Corelight Sensors
Engineered for speed, scale, and AI to transform raw network traffic into high-fidelity evidence.
Visibility into security threats and network performance
Corelight Sensors offer passive network traffic analysis to monitor, analyze, and log network activity. Available as hardware appliances, virtual machines, cloud instances, flow, and software sensors, Corelight has options for your deployment environment requirements.
Physical Sensor
Hardware appliance devices designed for high-performance passive network traffic monitoring and analysis in physical network infrastructures.
Cloud Sensor
Scalable, agentless network monitoring that delivers visibility across virtual, private clouds, hybrid environments, and multi-cloud infrastructures.
Software Sensor
Gain visibility and actionable telemetry with our most flexible sensor solution designed for those hard-to-reach places across your network where you can’t put an appliance.
Virtual Sensor
Software-based network monitoring solution for cloud-hosted infrastructure, virtualized enterprise networks, and service provider data centers.
Flow Log Sensor
Transform flow data into structured Zeek® logs and extend visibility across VPCs, containers, functions, and traditional networks.
AP 220 Appliance Sensor
-
Traffic analysis speeds: Up to 4 Gbps
-
Traffic analysis speeds - with Zeek, Suricata IDS and Smart PCAP1: Up to 2 Gbps
-
Best suited for:
-
Branch offices
-
DNS subnet
-
Critical services or systems
-
VPNs
-
-
Size and weight: 1U rackmount, (1.75 in. x 17.2 in. x 19.98 in.), 17.6 lbs
-
Monitoring interface: 4 SFP interfaces. Support for copper and optical modules at 100M & 1G
-
Management interface: One 10/100/1000 copper ethernet port
-
External connector: VGA, USB
-
Power: 120/240 VAC 50/60 Hz single 600W Titanium PSU. Approximately 80W usage when idle and 260W usage at load
-
Operational mode: Out of band—fed by tap, span, or packet broker
1 Traffic analysis based on benchmark profile; actual results will vary based on traffic mix
AP 620 Appliance Sensor
-
Traffic analysis speeds: Up to 10 Gbps
-
Traffic analysis speeds - with Zeek, Suricata IDS and Smart PCAP1: Up to 5 Gbps
-
Best suited for:
-
Branch offices
-
DNS subnet
-
Critical services or systems
-
VPNs
-
-
Size and weight: 1U rackmount, (1.71 in. x 17.3 in. x 29.27 in.), 19 lbs
-
Monitoring interface: Four 1G/10G SFP/SFP+ modules. Support for copper and optical modules at 1G and/or 10G
-
Management interface: 2x 1Gbe ports 4x 10/25G, SFP28 NIC
-
External connector: VGA, USB
-
Power: 100-240 VAC 50/60 Hz redundant dual 1200W PSUs. Approximately 252W usage when idle and 477W usage at load
-
Operational mode: Out of band—fed by tap, span, or packet broker
-
Additional: Available shunting or deduplication to improve performance in high volume environments
1 Traffic analysis based on benchmark profile; actual results will vary based on traffic mix
AP 1200 Appliance Sensor
-
Traffic analysis speeds: Up to 25 Gbps
-
Traffic analysis speeds - with Zeek, Suricata IDS and Smart PCAP1: Up to 12.5 Gbps
-
Best suited for:
-
Branch offices
-
DNS subnet
-
Critical services or systems
-
VPNs
-
-
Size and weight: 1U rackmount, (1.7 in. x 19 in. x 31.85 in.), 48 lbs
-
Monitoring interface: Four 1G/10G SFP/SFP+ modules. Support for copper and optical modules at 1G and/or 10G
-
Management interface: 2x 1Gbe ports 4x 10/25G, SFP28 NIC
-
External connector: VGA, USB
-
Power: 100-240 VAC 50/60 Hz redundant dual 1400W PSUs. Approximately 241W usage when idle and 1042W usage at load
-
Operational mode: Out of band—fed by tap, span, or packet broker
- Additional: Available shunting or deduplication to improve performance in high volume environments
1 Traffic analysis based on benchmark profile; actual results will vary based on traffic mix
AP 3200 Appliance Sensor
-
Traffic analysis speeds: 50+ Gbps
-
Traffic analysis speeds - with Zeek, Suricata IDS and Smart PCAP1: Up to 25 Gbps
