Open Source

Open-source MCP servers for Elastic, security, and cloud

Tocharian builds and maintains open-source MCP servers that let AI agents work safely across Elastic, security, cloud, and data platforms. Our work centers on three directions:

  1. Let AI agents safely call Elasticsearch, Kibana, and security tools.
  2. Connect security, observability, and search workflows through MCP.
  3. Keep every tool call scoped, permissioned, and auditable.
Flagship projects

Kibana MCP Server

25,000 / mo

Access, search, and manage Kibana from any MCP-compatible client. The most widely used project we maintain.

  • Data views and saved searches
  • Dashboards and visualizations
  • Saved objects
  • Detection rules and alerts
  • Cases and timelines
  • Security and observability queries
Read more →

Elasticsearch MCP Server

1,084 / mo

Query and manage Elasticsearch from MCP-capable AI clients, with a tool surface built around security analysis and incident investigation.

  • Query DSL
  • ES|QL queries
  • Mappings and index information
  • Cluster health
  • Shard and node information
  • Aggregations
Read more →

SecOps ES Benchmark

An evaluation harness that measures whether an AI agent can actually run a security investigation in Elasticsearch — labeled attack telemetry, a graded exam, and a score.

  • 239,000 ECS-normalized documents across 12+ Elastic data streams
  • Five Linux intrusions forming one kill chain
  • 27 ATT&CK techniques across 12 tactics
  • Five investigation tasks, 54 auto-graded questions
  • Endpoint, Zeek, nginx, Suricata, and detection-rule alerts
  • Hosted read-only copy — point an agent at it with no setup
Read more →
MCP server catalog

A growing set of open-source MCP servers, each in its own repository. Every link goes straight to the source.

Elasticsearch tooling & plugins

Multi-version compatibility

Elasticsearch in enterprise environments is not always on the latest version. Tocharian’s open-source and commercial engineering work can cover:

  • Older Elasticsearch versions
  • Elasticsearch 5.x–8.x environments
  • Old and new API differences
  • Kibana version compatibility
  • Authentication & permission differences
  • Self-hosted clusters
  • Elastic Cloud
  • Hybrid environments
  • Custom proxy layers
  • Multi-cluster routing

Enterprises do not need to rebuild their entire Elastic environment just to use AI or MCP.

Enterprise open-source support

Enterprises can get commercial support built on Tocharian’s open-source projects. Services include:

  • Private deployment
  • Production implementation
  • Legacy version compatibility
  • Custom MCP tools
  • Custom connectors
  • SSO & identity
  • RBAC & least privilege
  • Tool allowlists
  • Operation approvals
  • Audit logging
  • Multi-tenant isolation
  • Performance & stability optimization
  • Long-term maintenance
  • Custom development
Discuss open-source support

Security design principles

MCP lets AI call enterprise tools, but tool-calling must be tightly controlled. In enterprise MCP projects, Tocharian prioritizes:

  • Least privilege
  • Read/write tool separation
  • Human approval for high-risk actions
  • Environment-level permission isolation
  • Tool-call logging
  • Input & output auditing
  • Secure credential management
  • Data access scoping
  • Model & tool boundaries
  • Failure & rollback mechanisms

AI can assist with analysis and prepare actions, but it must not bypass the customer’s existing security controls.

From open source to enterprise implementation

Open-source projects provide general capability. Enterprise projects usually also need to solve:

  • Customer-specific data models
  • Internal identity & permission systems
  • Private networks
  • Custom Kibana objects
  • Internal ticketing & approval flows
  • Legacy version compatibility
  • Model deployment approach
  • Security & compliance requirements
  • Monitoring & high availability
  • Long-term maintenance ownership

Tocharian helps enterprises turn open-source tools into complete, production-ready implementations.