Best Software for 2025 is now live!
Show rating breakdown
Save to My Lists
Paid
Claimed

20 Corelight Reviews

4.6 out of 5
The next elements are filters and will change the displayed results once they are selected.
Search reviews
Popular Mentions
The next elements are radio elements and sort the displayed results by the item selected and will update the results displayed.
Hide FiltersMore Filters
The next elements are filters and will change the displayed results once they are selected.
The next elements are filters and will change the displayed results once they are selected.
20 Corelight Reviews
4.6 out of 5
20 Corelight Reviews
4.6 out of 5

Corelight Pros and Cons

How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Cons

Overall Review Sentiment for CorelightQuestion

Time to Implement
<1 day
>12 months
Return on Investment
<6 months
48+ months
Ease of Setup
0 (Difficult)
10 (Easy)
Log In
Want to see more insights from verified reviewers?
Log in to view review sentiment.
G2 reviews are authentic and verified.
William J.
WJ
Security Analyst
Enterprise(> 1000 emp.)
Validated Reviewer
Verified Current User
Review source: G2 invite
Incentivized Review
What do you like best about Corelight?

Being able to enrich data daily as it is ingested and feed that into a log agrigator has been extremly useful. Depoloyments in our environment have also gone smoothly and the price has been fair. Review collected by and hosted on G2.com.

What do you dislike about Corelight?

One of the few downsides I have noticed is that we have had to write some corelight modules ourselves to properly sort and ingest data. Review collected by and hosted on G2.com.

LS
Sr. Devops Engineer
Mid-Market(51-1000 emp.)
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about Corelight?

My most helpful about corelight is network detection and analyze. Review collected by and hosted on G2.com.

What do you dislike about Corelight?

I would like more UI experience and improve it I would say. Review collected by and hosted on G2.com.

Verified User in Market Research
UM
Mid-Market(51-1000 emp.)
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about Corelight?

Really good detection of threats and detailed informs, as a simple user this is super insightful Review collected by and hosted on G2.com.

What do you dislike about Corelight?

I would like the detection of threat be faster but i know there are some process to accomplish before i could reicive the results. Review collected by and hosted on G2.com.

Verified User in Computer Software
UC
Mid-Market(51-1000 emp.)
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about Corelight?

1) Clean Website UI

2)Services provided

3) It seems very easy to use the services Review collected by and hosted on G2.com.

What do you dislike about Corelight?

Not much popularity

To much techinal features in the website that would be overwhelming for someone who is not involved in the field Review collected by and hosted on G2.com.

Richard D.
RD
Enterprise(> 1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Corelight?

The support and periodic review with the team assigned to you are excellent. The product (sensor AP along with add-ons such as Suricata and machine-based learning that provide insights within the Crowdstrike (Humio) platform are excellent. The base platform is like Zeek on steriods. If needed,pro-active support even lets you know the hardware may be failing and an RMAs you an identical substitute. The device logs to Humio, syslog, etc. simultaneously

The command line control of the device is excellent, and so is fleet management for a series of APs. There is also an annual Zeek conference in which new insights and roadmaps are presented by Corelight Review collected by and hosted on G2.com.

What do you dislike about Corelight?

Nothing - the sensors work perfectly and dashboard summaries are very good. If one wants, one can always simply query the data manually. There is constant improvement with the release of updates and integrations with other vendor products. Corelight support is always helpful no matter what I throw at them - ranging from technical questions down to annual quotes to renew licenses. I simply cannot find anything to dislike Review collected by and hosted on G2.com.

Verified User in Consulting
AC
Enterprise(> 1000 emp.)
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about Corelight?

Great place for your cybersecurity needs! Review collected by and hosted on G2.com.

What do you dislike about Corelight?

Partnered with crowstrike and the uncertainty with those two combined. Review collected by and hosted on G2.com.

Verified User in Computer & Network Security
AC
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Corelight?

Very easy to deploy. The hardware sensors and pre-made VM images make deployment as an MSSP very easy as we can just hand this stuff to the customer and give them the key to our Fleet Manager and manage the rest on our side.

Fleet Manager in particular is really good for managing disparate configurations and one-offs across multiple customers. Review collected by and hosted on G2.com.

What do you dislike about Corelight?

I'd say Fleet Manager not having the ability to facilitate the particular MSSP scenario where the MSSP owns Fleet Manager and has a variety of customers in one instance, but the customer wants access to Fleet Manager for reporting or perhaps editing configurations. Because we can't silo customers in like a "site" fashion to prevent them from seeing other customer's data, it's a scenario we can't do right now. Review collected by and hosted on G2.com.

Swetha Y.
SY
Azure Data Engineer
Enterprise(> 1000 emp.)
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about Corelight?

Corelight helps you to find any bad things happening like sneaky viruses or hackers trying to get in and having a detective tool for our Network. So, that we can process Everything safe and run smoothly Review collected by and hosted on G2.com.

What do you dislike about Corelight?

The potential downsides of Corelight is that it can be complex to setup and manage and it might require specialized knowledge to use effectively and it needs to be improved for better usages. Review collected by and hosted on G2.com.

Verified User in Higher Education
AH
Enterprise(> 1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Corelight?

Corelight appliances do one thing and do it well: process your network traffic through analysis engines. Corelight support staff know what they're doing, reply promptly, and resolve most issues within two emails. Review collected by and hosted on G2.com.

What do you dislike about Corelight?

We've seen Corelight grow quite a bit since we first became a customer. I worry they might one day adopt Cisco's strategy of adding unnecessary features in the pursuit of achieving vendor lock-in. Doing would degrade the user experience and price out customers who can't afford a one-stop-shop security solution. Review collected by and hosted on G2.com.

Verified User in Computer & Network Security
UC
Enterprise(> 1000 emp.)
Validated Reviewer
Review source: Seller invite
Incentivized Review
What do you like best about Corelight?

If your SOC needs better visibility, in particular in a way that will integrate with any of the other tools in your security stack, Corelight is the way to do it. In 15 minutes you can turn a network tap into rich metadata about every packet that's crossed that wire, in an open source format that works with any SIEM, schema, or other setup that might be valuable to you. Their Suricata integration is also the best IDS setup on the modern market, and their customer support is second to none. You'll be glad to work with Corelight, both the tech and the people! Review collected by and hosted on G2.com.

What do you dislike about Corelight?

Corelight is best suited for larger organizations. The cost to ingest data into SIEMs whose pricing model runs on ingest can be high, and less advanced SOCs will have a learning curve using the tool. Review collected by and hosted on G2.com.