-
Best suited for:
-
Science DMZ environments
-
Telecommunication networks
-
High-volume data centers
-
-
Size and weight: 1U rackmount, (1.7 in. x 19 in. x 31.85 in.), 48 lbs
-
Monitoring interface: Monitoring interface dependent on SKU selected: Choice of 4x1/10G SFP+, 4x10/25G SFP28 or 2 x QSFP28 supporting 8 x 10G (via breakout cables), or 2 x 40G
-
Management interface: 2x 1Gbe ports 4x 10/25G, SFP28 NIC
-
External connector: VGA, USB
-
Power: 100-240 VAC 50/60 Hz redundant dual 1400W PSUs. Approximately 276W usage when idle and 1221W usage at load
-
Operational mode: Out of band—fed by tap, span, or packet broker
- Additional: Available shunting or deduplication to improve performance in high volume environments
1 Traffic analysis based on benchmark profile; actual results will vary based on traffic mix
AP 5200 Appliance Sensor
-
Traffic analysis speeds: 125+ Gbps
-
Traffic analysis speeds - with Zeek, Suricata IDS and Smart PCAP1: 62.5+ Gbps
-
Best suited for:
-
Science DMZ environments
-
Telecommunication networks
-
High-volume data centers
-
-
Size and weight: 1U rackmount, (1.7 in. x 19 in. x 31.85 in.), 48 lbs
-
Monitoring interface: 2 QSFP28 modules. Support for optical modules at 8 x 10G, 2 x 40G or 2 x 100G
-
Management interface: 2x 1Gbe ports 4x 10/25G, SFP28 NIC
-
External connector: VGA, USB
-
Power: 200-240 VAC 50/60 Hz redundant dual 1800W PSUs. Approximately 326W usage when idle and 1359W usage at load
-
Operational mode: Out of band—fed by tap, span, or packet broker
- Additional: Available shunting or deduplication to improve performance in high volume environments
1 Traffic analysis based on benchmark profile; actual results will vary based on traffic mix
Gartner® and Peer Insights™ are trademarks of Gartner, Inc. and/or its affiliates. All rights reserved. Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose
Exceptional Speeds and Performance Noted for Platform
The platform itself is very capable in terms of running various signatures and inspections. It can run at 100G speeds and do inspections at around 50G line rate IMIX traffic which is exceptional.
IT Security & Risk Management Associate, Banking
Gartner® and Peer Insights™ are trademarks of Gartner, Inc. and/or its affiliates. All rights reserved. Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose
Unveiling new insights into traffic monitoring with Corelight
The Corelight Network sensors have expanded our network monitoring capabilities and given us valuable insights into the traffic we monitor.
Special Agent, Government
Corelight Sensors for hybrid and cloud environments
Cloud Sensors
Real-time cloud threat detection
Corelight's Cloud Security Solutions enable complete visibility into your cloud network traffic, providing unparalleled insight into potential threats with a clear understanding of what is happening across your hybrid and multi-cloud environments in real time. Cloud Sensors enrich cloud traffic with control plane data and transform it into comprehensive logs, extracted files, and custom insights including cloud-specific detections. Corelight streamlines hybrid workflows and reduces tool sprawl by consolidating NSM, IDS, and PCAP datasets into a single, efficient platform.
- Complete network visibility in the cloud
- Uniform telemetry across environments
- Cloud-native detections
- 50-80% reduction in log volume
- Identify and map cloud services to hosts
- Available for AWS, GCP, and Azure
Software Sensors
Complete visibility, everywhere
Get all the benefits of the full Open NDR Platform capabilities in places that you couldn't otherwise reach. The Corelight Software Sensor can be deployed on your existing hardware to provide uniform network evidence across hybrid, multi-cloud, and distributed environments. This sensor parses dozens of network protocols and generates rich, actionable telemetry for threat hunting and incident response.
