- Expanso + Jev
- Example 07 of 10
A SOC pre-filter: Jev names the threat, Expanso picks the storage tier.
Every auth event gets a threat classification — brute force and credential stuffing escalate to the SIEM, benign noise goes to cold storage.
Where the record goes
Every stage on the left is Expanso, and it is deterministic. The record crosses to Jev once, for the one question a rule cannot answer, and comes straight back. Line numbers link to the YAML below.
POST /auth-events- Receive
- Shape
- Ask Jev
- Gate
- Route
threatescalate
siemwarmcold
- Receivelines 11 to 16
An HTTP server input accepts auth events on
POST /auth-events. - Shapelines 17 to 26
Parses the POST body if it arrived as a string, then stamps
received_at. It applies the same fixed rules every time, with no model involved; the timestamp is the one value that differs. - Ask Jevlines 27 to 73
Expanso packs the whole record and the typed questions into one request. Jev answers. If the call fails, a
catchsubstitutes empty answers markedjev-unavailable, and the pipeline keeps going.threatchoiceescalatenoul
- Gatelines 74 to 87
Fixed thresholds over Jev’s answers choose SIEM, warm, or cold.
- Routelines 88 to 111
A
switchoutput writes to one file per tier.
What Jev is asked
Jev, judgmentThe pipeline sends the record with 2 typed questions. Jev answers each one with a value the pipeline can compare against a number.
threatchoiceWhat threat pattern does this authentication event match?
benign · brute_force · credential_stuffing · impossible_travel · token_abuse · other
escalatenoulShould a security analyst review this event immediately?
What Expanso does with the answers
Expanso, deterministicFixed thresholds, checked in order. The first rule that matches sets the route. These are the expressions in the pipeline, not a summary of them.
- $escalate >= 0.85siem · Jev is confident an analyst should look now.
- $threat != "benign"warm · Matches a threat pattern, not urgent.
- elsecold · Benign.
If Jev is unreachable: cold
With no answers, the threat defaults to benign and escalation to 0, so every event goes to cold storage while Jev is unreachable.
The pipeline
This is the example's own pipeline file, unmodified. Violet marks the lines Expanso runs on its own. Orange marks the handoff, and the darker orange band is the HTTP call to Jev itself.
name: jev-soc-prefilter
type: pipeline
description: SOC pre-filter with Jev — auth and access events get a threat classification and escalation judgment at the edge. Only real escalations reach the SIEM; everything else lands in cheap storage with scores attached.
namespace: production
labels:
category: data-security
pattern: ai-decision
model: jev
config:
input:
http_server:
address: "0.0.0.0:8080"
path: /auth-events
allowed_verbs: ["POST"]
pipeline:
processors:
- mapping: |
# http_server already parses JSON bodies; only parse raw strings
root = if this.type() == "string" { this.parse_json() } else { this }
- mapping: |
root = this
root.received_at = now()
# ── Ask Jev ──
- mutation: |
meta jev_start = timestamp_unix_milli()
- branch:
request_map: |
root = {
"state": this.string(),
"model": "jev-latest",
"questions": {
"threat": {
"type": "choice",
"instructions": "What threat pattern does this authentication event match?",
"criteria": {
"benign": "Normal user behavior, no threat indicators",
"brute_force": "Repeated failed logins against one account",
"credential_stuffing": "Many accounts tried from one source, low success rate",
"impossible_travel": "Logins from geographically distant locations too fast to be one person",
"token_abuse": "Stolen or replayed session tokens, anomalous API use",
"other": "Suspicious but does not match a known pattern"
}
},
"escalate": {
"type": "noul",
"instructions": "Should a security analyst review this event immediately?"
}
}
}
processors:
- http:
url: "${JEV_API_URL:https://api.typesafe.ai/v1/systemone}"
verb: POST
headers:
Content-Type: application/json
Authorization: "Bearer ${TYPESAFE_API_KEY}"
timeout: 2s
retries: 1
- catch:
- mapping: |
root = {"answers": {}, "model": "jev-unavailable"}
result_map: |
root.jev = {
"answers": this.answers,
"model": this.model.or("jev-latest"),
"ms": timestamp_unix_milli() - metadata("jev_start")
}
# ── Confidence-gated cascade ──
- mapping: |
root = this
let threat = this.jev.answers.threat.choice.or("benign")
let escalate = this.jev.answers.escalate.noul.or(0)
root.jev_decision = if $escalate >= 0.85 {
"siem"
} else if $threat != "benign" {
"warm"
} else {
"cold"
}
output:
broker:
pattern: fan_out
outputs:
- stdout:
codec: lines
- switch:
cases:
# Production: swap for http_client -> SIEM ingestion API
- check: this.jev_decision == "siem"
output:
file:
path: ./data/jev-soc-prefilter/siem-${! now().ts_format("2006-01-02") }.jsonl
codec: lines
- check: this.jev_decision == "warm"
output:
file:
path: ./data/jev-soc-prefilter/warm-${! now().ts_format("2006-01-02") }.jsonl
codec: lines
- check: "true"
output:
file:
path: ./data/jev-soc-prefilter/cold-${! now().ts_format("2006-01-02") }.jsonl
codec: lines
111 lines. Copy and Download both give you the file byte for byte.
What you need
- Expanso Edge installed, to validate and run the pipeline.
- A Jev endpoint. The pipeline posts to
JEV_API_URL, and falls back tohttps://api.typesafe.ai/v1/systemonewhen that variable is unset. - A key for that endpoint in
TYPESAFE_API_KEY. The pipeline sends it as a bearer token and has no default for it.
What it proves
- Input. POST /auth-events on port 8080.
- Output. Local files under
./data/jev-soc-prefilter/. A comment in the YAML marks where a SIEM ingestion API replaces the file in production. - Scope. This example ships as a pipeline file and sample records. Its README marks the live runtime (event generator and dashboard) as coming next, so what is published here is the pipeline itself.
- Revision. The file shown is the example as of commit
517c38fof its repository, which is still being developed.
Sample records
The first two of the records that ship with this example. Download all of them.
{"ts":"2026-09-18T14:00:00Z","user":"[email protected]","ip":"10.4.2.18","geo":"Seattle, US","result":"success","mfa":true}{"ts":"2026-09-18T14:01:12Z","user":"[email protected]","ip":"203.0.113.99","geo":"Lagos, NG","result":"failed","failures_10m":47}Questions about this example.
receive, shape, gate, route. Each of those stages applies the same fixed rules every time, with no model involved. Expanso also sets the thresholds that turn Jev's answers into a route.
Jev answers 2 typed questions about each record: threat, escalate. It does not choose the route. The pipeline's gate does that from Jev's answers.
The pipeline catches the failed call, marks the record jev-unavailable, and the gate resolves to "cold". With no answers, the threat defaults to benign and escalation to 0, so every event goes to cold storage while Jev is unreachable.
Run the deterministic half on your own nodes.
Expanso Edge runs these pipelines where the data is created. The first five nodes are free.