          "minimum": 1,
          "maximum": 95,
          "description": "% reduction goal carried from log10x_start pick, pre-filled when the user stated a target."
        },
        "monthly_volume_gb": {
          "type": "number",
          "exclusiveMinimum": 0,
          "description": "What-if volume lens, forwarded into the log10x_estimate_savings call this menu routes to. cost_options itself emits no scaled magnitudes; it only passes monthly_volume_gb through so the downstream projection inherits it. Omit it for the environment's real measured volume."
        },
        "service": {
          "type": "string",
          "description": "Scope to a service. Passed forward to estimate_savings when the user picks a mode."
        },
        "pattern_hash": {
          "type": "string",
          "description": "Optional pattern hash to scope the cost option menu to a single pattern. When present, routes_to.args will include a proposed_config row for this hash."
        }
      },
      "additionalProperties": false
    }
    ```

    Source: [`src/tools/cost-options.ts`](https://github.com/log-10x/log10x-mcp/blob/main/src/tools/cost-options.ts).

??? tenx-output-schema "Output schema"

    The `data` block inside the [StructuredOutput envelope](../index.md#json-by-default-output):

    ```typescript
    interface ToolData {
      modes: Array<{
        id: 'compact' | 'offload' | 'tier_down' | 'sample' | 'drop' | 'observe_only' | 'install_receiver';
        label: string;
        description: string;
        who_enforces: 'engine' | 'SIEM' | 'forwarder' | 'customer';
        applicable: boolean;
        gated_reason?: string;
        what_survives: string;
        routes_to: { tool: string; args: Record<string, unknown> };
      }>;
      siem_detected: string | null;
      capability_summary: { [key: string]: boolean };
      must_render_verbatim: string;
      must_ask_user: { question: string; options: string[] };
      forbidden_next_actions: string[];
    }
    ```

    Envelope-level fields the agent should also read: `summary.headline`, `actions[]`, `schema_epoch`.
