Reviews from AWS Marketplace
0 AWS reviews
-
5 star0
-
4 star0
-
3 star0
-
2 star0
-
1 star0
External reviews
External reviews are not included in the AWS star rating for the product.
Great tool for Analyze and Monitor Traffic
What do you like best about the product?
Corelight is a Centralized Administration tool. its interface is user friendly.
What do you dislike about the product?
Nothing found so far that i dislike Corelight
What problems is the product solving and how is that benefiting you?
Provide Network visibility and play significant role
- Leave a Comment |
- Mark review as helpful
A premier tool for advanced SOCs
What do you like best about the product?
If your SOC needs better visibility, in particular in a way that will integrate with any of the other tools in your security stack, Corelight is the way to do it. In 15 minutes you can turn a network tap into rich metadata about every packet that's crossed that wire, in an open source format that works with any SIEM, schema, or other setup that might be valuable to you. Their Suricata integration is also the best IDS setup on the modern market, and their customer support is second to none. You'll be glad to work with Corelight, both the tech and the people!
What do you dislike about the product?
Corelight is best suited for larger organizations. The cost to ingest data into SIEMs whose pricing model runs on ingest can be high, and less advanced SOCs will have a learning curve using the tool.
What problems is the product solving and how is that benefiting you?
I can triage alerts much more rapidly, and I have a better asset inventory than ever before. It's a source of truth that has a lot of applications - there are plenty more than I'm using it for, for sure!
Right Tool, Great Support
What do you like best about the product?
Corelight appliances do one thing and do it well: process your network traffic through analysis engines. Corelight support staff know what they're doing, reply promptly, and resolve most issues within two emails.
What do you dislike about the product?
We've seen Corelight grow quite a bit since we first became a customer. I worry they might one day adopt Cisco's strategy of adding unnecessary features in the pursuit of achieving vendor lock-in. Doing would degrade the user experience and price out customers who can't afford a one-stop-shop security solution.
What problems is the product solving and how is that benefiting you?
Corelight solves the problem of having to maintain the physical and application layers of a network traffic analysis tool. This frees up our engineers to concentrate on configuring Zeek and Suricata, in turn improving the quality of the data used by our SOC.
Implementing Corelight monitoring as an MSSP for various customers
What do you like best about the product?
Very easy to deploy. The hardware sensors and pre-made VM images make deployment as an MSSP very easy as we can just hand this stuff to the customer and give them the key to our Fleet Manager and manage the rest on our side.
Fleet Manager in particular is really good for managing disparate configurations and one-offs across multiple customers.
Fleet Manager in particular is really good for managing disparate configurations and one-offs across multiple customers.
What do you dislike about the product?
I'd say Fleet Manager not having the ability to facilitate the particular MSSP scenario where the MSSP owns Fleet Manager and has a variety of customers in one instance, but the customer wants access to Fleet Manager for reporting or perhaps editing configurations. Because we can't silo customers in like a "site" fashion to prevent them from seeing other customer's data, it's a scenario we can't do right now.
What problems is the product solving and how is that benefiting you?
I'd say most customers have an idea of how much traffic they've got, but not the composition of it. That rich NTA data central to Corelight is the main value I've seen for the customer's side.
Great Company to Partner With
What do you like best about the product?
Their TAM team is very helpful when setting up the sensors. So far, the sensors are very easy to use. I like the fleet manager to manage all the sensors from one location.
What do you dislike about the product?
So far have hot found anything that I dislike
What problems is the product solving and how is that benefiting you?
It is giving our SOC visibility into the third leg of the SOC visibility triad - network monitoring.
Corelight at Mississippi State/HPC2
What do you like best about the product?
The support from the Corelight guys is amazing. They provide one-on-one support. They put out updates and features as necessary. Great product integration
What do you dislike about the product?
Increasing throughput or full packet capture would be significant investments.
What problems is the product solving and how is that benefiting you?
Corelight is our source of network visibility. It plays a significant role in our compliance posture.
Corelight - A great competitor in NDR space!
What do you like best about the product?
- Centralized administration
- Great customer service
- Administrator friendly user interfaces
- Great customer service
- Administrator friendly user interfaces
What do you dislike about the product?
- Can improve on the documentations/knowledge articles
- Needs only the involvement of Corelight Technical assistance team to carry out certain commands/options
- Needs only the involvement of Corelight Technical assistance team to carry out certain commands/options
What problems is the product solving and how is that benefiting you?
Help protect critical assets by continuous threat monitoring and reporting
Corelight is easy to use and open source
What do you like best about the product?
Corelight it pretty straight forward and easy to use. I do enjoy the open sourced aspect of it, giving customers the ability to create their own Zeek packages for very specific use cases.
What do you dislike about the product?
I wish Fleet Manager had more capabilities. Things such as multi-tenant, exportable reporting, and alerting capabilities when it comes to a sensor(s) specific health.
What problems is the product solving and how is that benefiting you?
Being that I am part of an MSSP, we use Corelight to assist our different customers to improve their security posture. It has helped bridge the gap on what an EDR tool cannot see.
Corelight and the benefits to your organization
What do you like best about the product?
The support and periodic review with the team assigned to you are excellent. The product (sensor AP along with add-ons such as Suricata and machine-based learning that provide insights within the Crowdstrike (Humio) platform are excellent. The base platform is like Zeek on steriods. If needed,pro-active support even lets you know the hardware may be failing and an RMAs you an identical substitute. The device logs to Humio, syslog, etc. simultaneously
The command line control of the device is excellent, and so is fleet management for a series of APs. There is also an annual Zeek conference in which new insights and roadmaps are presented by Corelight
The command line control of the device is excellent, and so is fleet management for a series of APs. There is also an annual Zeek conference in which new insights and roadmaps are presented by Corelight
What do you dislike about the product?
Nothing - the sensors work perfectly and dashboard summaries are very good. If one wants, one can always simply query the data manually. There is constant improvement with the release of updates and integrations with other vendor products. Corelight support is always helpful no matter what I throw at them - ranging from technical questions down to annual quotes to renew licenses. I simply cannot find anything to dislike
What problems is the product solving and how is that benefiting you?
Pro-active security monitoring and if there is penetration, one can look back to trace the origins. I am far more productive than I was without using Corelight.
Works great!
What do you like best about the product?
Simple deployment and great partnership with the account team. Very much appreciate the simplicity of managing a single device or multipule through fleet management tools.
What do you dislike about the product?
Only enable what you need... the volume of events can be substantial.
What problems is the product solving and how is that benefiting you?
Providing a top-notch NDR solution that can handle up to 10gbps of data.
showing 11 - 20