Pre-Agent Fan-In Filtering: Cost Control Before the Agent Sees the Input
This piece argues that in high fan-in scenarios like alert storms, piping every alert straight to an agent investigation blows up the bill. The fix is a cheap pre-agent filter: use a small Mamba model to score log sequence perplexity, and only hand off truly anomalous events to the expensive LLM agent. Datadog's Mambark model reportedly narrows ~10B daily security events down to ~10K candidates—a six-order-of-magnitude reduction, though these are vendor self-reported figures without independent verification. The article traces the lineage from DeepLog's LSTM-based log anomaly detection in 2017 to Mamba SSMs in 2023, which keep streaming inference memory from ballooning with sequence length. For implementation, it recommends Drain for log template parsing first, then choosing a filter tier based on daily event volume.
Why it matters: An engineering piece with real numbers and architectural judgment, not generic 'AIOps' fluff. The Datadog Mambark case gives a quantified cost-compression reference, and the author's explanation of why generic small text models don't fit log streams adds real signal. Dings: ve...