Licensing

A subscription to Corelight Investigator includes the features and functionality available to your organization, as described in the Feature summary table below.

Feature summary

The following table summarizes the features supported by Corelight Investigator.

Feature

Supported

Incident Response

Detection triage and workflow

Alert aggregation, prioritization, and tuning

Analytics

Corelight sensor collections

Suricata IDS + Proofpoint ET Pro ruleset

Cloud-based ML detections

CrowdStrike Falcon X IOC database

Data Retention

Investigator alerts & detections

90 days

Investigator alert contextualized logs

30 days

Additional alert contextualized logs retention

N/A

Full Zeek + Suricata logs

30 days

Additional Zeek + Suricata log retention

Optional

Data Export to SIEM/XDR

Full Zeek + Suricata log export from sensor

Alert export from Investigator

Administration & Integration

SAML / SSO

Security auditing

Fleet Manager

Smart PCAP

Support and Services

Standard support

Enterprise support

Optional*

QuickStart service

Managed threat hunting services

Optional*

*Evaluation deployments include all Investigator features and functionality; however, optional add-ons for Enterprise support and managed threat hunting services are available only with a production subscription license.

License status

You can view your subscription license status and details at any time. From the System Settings in the left navigation, choose General Settings.

The License Status section displays your license information, including the subscription start date, the subscription expiration date, and the primary contact for your account. The section also shows the type of license you have and the log retention period.

The license information is read only; contact Corelight Support or your Account Manager to make any changes.

Licensing and usage

How Investigator licensing works

Investigator is licensed in per Gbps increments based on the throughput capacity of the Corelight sensors deployed with it. Each Gbps increment also includes a built-in daily data ingestion entitlement, so a single license purchase covers both the sensor throughput and the log volume that Investigator processes.

  • Sensor throughput (Gbps) is the primary licensing metric. It represents the volume of network traffic your sensors are licensed to observe.

  • Data ingest (GB/day) measures the volume of log data ingested into Investigator from your sensors during each calendar day. Every 1 Gbps of licensed sensor throughput includes a default ingestion entitlement of 100 GB/day.

Your usage is measured against the capacity specified in your order. For details on how Corelight measures capacity, reviews usage, and handles excess consumption, see the Corelight Product-Specific Terms.

Data ingestion

Every 1 Gbps of licensed sensor throughput includes a default ingestion entitlement of 100 GB/day. This entitlement is pooled across all sensors under the same Investigator account. The two metrics scale together. As you add Gbps capacity, your ingestion pool grows proportionally.

License Throughput

Data Ingestion Pool (shared)

1 Gbps

100 GB / day

In practice, this means you do not need to separately size or purchase ingestion capacity in most deployments. The ingestion entitlement included with your Gbps license is designed to accommodate the log volume that a sensor deployment of that size typically generates.

Monitoring data ingestion

Monitor your usage by viewing your daily log ingest volume from Platform Monitoring | Log Ingest. Reviewing this dashboard regularly helps you track consumption against your pooled ingestion entitlement and identify trends before usage exceeds your allocation.

When you exceed your data ingestion entitlement

Investigator does not automatically stop ingesting data when daily ingestion exceeds your entitlement.

If your usage consistently exceeds your daily allocation, Corelight will notify you and work with you for up to 30 days to bring ingestion within your allocation. During this cooperation period, options include adjusting configurations, reducing unnecessary log sources, filtering ingested logs, or purchasing additional ingestion capacity.

If excess usage continues after the cooperation period, Corelight may invoice for excess usage or require the purchase of additional capacity. Corelight does not retroactively charge for excess ingestion consumed before notification and completion of the cooperation period.

Review the Data ingestion best practices section below to determine whether configuration changes can bring your ingestion within your current entitlement.

Purchasing additional log ingest capacity

If your environment consistently exceeds your included allocation, you can purchase additional ingestion capacity. Depending on your deployment, this may be available as a standalone data ingest add-on or as part of an additional Gbps license. Each additional 1 Gbps license adds 100 GB/day to your shared log ingest pool and increases your sensor throughput capacity. Contact your Corelight Account Manager to discuss options.

Provisioning requirements and limitations

Before provisioning a new environment or adding tenants to an existing structure, ensure the deployment meets the following capacity, licensing, and regional requirements.

Tenant sizing limitations

These limits apply to all deployments, including individual Child Tenants within a Federated (Parent) structure:

  • Minimum Capacity: Investigator does not support tenants below 1Gbps.

  • Maximum Capacity: Provisioning any tenant type exceeding 500Gbps requires three months’ advance notice and approval from Corelight before the intended deployment date. This limit applies to both standalone deployments and Child Tenants in a Federated (Parent) structure.

Federated tenant limitations

Federated (Parent) and Child Tenant deployments are subject to the following regional and licensing constraints:

  • Licensing Restrictions: A Federated (Parent) tenant with a production license cannot include Child Tenants on evaluation licenses.

  • Regional Requirements: Federated (Parent) tenants are not supported across multiple regions. All Federated (Parent) and Child Tenants must reside within the same service region.

Datacenter regions

Your Corelight Investigator tenant will be provisioned in the datacenter region you select at initial purchase from the options listed in the following table:

Region

Location

Region Identifier

North America

United States (West)

us-west-2

Europe

Germany (Frankfurt)

eu-central-1

Middle East

UAE (Abu Dhabi)

me-central-1

The region is set at provisioning and cannot be changed afterward. If your deployment requires a region not listed above, contact your Corelight Account Manager. New region requests require advance notice and approval. For Federated (Parent) deployments, all Parent and Child Tenants must reside in the same region.

License expiration

Investigator notifies you before your subscription license expires and restricts access once it does.

  • At 60 days before expiration, a warning appears in the Investigator left navigation panel showing the number of days remaining.

  • At 60 and 30 days before expiration, and again when the license expires, the system sends an email notification to account admins.

License expiration warning

When a license expires

  • Account users cannot log in to Investigator.

  • Corelight retains the account infrastructure for a 90-day grace period, after which all infrastructure is deleted.

Contact Corelight Support or your Account Manager to renew your license.

Data ingestion best practices

If your daily log ingest volume is consistently high, the most common causes are configuration issues that can be identified and resolved without reducing your security coverage.

Common causes of high log ingest volume

  • Duplicate logs: A misconfigured or redundant tap can cause the same traffic to be logged more than once. This is one of the most frequent causes of unexpectedly high log ingest volume.

  • Verbose log enrichments: Overly broad enrichment configurations can significantly increase log size.

  • Abnormal tap behavior: Taps that run continuously without nights/weekends exclusions, or that capture traffic outside their intended scope, can generate more data than expected.

Reducing your log ingest volume

  1. Review your sensor configurations for duplicate or redundant taps.

  2. Check your log enrichment settings and reduce verbosity where possible.

  3. See the Corelight Investigator Ingest Optimization Guide.

  4. Contact Corelight Support if you need help identifying the source of high log ingest volume.