-
Deploy and scale in minutes
-
Focus on evidence, not instances
- Built-in detection, monitoring, and enrichment
- 50-80% reduction in log volume
Virtual Sensors
High-fidelity network data
Corelight's Hyper-V and VMware Open NDR Virtual Sensors transform network traffic into high-fidelity data for incident response, intrusion detection, and more. Our virtual sensors parse dozens of network protocols and generate rich, actionable evidence and detections, designed by security professionals for security professionals.
- Up to 8 Gbps monitored traffic
- 50-80% reduction in log volume
- Deploy and scale in minutes
- Full coverage from Corelight Support
- Focus on evidence, not instances
- Built-in detection, monitoring, and enrichment
- Automatic updates and enhancements
Flow Log Sensor
Normalization of flow data for multi-layered threat detection
Corelight’s Flow Log Sensor transforms raw flow logs, whether from AWS, NetFlow, or other native flow sources, into enriched, actionable security insights. Corelight combines unidirectional flow data from communicating hosts to provide a complete view of all network activity. By normalizing, correlating, and enhancing native flow data into Corelight’s security-focused metadata, you gain the clarity needed to accelerate investigations, detect advanced threats, and strengthen defenses across cloud, hybrid, and on-premises environments.
-
Extend visibility across VPCs, containers, functions, and traditional networks
-
Eliminate redundant data and focus on high-value insights
-
Normalize non-standard flow logs into correlated, structured Zeek logs
-
Export enriched, standardized logs into any SIEM, data lake, or analytics tool
Case study
Global law firm unlocks new threat hunting capabilities with a Corelight Sensor and Zeek Logs
Case study
How Corelight cured an energy company's SOC of a serious SMB headache
Case study
Security team sees 95% reduction in incident response time with Corelight's network visibility
Fortune 50 retailer saves $10M at the edge
Challenge
The projected cost and logistics of deploying physical appliances were prohibitive at over $10 million, and their fragmented mix of existing tools created data silos and operational headaches.
Solution
The retailer deployed Corelight's Open NDR Platform using Virtual Sensors on existing store servers, managing the entire 2,000+ sensor fleet with just two engineers via the Fleet Manager API.
Results
They saved millions in hardware costs, unified security data by replacing legacy tools, and gained critical visibility across all retail locations.
Maximize ROI with services and training from Corelight
Corelight Services and Training puts elite defense within reach by ensuring your team can maximize the value of our Open NDR Platform. From precision deployment and SIEM integration to activity-based training from world-class experts, our services provide the technical guidance needed to accelerate SOC maturity.
-
Accelerate implementation and time to value with health checks
-
Precision engineering for detection calibration and customization
-
Expert-led training and education services
FAQ
What are Corelight Sensors and what do they do?
Corelight Sensors are passive network traffic analysis tools that monitor, analyze, and log network activity to provide deep visibility into security threats and network performance. They use Zeek for advanced analytics, can integrate Suricata IDS, and support features like Smart PCAP and YARA file analysis for comprehensive threat detection and response.
What types of Corelight Sensors are available?
Corelight offers hardware appliance sensors, virtual sensors for VMware and Hyper-V, cloud sensors for AWS, Azure, and GCP, software sensors for Linux and Kubernetes environments, and flow log sensors that transform flow data into structured Zeek logs. This flexibility ensures organizations can deploy sensors wherever network visibility is needed.
How do Corelight Sensors support threat detection?
Corelight Sensors combine signature-based detection (Suricata), behavioral analytics (Zeek), and enrichment with threat intelligence to detect a wide range of threats, including malware, lateral movement, encrypted traffic misuse, and command-and-control activity.
What makes Corelight Sensors unique?
Corelight Sensors uniquely blend open-source Zeek analytics with enterprise features like centralized management (Fleet Manager), Smart PCAP selective packet capture, and seamless integration with SIEM, SOAR, and XDR platforms, delivering high-fidelity, actionable network evidence at scale.
In what environments can Corelight Sensors be deployed?
Corelight Sensors can be deployed in physical data centers, virtualized environments, public and private clouds, and hybrid networks, supporting a wide range of throughput and deployment scenarios to meet the needs of enterprises, service providers, and government agencies.