No more typing reviews! Try our Samantha, our new voice AI agent.

Check Point IPS vs Corelight Open NDR comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Check Point IPS
Ranking in Intrusion Detection and Prevention Software (IDPS)
3rd
Average Rating
8.6
Reviews Sentiment
6.8
Number of Reviews
68
Ranking in other categories
No ranking in other categories
Corelight Open NDR
Ranking in Intrusion Detection and Prevention Software (IDPS)
19th
Average Rating
8.8
Reviews Sentiment
7.6
Number of Reviews
7
Ranking in other categories
Network Traffic Analysis (NTA) (4th), Network Detection and Response (NDR) (7th), AI-Powered Cybersecurity Platforms (12th)
 

Mindshare comparison

As of October 2026, in the Intrusion Detection and Prevention Software (IDPS) category, the mindshare of Check Point IPS is 3.1%, down from 3.6% compared to the previous year. The mindshare of Corelight Open NDR is 1.3%, down from 2.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Intrusion Detection and Prevention Software (IDPS) Mindshare Distribution
ProductMindshare (%)
Check Point IPS3.1%
Corelight Open NDR1.3%
Other95.6%
Intrusion Detection and Prevention Software (IDPS)
 

Featured Reviews

GR
Support at a security firm with 51-200 employees
Real-Time Blocking Improves Response and Reduces Manual Logs
The best feature in my experience with Check Point IPS is the real-time prevention because it uses thousands of preventive protections based on both known exploit signatures and behavioral analysis to detect and block threats before they reach vulnerable systems. I find the behavioral analysis feature of Check Point IPS to be a most valuable feature because it can detect sophisticated threats that do not match known signatures. For example, when I need to view anomaly detections, instead of relying solely on known attack patterns, Check Point IPS monitors network traffic for unusual behavior such as unexpected protocol use, abnormal data flows, or suspicious command sequences. Check Point IPS impacts my organization positively because it has had a strong positive impact by strengthening our network defense, reducing manual work, and improving our incident response times.
reviewer2834367 - PeerSpot reviewer
Growth And Strategy Lead at a computer software company with 51-200 employees
Network visibility has transformed how we detect nation state threats and protect critical industry
Before Corelight recently started pushing some of the agentic features, querying at times could be a little difficult, depending on your mastery of log scale. However, I think with a lot of the artificial intelligence that they are building in, it is getting a lot easier to query in the platform. I would definitely encourage them to continue down that path where anybody can hop into the platform and start running queries, whether it is a simple instruction like I want this, and an artificial intelligence process can actually build the query and do it. I think that would be super powerful. Cyber skill sets are in high demand, and there is a huge backlog in cyber talent. We cannot fill all the positions we need. The easier we can make these cyber systems for people to pick up and be effective on, I think is really key. Explainability of data is hyper important. In the past few artificial intelligence related updates we have gotten from Corelight, that has been one of the first questions our team has asked every time or that I have asked: show me what the model is doing, show me how it came to this analysis. Within Investigator platform, they are able to walk through and see exactly what data the artificial intelligence pulled from where and why it did what it did as far as making its suggestions. They have definitely built their system with artificial intelligence in mind up front, and having that openness as one of the key features of any of their artificial intelligence and machine learning processes in the platform is important. The issue with black boxes is obviously hallucinations from artificial intelligence and just not being able to trace to ground truth. When we are talking about these cyber incidents and being able to do forensics, you need to be able to pinpoint and tie everything together, and black boxes really obscure that and prevent you from doing so. Corelight has done a really good job of making sure that everything is explainable and everything is mapped when it comes to leveraging any of their artificial intelligence features.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Basically, it is easy to use and offers a wide variety of protections through all kinds of software, services, appliances, and IoT-Devices."
"It is also worth noting that many IPS signature comes with detailed background about the vulnerability, and potentially how the vulnerability would affect the network security."
"Real-time protection has blocked most threats that could affect system operations."
"IPS logs enable complete visibility and reporting through the smart console."
"Since implementing Check Point IPS, we've seen a significant positive impact, as the company no longer spends time worrying about threats like ransomware, allowing us to focus on our core operation with greater peace of mind, and it has also reduced the time our team spends managing incidents, making our security process more efficient overall."
"Check Point Intrusion Prevention System has great profiles, and we can continuously create, modify, activate, deactivate or configure any specific setting to allow the profile to focus on just one thing or for certain attacks."
"The integration of IPS with the firewall is quite efficient."
"It protects against specific known exploits but also, with SandBlast integration, it is able to protect against unknown or zero-day attacks at the perimeter level."
"Our company has seen massive improvements in cybersecurity position for our clients."
"The most valuable feature is the embedded IDS from Suricata."
"It's easy to create additional dashboards specific to supporting specific tasks."
"It is easy to deploy and easy to handle."
"It's an easy way for us to get visibility in a client's environment."
"Technical support seems to be good."
"Corelight is easy to use."
"Corelight Open NDR has had a positive impact on my company, providing visibility as the Suricata engine can scan huge volumes of traffic, including north-south and east-west, revealing signatures and exposures I was not expecting and enabling me to catch them with Suricata alerts."
 

