Licensing¶
A subscription to Corelight Investigator includes the features and functionality available to your organization, as described in the Feature summary table below.
Feature summary¶
The following table summarizes the features supported by Corelight Investigator.
Feature |
Supported |
|---|---|
Incident Response |
|
Detection triage and workflow |
✅ |
Alert aggregation, prioritization, and tuning |
✅ |
Analytics |
|
Corelight sensor collections |
✅ |
Suricata IDS + Proofpoint ET Pro ruleset |
✅ |
Cloud-based ML detections |
✅ |
CrowdStrike Falcon X IOC database |
✅ |
Data Retention |
|
Investigator alerts & detections |
90 days |
Investigator alert contextualized logs |
30 days |
Additional alert contextualized logs retention |
N/A |
Full Zeek + Suricata logs |
30 days |
Additional Zeek + Suricata log retention |
Optional |
Data Export to SIEM/XDR |
|
Full Zeek + Suricata log export from sensor |
✅ |
Alert export from Investigator |
✅ |
Administration & Integration |
|
SAML / SSO |
✅ |
Security auditing |
✅ |
Fleet Manager |
✅ |
Smart PCAP |
✅ |
Support and Services |
|
Standard support |
✅ |
Enterprise support |
Optional* |
QuickStart service |
✅ |
Managed threat hunting services |
Optional* |
*Evaluation deployments include all Investigator features and functionality; however, optional add-ons for Enterprise support and managed threat hunting services are available only with a production subscription license.
License status¶
You can view your subscription license status and details at any time. From the System Settings in the left navigation, choose General Settings.
The License Status section displays your license information, including the subscription start date, the subscription expiration date, and the primary contact for your account. The section also shows the type of license you have and the log retention period.
The license information is read only; contact Corelight Support or your Account Manager to make any changes.
Licensing and usage¶
How Investigator licensing works¶
Investigator is licensed in per Gbps increments based on the throughput capacity of the Corelight sensors deployed with it. Each Gbps increment also includes a built-in daily data ingestion entitlement, so a single license purchase covers both the sensor throughput and the log volume that Investigator processes.
Sensor throughput (Gbps) is the primary licensing metric. It represents the volume of network traffic your sensors are licensed to observe.
Data ingest (GB/day) measures the volume of log data ingested into Investigator from your sensors during each calendar day. Every 1 Gbps of licensed sensor throughput includes a default ingestion entitlement of 100 GB/day.
Your usage is measured against the capacity specified in your order. For details on how Corelight measures capacity, reviews usage, and handles excess consumption, see the Corelight Product-Specific Terms.
Data ingestion¶
Every 1 Gbps of licensed sensor throughput includes a default ingestion entitlement of 100 GB/day. This entitlement is pooled across all sensors under the same Investigator account. The two metrics scale together. As you add Gbps capacity, your ingestion pool grows proportionally.
License Throughput |
Data Ingestion Pool (shared) |
|---|---|
1 Gbps |
100 GB / day |
In practice, this means you do not need to separately size or purchase ingestion capacity in most deployments. The ingestion entitlement included with your Gbps license is designed to accommodate the log volume that a sensor deployment of that size typically generates.
Monitoring data ingestion¶
Monitor your usage by viewing your daily log ingest volume from Platform Monitoring | Log Ingest. Reviewing this dashboard regularly helps you track consumption against your pooled ingestion entitlement and identify trends before usage exceeds your allocation.
When you exceed your data ingestion entitlement¶
Investigator does not automatically stop ingesting data when daily ingestion exceeds your entitlement.
If your usage consistently exceeds your daily allocation, Corelight will notify you and work with you for up to 30 days to bring ingestion within your allocation. During this cooperation period, options include adjusting configurations, reducing unnecessary log sources, filtering ingested logs, or purchasing additional ingestion capacity.
If excess usage continues after the cooperation period, Corelight may invoice for excess usage or require the purchase of additional capacity. Corelight does not retroactively charge for excess ingestion consumed before notification and completion of the cooperation period.
Review the Data ingestion best practices section below to determine whether configuration changes can bring your ingestion within your current entitlement.
Purchasing additional log ingest capacity¶
If your environment consistently exceeds your included allocation, you can purchase additional ingestion capacity. Depending on your deployment, this may be available as a standalone data ingest add-on or as part of an additional Gbps license. Each additional 1 Gbps license adds 100 GB/day to your shared log ingest pool and increases your sensor throughput capacity. Contact your Corelight Account Manager to discuss options.
Provisioning requirements and limitations¶
Before provisioning a new environment or adding tenants to an existing structure, ensure the deployment meets the following capacity, licensing, and regional requirements.
Tenant sizing limitations¶
These limits apply to all deployments, including individual Child Tenants within a Federated (Parent) structure:
Minimum Capacity: Investigator does not support tenants below 1Gbps.
Maximum Capacity: Provisioning any tenant type exceeding 500Gbps requires three months’ advance notice and approval from Corelight before the intended deployment date. This limit applies to both standalone deployments and Child Tenants in a Federated (Parent) structure.
Federated tenant limitations¶
Federated (Parent) and Child Tenant deployments are subject to the following regional and licensing constraints:
Licensing Restrictions: A Federated (Parent) tenant with a production license cannot include Child Tenants on evaluation licenses.
Regional Requirements: Federated (Parent) tenants are not supported across multiple regions. All Federated (Parent) and Child Tenants must reside within the same service region.
Datacenter regions¶
Your Corelight Investigator tenant will be provisioned in the datacenter region you select at initial purchase from the options listed in the following table:
Region |
Location |
Region Identifier |
|---|---|---|
North America |
United States (West) |
us-west-2 |
Europe |
Germany (Frankfurt) |
eu-central-1 |
Middle East |
UAE (Abu Dhabi) |
me-central-1 |
The region is set at provisioning and cannot be changed afterward. If your deployment requires a region not listed above, contact your Corelight Account Manager. New region requests require advance notice and approval. For Federated (Parent) deployments, all Parent and Child Tenants must reside in the same region.
License expiration¶
Investigator notifies you before your subscription license expires and restricts access once it does.
At 60 days before expiration, a warning appears in the Investigator left navigation panel showing the number of days remaining.
At 60 and 30 days before expiration, and again when the license expires, the system sends an email notification to account admins.
When a license expires¶
Account users cannot log in to Investigator.
Corelight retains the account infrastructure for a 90-day grace period, after which all infrastructure is deleted.
Contact Corelight Support or your Account Manager to renew your license.
Data ingestion best practices¶
If your daily log ingest volume is consistently high, the most common causes are configuration issues that can be identified and resolved without reducing your security coverage.
Common causes of high log ingest volume¶
Duplicate logs: A misconfigured or redundant tap can cause the same traffic to be logged more than once. This is one of the most frequent causes of unexpectedly high log ingest volume.
Verbose log enrichments: Overly broad enrichment configurations can significantly increase log size.
Abnormal tap behavior: Taps that run continuously without nights/weekends exclusions, or that capture traffic outside their intended scope, can generate more data than expected.
Reducing your log ingest volume¶
Review your sensor configurations for duplicate or redundant taps.
Check your log enrichment settings and reduce verbosity where possible.
Contact Corelight Support if you need help identifying the source of high log ingest volume.