On Thursday 30 October 2025 I went back to the Beurs van Berlage in Amsterdam for ElasticON Amsterdam. The 2025 theme, on every screen and banner, was âForge the Futureâ. A year earlier I had been in the same building for ElasticON 2024, which I wrote up in my Elastic Meetup and ElasticON Amsterdam 2024 post.
The timing was interesting. Elastic had announced Agent Builder on 21 October, as a technical preview on Elastic Cloud Serverless, âcoming soon in version 9.2â. Two days later Elastic 9.2 shipped, with Agent Builder, DiskBBQ, Streams and smarter ES|QL lookup joins. So the Amsterdam audience was seeing all of this a week after release.
This is a throwback built from my photos. Iâve kept to what was on the slides and signs, and Iâve checked the product facts against Elasticâs own pages.
![]()
The keynote hall filling up, with âSearch AIâ on the big screen.
The agenda board
The digital agenda board split the day into five colour-coded tracks: Keynote Sessions, Search Track, Security Track, Observability Track and Lightning Talks. The rooms were the Effectenbeurszaal, Graanbeurszaal 1 and 2, the Administratiezaal and, for lunch and the reception, the Grote Zaal.
![]()
The ElasticON agenda: Agent Builder, ES|QL, Streams and LLM observability all had their own slots.
The session titles tell you where Elastic was putting its effort:
- Agents: âThe future of building AI agents in Elasticsearch: Agent Builderâ, âFrom Search to Intelligence: Building Autonomous Agents with Elastic MCP and Amazon Bedrockâ, and âThe AIOps Agentic Stack: Building Autonomous AI Agents with Elastic and Googleâs Vertex AIâ.
- ES|QL: âExplorations in ES|QLâ and âPipe dreams: A year of ES|QL innovation, search, and Joinsâ, plus âPresent and future of Elasticsearch queriesâ.
- Observability: âStreams: The future of solving problems with logsâ, âA new era for Metrics in Elastic: Performance, Prometheus, and moreâ, âSimplifying OTel data ingestion and analysis with Elasticâ, âNo more AI visibility gaps: LLM Observability in Elasticâ, and âThe road towards enterprise observability at TVHâ.
- Security: âArchitecting the SOC of the future: Overcome data deluge and hidden threatsâ, âAccelerate threat intelligence by including Attack Discoveryâ, and âAdapting to AI in security: Best practices for autonomous AI and human interactionâ.
- Search: âOutsmarting the Enemy: Elevating Enterprise Search with Generative AIâ, âAI powered autosuggestâ, and âSemantics and scale: Elasticsearch vector database enhancementsâ.
The day ended with âClosing Remarks & AWS Hackathon Winnerâs Presentationâ at 17:25 and a networking reception from 17:45 to 18:45.
Opening keynote: Ash Kulkarni and Steven Schuurman
The opening keynote put two people on stage together: Ash Kulkarni, Chief Executive Officer, and Steven Schuurman, listed on the slide as Co-founder & Former CEO. My photo is from the back of the hall, so Iâll leave it at that rather than guess at what was said.
![]()
Ash Kulkarni (CEO) and Steven Schuurman (co-founder and former CEO) opening ElasticON Amsterdam 2025.
AWS: âInnovation Multipliedâ
Next on the main stage was Michael Rambold, Chief Technologist at AWS, with âInnovation Multiplied: How Elastic and AWS collaborate on Generative AI and beyondâ. The partnership slide listed three points under âThe most secure, extensive, and reliable Global Cloud Infrastructureâ:
- Long-term thinking and working backwards
- a 5-year Strategic Collaboration Agreement focused on GenAI
- 2024 AWS Global Generative AI Infrastructure and Data Partner of the Year
A quote from an AWS vice president on the same slide mentioned a âshared commitment to standards like Model Context Protocolsâ for agent-to-agent interactions. It also said Elasticâs search capabilities would be available with Amazon Bedrock through the AWS Marketplace.
![]()
The Elastic and AWS slide: a 5-year GenAI collaboration agreement and a 2024 partner-of-the-year award.
Observability with Elastic on Google Cloud
Over lunch I joined âUnleashing AI: The Power of Elastic on Google Cloudâ, which the agenda put in the Administratiezaal at 12:45. One slide repeated Elasticâs claim that it was named a Leader in the 2025 Gartner Magic Quadrant for Observability Platforms âfor the second year in a rowâ.
The main architecture slide was titled âObservability with Elastic on Google Cloud: AI-Powered with Search AIâ, with the claim â50%+ better at RCA, resolution w/ 50% lower costâ. It showed:
- Ingest: logs, metrics, traces, profiling, custom KPIs, SLI/SLOs and alerts, and runbooks, with OpenTelemetry as the ingest path.
- Processing: an ML platform with âzero config AIOpsâ, accurate insights and automated analytics, on ESRE as the unified datastore.
- A RAG-based AI Assistant with Gemini: automated problem solving (RCA, remediations, correlations), answers (summaries, explanations, guides, examples, queries, parsing), cost optimization (time, effort, MTTR) and security.
![]()
Elastic on Google Cloud: telemetry in, relevant context out to a Gemini-based assistant.
My take: the useful part of this diagram is that runbooks and SLOs sit next to logs and traces as inputs. An assistant that suggests remediations is only as good as the runbooks it can retrieve. Iâd also treat â50% lower costâ as a vendor claim to test on your own incidents.
TVH: the road towards enterprise observability
In the next session I joined, the whole audience wore wireless headphones. The slides carried the TVH logo, matching âThe road towards enterprise observability at TVHâ in the 13:30 slot on the agenda. The speakerâs name wasnât on any slide I photographed.
