Corelight Sensors operate out-of-band and transform raw traffic into rich logs, extracted files, and security insights using a specialized version of the open-source Zeek (formerly ‘Bro’). Security teams can stream Corelight’s logs and insights directly to the Humio platform for search and analysis.
Corelight sensors are built with simplicity in mind and are easy to install, configure, and deploy. Corelight sensors come in platforms:
A Corelight sensor requires:
The initial setup involves:
Then, you can sign in to the sensor through the Managment IP and configure the sensor.
Configuring a Corelight sensor to send data to Humio is effortless and quick. Once you have network traffic coming in through the monitoring port of the sensor, follow these steps
Data should now be exported and ingested by the Humio server, and parsed.
The Corelight sensor manual is available from the sensor’s main page. Corelight also has a dedicated team of support experts which include the core team and contributors of the Zeek project.
Corelight and Humio’s integrated solution helps companies manage security threats and gain visibility across a company’s entire network. Humio’s instant, streaming search capabilities coupled with simple per-sensor pricing options makes it a perfect compliment for Corelight and open source Bro users.