---
title: "Explain mode"
description: "Explains one enforcement mode in plain language before any action is taken, showing what it does, what is needed, and what it would mean for the service."
icon: material/information-outline
---

Called after the user picks a mode from [log10x_cost_options](cost-options.md). Returns a three-section plain-text card (not markdown) explaining the mode at a service level:

1. **What it does**: effect on events, no mechanism jargon
2. **What you need**: prerequisites
3. **What it would mean for [service]**: volume and estimated dollar impact when metrics are available

Then asks: Apply or Preview? Routes to `log10x_configure_engine` (apply) or `log10x_preview_filter` (preview).

## :material-code-braces: Example

!!! tenx-ask "You"

    explain drop for payment-svc

!!! tenx-answer "Log10x"

    What it does
      No events reach the SIEM; engine drops at the Receiver before delivery. Events are discarded permanently.

    What you need
      The 10x Receiver sidecar must be installed in-path. Requires a GitOps repo configured so 10x can open the action-plan PR.

    What it would mean for payment-svc
      payment-svc sends roughly 45.3 GB per month (splunk).
      Potential reduction: 45.3 GB × $0.50/GB = $272/mo.

    Do you want to apply drop to payment-svc, or first preview which patterns would be affected?
      1. Apply: route to log10x_configure_engine
      2. Preview: show me the pattern list first (log10x_preview_filter)

## :material-chat-question-outline: More to ask

- *"explain compact for checkout-svc"*
- *"what's the difference between drop and offload?"*
- *"explain tier_down"*

## :material-check-decagram-outline: Prerequisites

Reporter deployed (for volume figures). Volume data is best-effort; the card renders without it.

## :material-code-json: Schema and samples

??? tenx-input-schema "Input schema"

    Agent-facing JSON Schema (the canonical shape the MCP server publishes via `tools/list`):

    ```json
    {
      "type": "object",
      "properties": {
        "service": {
          "type": "string",
          "description": "Service name to personalize the explanation with service-level volume and cost figures."
        },
        "mode": {
          "type": "string",
          "enum": [
            "compact",
            "offload",
            "tier_down",
            "sample",
            "drop",
            "observe_only"
          ],
          "description": "Which enforcement mode to explain. Keep-everything levers come first, then the lossy opt-ins. `compact` = keeps everything: engine minifies events losslessly; all events still reach the stack. `offload` = keeps everything: engine diverts matched events to a customer-owned S3 bucket; readable via log10x_retriever_query. `tier_down` = keeps everything: engine stamps the routeState marker; a routing rule moves those events to a cheaper storage tier (Datadog Flex / CloudWatch IA / Azure Monitor Basic or Auxiliary Logs). `sample` = lossy opt-in: engine passes 1-in-N events through to the stack; the rest are discarded. `drop` = lossy opt-in: engine hard-drops matched patterns at the Receiver before delivery. `observe_only` = engine observes and fingerprints but does not act; use to baseline volume before committing."
        },
        "destination": {
          "type": "string",
          "description": "Auto-detected destination stack or forwarder. When omitted the tool infers from envs.json / env vars. Used to name the specific vendor in the explanation (\"your Datadog workspace\", \"your Splunk index\", etc.)."
        },
        "effective_ingest_per_gb": {
          "type": "number",
          "description": "Customer-supplied $/GB rate used for the dollar overlay. When set, source_disclosure.rate_source='customer_supplied'. When absent, the shared rate resolver falls back to envs.json analyzerCost → LOG10X_ANALYZER_COST → destination list price → unset (no dollar overlay)."
        }
      },
      "required": [
        "service",
        "mode"
      ],
      "additionalProperties": false
    }
    ```

    Source: [`src/tools/explain-mode.ts`](https://github.com/log-10x/log10x-mcp/blob/main/src/tools/explain-mode.ts).

??? tenx-output-schema "Output schema"

    The `data` block inside the [StructuredOutput envelope](../index.md#json-by-default-output):

    ```typescript
    interface ToolData {
      service: string;
      mode: 'compact' | 'offload' | 'tier_down' | 'sample' | 'drop' | 'observe_only';
      destination: string | null;
      service_bytes_per_month: number | null;
      service_cost_per_month_usd: number | null;
      must_render_verbatim: string;
      must_ask_user: { question: string; options: string[] };
      forbidden_next_actions: string[];
      routes_to: {
        apply: { tool: string; args: Record<string, unknown> } | null;
        preview: { tool: string; args: Record<string, unknown> };
      };
    }
    ```

    Envelope-level fields the agent should also read: `summary.headline`, `actions[]`, `schema_epoch`.
