Home Business Leadership Elastic CEO brings a product mindset to the enterprise

Elastic CEO brings a product mindset to the enterprise

Elastic CEO Ashutosh Kulkarni argues that cybersecurity is, at its core, a data problem: a view he held long before it became mainstream. Now he sees unstructured information reaching the kind of turning point that databases brought to structured data half a century ago.

In this first of a two-part interview with Frontier Enterprise, Kulkarni explains how Elastic’s product-led culture, rooted in open source and search, is shaping new approaches to observability, security, and AI across the enterprise.

What was the transition from CPO to CEO like?

Building businesses and products has always been my passion. At the end of the day, our customers work with us because of the innovations we deliver, the features we build into our products that help them solve specific problems, and the support these products provide in their daily work. My heart has always been in products, and I think it always will be.

In some ways, a CEO’s job is to be a good teammate to colleagues who are each specialised in their own areas. I lead with a product-centric mindset, but it’s been a fun transition. I loved the culture when I joined Elastic. I was already familiar with the product and had a strong affinity for it, and I quickly came to appreciate the customer base as well. The year I spent running product and engineering made the move into the CEO role a very smooth one.

How did you transition from Informatica and McAfee to Elastic?

My focus has always been on the enterprise side, rather than consumer technology, but it has consistently involved data and cybersecurity. I’ve always seen cybersecurity as a data problem, and more people are starting to frame it that way now. Even 10 years ago, when I was at McAfee and Akamai working on security products, I saw that threats manifested as information hidden in logs and systems, just waiting to be identified. If you knew what to look for and could spot those patterns quickly, you could stop the problem from spreading and isolate and fix it.

I’ve spent most of my career working on enterprise data and cybersecurity problems. I first encountered Elastic at a previous company, where I had to solve the problem of building a monitoring solution across a large CDN network with more than a quarter of a million servers distributed worldwide. We needed to fine-tune observability at scale, and that was when we began using Elastic for logging.

When I was at Informatica, around the time Google first launched Gmail, I became one of its early adopters. What struck me was that you no longer needed folders, because the system handled categorisation and discovery. You could keep everything in one inbox, and if you needed to find something later, you just searched for it. I realised that, for all our strengths in reasoning and problem-solving, human beings suck at information retrieval. Machines, however, excel at it.

Search has fascinated me for a long time. When I discovered Elasticsearch at a previous company, I started using it more and more. Later, at McAfee, we built our EDR solution on Elasticsearch, and I became a fanboy. By the time I joined Elastic, I was already drawn to the culture. I had never worked directly on open-source software before, though I had used it, and I quickly saw the value of being close to a user base and community. You don’t always have the best ideas internally, but when you look at the collective wisdom of the community, there’s a lot that you can learn.

Elastic moved into observability because we saw customers using us for observability. We entered security because customers used us for security solutions. We began investing in AI when customers started storing dense vectors with us, which led to the start of our vector database technology five years ago. The journey has been fascinating. Open source was something I knew but hadn’t fully grasped until working here. After four and a half years, I now understand why open source is so powerful. It accelerates innovation in ways that closed-source approaches cannot.

Our source code is open, which means people can examine it and give us feedback. Customers regularly review our GitHub repositories and comment, often making requests through pull requests. This creates a faster, more direct feedback loop. It also raises the standard for quality. If only you and a handful of engineers ever look at your code, the bar is lower than if millions of developers worldwide may examine and judge it. Knowing that helps us write really high-quality code.

Will enterprise interfaces just end up being a white box with text queries?

If you step back and think about the challenge that has always existed with unstructured, messy information, even with search, the issue has been that answers are never deterministic. Google solved this for the internet. We did this for internal data, and there are strong parallels. What Google did by indexing information on the web, we do for our customers by indexing all the information within their environment. The algorithms differ. Google used the PageRank algorithm, which looked at indirected links. We used an algorithm called BM25, and now we use vector similarity search and semantic search. The algorithms are different, but the principle is the same: finding ways to search across all your data.

Unstructured data has always been information sparse. If I ask a good lawyer to read a 100-page legal document and write a one-paragraph summary, the lawyer can do that. That has been near impossible to do in the past. When you used Google or Elastic to search for something, what you received was a list of the most relevant links, or in Elastic’s case, the most relevant documents. You still had to read them and determine how they related to your query. That required extra effort and highlighted the persistent gap in search and unstructured data.

Large language models have changed this. Now you can reason, summarise, and synthesise. ChatGPT, instead of returning a list of links, can give you an answer. Gemini can do the same. Likewise, with internal data, Elastic can now provide an answer rather than just the top five or 10 relevant documents. That has been a massive breakthrough.

Business processes that previously depended entirely on unstructured information and could not be automated—documents of all kinds—are now being automated. People are building agentic workflows and conversational chatbots, creating sophisticated systems for customer support, vendor interactions, marketing, and sales. These processes are now automated, which I find fascinating.

A few years from now, every knowledge worker will rely on AI to do their job more efficiently and quickly, no matter the industry. This is going to do for unstructured data what databases did for structured data 40 or 50 years ago. That was when ERP and CRM systems emerged, enabled by SQL. We are now seeing the same transformation with unstructured data. It’s truly exciting.

Going back to open source, is it the model for enterprise tech?

It’s clearly not yet the majority of how things are done. Open source requires a significant level of discipline. The model itself has also evolved. If you think back to the first incarnation of commercial open source, it was something like Red Hat, whose early business model was to provide the product for free and charge for support. That was the monetisation approach. Over the years, this evolved as companies learned from one another and figured out how to do things better.

Elastic has always monetised the product itself, rather than relying primarily on services or support. We’ve always offered a free version of our product, which was highly capable and not a limited or gimmicky release. Then we identified the high-value features that customers would be willing to pay for. Today these generally fall into a few categories.

For example, anything that enables customers to significantly reduce infrastructure costs goes into the paid edition. That makes for an easy business decision: even though they are paying us, they’re saving a lot more on what they spend on hardware, resulting in a net gain on ROI. Similarly, we monetise AI features that allow customers to operate more efficiently or do things that were previously impossible.

Today, about 35% of our business comes from AI and search use cases, roughly 40% from observability use cases, and around 25% from cybersecurity use cases. That’s how the business is divided, and across all of these areas, it’s our product capabilities that customers are buying.

- Advertisement -