Natural-language SOC assistance on your stack — Elasticsearch, Ollama, and Elastic MCP — without shipping logs to the cloud.
BUILT ON A TRUSTED LOCAL STACK
PROBLEM
SOC teams drown in raw logs and noisy events without a local-first way to ask clear questions of their own data.
Jumping between Kibana, shells, and tickets burns minutes when you need answers about IPs, hosts, and windows now.
Shipping sensitive security telemetry to third-party AI endpoints is a non-starter for many regulated environments.
SOLUTION
Purpose-built around local models and security indices — not a generic chat wrapper.
ES, Ollama gemma4:e4b, Elastic MCP, FastAPI, and Next.js report real Operational status — not mock badges.

200 indexed alerts, severity distribution from /api/stats, and healthy stack components in one console.

Investigate, block IP, or resolve seed alerts from the same corpus the agent searches.

HOW IT WORKS
Bring up Elasticsearch, Ollama, Elastic MCP, and FastAPI with Docker Compose. Seed alerts land in alerts-security.
The console checks real connectivity — model tag, MCP ping, cluster health — not fake status badges.
Open the operations console to explore modules, logs, and the foundation that later agent phases will use.
OPERATIONS CONSOLE PREVIEW

ARCHITECTURE
Intake, topology, and triage — one screen, no endless sticky chapters.
Security alerts index into Elasticsearch (alerts-security) with deterministic seed data for demos.
FastAPI gateway links the analyst to Ollama, Elasticsearch, and Elastic MCP over the Docker network.
Incidents surface with severity so you can scope the window before agent workflows arrive in later phases.

FEATURES
Switch tabs to preview modules — not the same console repeated three times.

DESIGN PRINCIPLE
“Evidence first, language second. The agent only earns trust when Elasticsearch, Ollama, and MCP are actually healthy.”
FAQ
Open the operations console to verify health and explore Phase 0 modules.