Chainsaw: assess results with Jev
chainsaw_jev_triageSend selected Windows EVTX result rows to TypeSafe Jev for advisory classification and priority scoring, returning probabilities and confidence for triage.
Instructions
Send selected result rows to TypeSafe Jev for advisory classification and priority.
EXTERNAL DATA TRANSFER: sends the selected evidence fields to api.typesafe.ai. Requires CHAINSAW_JEV_ENABLED=true and credentials. One bounded API request per call, no retries. Returns source row indexes, probabilities and confidence; invalid answers fail only their source row, with both scores null and a named error; invalid response containers reject the batch. Each assessment lists all uncertain_reasons: insufficient_context, low_classification_confidence, low_priority_confidence or validation_failed. uncertain is true when reasons exist. Scores are model judgments, not confirmed findings. Review the original evidence before acting. Evidence and stored results are unchanged.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | Maximum rows sent to Jev. | |
| fields | No | Dotted paths or result-field shorthand to send. Omit to send whole selected rows, including their evidence file path. Use chainsaw_result_page with these fields to preview exactly what would be disclosed. | |
| handle | Yes | Source JSONL result handle to assess. | |
| offset | No | First source row index. | |
| min_confidence | No | Below this confidence, flag uncertainty. |