Very specifically, the open core of Elastic's offering doesn't do authentication. It's not that there's a limited number of users. It's not that it's a single user and password in a config file somewhere. It's that you go from having all the features of a licensed version including multiple users with configurable access to different data sets down to needing to run elk with no native authentication and authorization and then wrap authentication around it one way or another if you want the community edition. This is 2019. A data aggregation and inspection system that by default sits open on a port for anyone to use is not quite fit for purpose.