![]()
![]()
TVHâs phase 1 plan and the cost results, with the audience on headphones.
Phase 1 â Observability platform had four steps:
- a target architecture exercise, with Elastic Cloud as the key solution for logs and traces
- analyse usage patterns
- consolidate the existing platform
- define policies, set guardrails, and actively optimise cost through the right data retention policies and infrastructure
The Optimizing cost slide gave the numbers: steady data ingestion of up to 2.5 TB per day. Changing data retention allowed infrastructure downscaling, and gave an immediate 10% cost reduction. A chart over four quarters peaked in Q3 and then dropped.
The Key takeaways slide said:
- organisation-wide adoption of observability requires a transformation
- use observability to bridge the gap between business and IT, and teach teams to self-organise around their own KPIs
- consider accelerators such as communities of interest and a dedicated SRE
- understand your stakeholdersâ requirements and usage patterns before setting infrastructure and policies (Elastic professional services can speed this up)
- empower developers through self-service, but with fit-for-purpose policies and guardrails
My take: retention is the cheapest lever in any log platform, and itâs a policy decision, not a technical one. Getting 10% back right away at 2.5 TB/day, just by agreeing who needs which data for how long, is the usual pattern: the engineering is easy, and getting the data owners to agree is the hard part.
Semantics and scale: vector database enhancements
On the main stage, âSemantics and scale: Elasticsearch vector database enhancementsâ picked up where the int8 and BBQ talk at the 2024 meetup had left off.
It started with âWhat is a Vector Database?â: it stores and searches high-dimensional dense vectors. The core building blocks were managed embeddings, ANN index structures (graph-based and clustered), efficient storage and quantisation, filtering and hybrid search, and reranking on full-precision vectors.
![]()
âOur Progressionâ: from BM25 to semantic_text, quantisation and DiskBBQ, to hybrid and (future) managed multi-modal.
The âOur Progressionâ slide summed up Elasticsearchâs search features in three columns:
- Text and metadata: lexical search, BM25, Weak AND (WAND), feature fields.
- Semantic: semantic text (âjust like text ⌠with an embedding model behind the scene!â); bring your own vector (dense, sparse, rank); automatic quantisation (BBQ, int8, int4) with rescoring; HNSW and DiskBBQ.
- Hybrid: retrievers and ES|QL, Reciprocal Rank Fusion, normalisers. Under âManaged Multi-modal (future)â: text and image, then audio, then video, all embedded into one vector.
A-CORN for filtered graph search
The next slide was about a common problem in multi-tenant search: filters in ANN structures. The slideâs answer was âA-CORN adaptive pruning on HNSW graphsâ, which âreduces candidate explosionâ and is âapplied automatically based on the selectivity of the filterâ.
![]()
A-CORN: filtered kNN on HNSW without exploring the whole graph.
Elasticâs Search Labs post on filtered HNSW search with ACORN-1 gives the background. In Lucene 10.2, filtered kNN search became up to 5Ă faster. The new algorithm only kicks in when 40% or more of the vectors are filtered out, which is what âbased on the selectivityâ means in practice.
Vectors out of _source by default
The last slide I photographed was âExcluding Vectors from _sourceâ. From 9.2.0, vectors are removed from _source by default, which reduces disk and snapshot size. The bar chart compared a baseline of 52.3 GB with 19.3 GB with excluded vectors.
![]()
Dropping the duplicate copy of each vector: 52.3 GB down to 19.3 GB in Elasticâs example.
The Search Labs post Lighter by default: Excluding vectors from source explains the details. The setting is index.mapping.exclude_source_vectors. It defaults to true only for newly created indices, so existing indices are unaffected. Elasticsearch ârehydratesâ the vectors when it needs them for partial updates, reindex and recovery.
My take: this is the same lesson as int8-by-default in 2024. Defaults now depend on the version an index was created on. If your application reads embeddings back out of _source, test that path before you roll a new index template to production.
The session ended with a âCompetitive Benchmarkingâ chart that I couldnât read from my seat.
The expo floor and partners
Between sessions the Beurs van Berlageâs main hall was the expo, with Elastic stands around the floor and partner booths along the sides.
![]()
The expo floor from the balcony.
The partner wall thanked AWS, Microsoft, Google Cloud and Tines at the top, with Atos, Corelight, Devoteam and others below.
![]()
Me at the partner wall.
In the afternoon I stopped by BASE Conference 2025 at StartDock Singel (I wrote about BASE Conference 2024 last year). In the evening I went to the SRE NL meetup, which has its own post: SRE NL Amsterdam 2025: Learning from Incidents.
My take: from search engine to agent platform
Put the agenda next to the 9.2 release notes and the direction is clear. Elastic wants Elasticsearch to be the place where agents get their context, with ES|QL as the language that defines the tools. In 2025, agent sessions appeared in the search, security and observability tracks alike, not in one AI corner.
What Iâd do with it:
- Try Agent Builder on a copy of real data first. I later tested Agent Builderâs MCP endpoint and ES|QL tools on a local cluster, without an LLM, in Elastic Agent Builder MCP: Tools and Workflows, No LLM. Treat the tool definitions like any other API: version them and give them least-privilege keys.
- Keep the observability basics boring. TVHâs story was retention policies and guardrails, not AI. Thatâs still where most of the savings are.
- Re-check vector index assumptions on each upgrade. Quantisation, DiskBBQ and
_sourceexclusion are all defaults that change storage and recall without anyone choosing them.