Corelight-update¶
The primary purpose of the Corelight-update utility is to automate and simplify the workflow of collecting data from disparate sources of dynamic content for Corelight Sensors by integrating into your existing CI/CD process.
This data includes threat intel, Suricata rulesets, vulnerability data, Zeek packages and other Input Framework data. The data can come from pre-formatted local sources, pre-formatted remote sources, or third-part integrations.
There’s no need for additional tools if you integrate Corelight-update with your CI/CD or change control process to manage Suricata rulesets, Intel files, Input files or Zeek package bundles.
In addition to collecting and formatting data sources, Corelight-update can optionally apply Corelight best practices to Suricata rulesets, extracting indicators from atomic Suricata rules and creating Zeek Intel files. The corresponding Suricata rules are then disabled, reducing the workload of the Suricata process.
Corelight-update natively supports the concept of hierarchical processing with a single global configuration and multiple policy configurations.
The output of each policy is a single Intel file, a single Suricata ruleset, a single package bundle, and multiple Input files ready to be consumed by a Corelight Sensor.
A secondary function of Corelight-update is to push content to Corelight Sensors. It supports ALL types of sensors, both Fleet-managed and stand-alone.
- QuickStart - new install
- QuickStart - upgrade
- Global configuration
- Policy configuration
- References
- Corelight-update Release Notes
- v1.14.0 (March 2025)
- v1.13.1 (January 2025)
- v1.13.0 (November 2024)
- v1.12.0 (September 2024)
- v1.11.0 (August 2024)
- v1.10.1 (April 2024)
- v1.10.0 (April 2024)
- v1.9.4 (March 2024)
- v1.9.2 (January 2024)
- v1.9.0 (January 2024)
- v1.8.1 (September 2023)
- v1.8.0 (September 2023)
- v1.7.3 (August 2023)
- v1.7.2 (August 2023)
- v1.7.1 (August 2023)
- v1.7.0 (July 2023)
- v1.6.3 (July 2023)
- v1.6.2 (June 2023)
- v1.6.1 (May 2023)
- v1.6.0 (March 2023)
- v1.5.0 (February 2023)
- v1.4.1 (February 2023)
- v1.4.0 (January 2023)
- v1.3.0 (November 2022)
- v1.2.1 (November 2022)
- v1.2.0 (October 2022)
- v1.1.0 (October 2022)
- v1.0.1 (October 2022)