- Home
- Network Security
- Network Detection and Response
- Corelight AP 200
Corelight AP 200
Network sensor appliance for traffic monitoring using Zeek and Suricata

Corelight AP 200
Network sensor appliance for traffic monitoring using Zeek and Suricata
Go Beyond the Directory. Track the Entire Market.
Monitor competitor funding, hiring signals, product launches, and market movements across the whole industry.
Corelight AP 200 Description
The Corelight AP 200 is a network sensor appliance designed for out-of-band network traffic monitoring and analysis. The device operates by receiving network traffic from taps, span ports, or packet brokers and processes it for security analysis. The AP 200 is a 1U half-depth rackmount appliance with a nominal capacity of 2 Gbps for Zeek-only traffic monitoring. The device includes one gigabit Ethernet copper management interface (1000 Mbps only) and external VGA and USB connectors. It operates on 120/240 VAC 50/60 Hz power with a single power supply unit, consuming approximately 83 watts when idle and 141 watts under load. The physical dimensions are 19 × 14.5 × 1.75 inches with a weight of 22 pounds. The appliance supports multiple analysis workloads including Zeek network security monitoring, Suricata IDS, and Smart PCAP capabilities. Performance varies depending on the traffic mix and which analysis workloads are enabled, with additional workloads beyond Zeek reducing the sensor throughput speed. The AP 200 is part of a broader product line of appliance sensors ranging from 2 Gbps to 100 Gbps capacity, designed to provide network visibility and security monitoring capabilities for organizations of different sizes and network traffic volumes.
Corelight AP 200 FAQ
Common questions about Corelight AP 200 including features, pricing, alternatives, and user reviews.
Corelight AP 200 is Network sensor appliance for traffic monitoring using Zeek and Suricata developed by Corelight. It is a Network Security solution designed to help security teams with Network Security, Network Traffic Analysis, Zeek.
FEATURED
Fix-first AppSec powered by agentic remediation, covering SCA, SAST & secrets.
Cybercrime intelligence tools for searching compromised credentials from infostealers
Password manager with end-to-end encryption and identity protection features
Fractional CISO services for B2B companies to build security programs
POPULAR
Real-time OSINT monitoring for leaked credentials, data, and infrastructure
A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.
AI security assurance platform for red-teaming, guardrails & compliance
TRENDING CATEGORIES
Stay Updated with Mandos Brief
Get strategic cybersecurity insights in your inbox