We use the solution to monitor Internet traffic, the data center, and LAN traffic.

Corelight Cloud Sensor
Corelight, Inc.Reviews from AWS customer
-
5 star0
-
4 star0
-
3 star0
-
2 star0
-
1 star0
External reviews
External reviews are not included in the AWS star rating for the product.
Corelight the Threat Hunters
We use Corelight sensors in our environment to monitor and alert based off of traffic.
Great Threat hunting choice
Pretty straight forward
I loved it
An expensive solution to monitor internet traffic with multiple dashboards
What is our primary use case?
How has it helped my organization?
The huge library especially the open source link, makes it the main engine for Corelight with some enhancements in the commercial version. It has a very powerful level, such as signature-based attacks or behavioral attacks, with enhancements in the design. It is very flexible for intelligent implementations like IPs, especially between big companies and banks.
Corelight is easy to understand and monitor what is going on behind the team.
The solution is already integrated with other systems like Suricata, Elastic, and Microsoft tools. It's very easy to integrate signature-based or behavior-based engines. You can use Elastic for the dashboards to get it from Corelight, along with all the benefits and expandability.
What is most valuable?
The tool helps us track the traffic easily. Additionally, the soft analysis is very easy to learn due to the simplicity of the engine. It can integrate with multiple threat and intelligence feeds. This empowers the solution more than its powerful. It's also easy to create additional dashboards specific to supporting specific tasks.
What needs improvement?
The solution’s architecture is complex and difficult to understand. There's multiple machines and VMs. It’s size will increase the pricing to reflect the design. The solution should make it to one single platform with all the features.
For how long have I used the solution?
I have been using Corelight as a distributor for one and a half years.
What do I think about the stability of the solution?
The product is very stable.
What do I think about the scalability of the solution?
The solution is very scalable. More than 12 users are using this solution in the middle east. Corelight is easy to expand, especially in Kubernetes. Just add the new machine, and it will work with the existing ones.
How are customer service and support?
There is a strong community behind Corelight. You may need support due to stability from the team in very specific cases.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is not straightforward. You need expertise for it. I rate the solution’s documentation a six out of ten.
Deployment depends on the MVP, the amount and the capacity of the environment. If it's a huge customer, you will face big problem, and it will not be easy to implement. You will have multiple integrations, multiple positions to position the sensors. It will be easier to pick for the smaller customers or networks. Deployment can take be two weeks to three months to complete.
I rate the initial setup a five out of ten, where one is difficult, and ten is easy.
What's my experience with pricing, setup cost, and licensing?
The solution is too expensive compared to others. If you have the technical knowledge, it's good. Corelight is a very big gap between you and others if you’re new.
What other advice do I have?
Overall, I rate the solution a seven out of ten.
Which deployment model are you using for this solution?
Best NDR solution Guardians of Network
Corelight
"Unveiling Network Threats"core
An open-source solution that gave us insight into our clients' network traffic flow
What is our primary use case?
We use the solution for packet capture sampling. We offer it as part of our managed service. It's so we can identify east-west traffic on a customer's network.
What is most valuable?
Corelight is low-cost and made on open-source, and the code is Zeek. It's an easy way for us to get visibility in a client's environment.
What needs improvement?
Corelight hasn’t added features in a long time.
For how long have I used the solution?
I have five years of experience with the solution.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is very scalable.
How was the initial setup?
The initial setup was straightforward. When deploying Corelight, the customer just needs to put the solution on a VM. The only maintenance required is the maintenance of the license.
What was our ROI?
We immediately realized the solution’s ROI. Its visibility into east-west traffic, being able to sample capture, gives a sense of traffic flow. Moreover, it's inexpensive.
What's my experience with pricing, setup cost, and licensing?
The product is open-source.
What other advice do I have?
I rate the solution an eight out of ten.