Cons

"Sometimes it will not connect to the threat cloud."
"One area where Check Point IPS could be improved is the language in the support, as it is currently only available in English."
"I would like the product to provide us with intelligence to understand what we really have in our environment."
"I observed on our management that sometimes IPS does not connect to the threat cloud, we have to check and improve it. Otherwise, all of the features are good."
"There is no standalone IPS appliance available."
"The scalability of Check Point IPS is on point, while the customer support is sometimes a bit slow."
"One area that could be improved in Check Point IPS is the user interface for managing IPS policies, which can be a bit complex for new users, along with the need for faster signature updates for emerging threats and more seamless integration with third-party tools."
"The IPS inspection throughput goes high in older security gateways that have limited hardware resources, so that can be improved."
"The solution’s architecture is complex and difficult to understand. There are multiple machines and VMs."
"In the next release, building a graphical user interface would be helpful."
"Corelight hasn’t added features in a long time."
"Before Corelight recently started pushing some of the agentic features, querying at times could be a little difficult, depending on your mastery of log scale."
"Machine learning could be a good improvement, but it's very costly."
"They can enhance the interface of the product. They can make it more interactive and also easier to use for feature access."
"It's an expensive solution and the price could be reduced."
 

Pricing and Cost Advice

"The tool's licensing model is good. The licensing costs are yearly. I rate it an eight out of ten."
"I think that the price of support is around $40,000 USD or $50,000 USD per year."
"There is a license needed to use the Check Point IPS which is not expensive. However, the Check Point IPS device is expensive."
"I give the price of the solution a five out of ten."
"I rate the product price an eight on a scale of one to ten, where one means it is very cheap and ten means it is very expensive. The product is expensive."
"The pricing is quite reasonable."
"You can pay for Check Point IPS yearly, or you can go with a three-year license. There's no extra cost apart from the standard licensing fee."
"The pricing for Check Point IPS is competitive and brings good value for the money."
"It's a yearly fee and depends on what you are looking for."
report
Use our free recommendation engine to learn which Intrusion Detection and Prevention Software (IDPS) solutions are best for your needs.
915,341 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
20%
Financial Services Firm
10%
Construction Company
7%
Security Firm
6%
Financial Services Firm
12%
Government
9%
Real Estate/Law Firm
7%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business51
Midsize Enterprise21
Large Enterprise23
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise2
Large Enterprise1
 

Questions from the Community

What is your experience regarding pricing and costs for Check Point IPS?
I have saved around two or three hours a week since I started using Check Point IPS. My experience with pricing, setup cost, and licensing for Check Point IPS is great, and I have no problem with t...
What needs improvement with Check Point IPS?
Check Point IPS is working well for our organization. In the future, more automated and more AI-based intelligence could be fed into Check Point IPS, and that would be helpful for us.
What is your primary use case for Check Point IPS?
Check Point IPS is used as a security feature to prevent zero-day attacks and the execution of malicious files in our network. Check Point IPS is an Intrusion Prevention System that prevents malici...
What is your experience regarding pricing and costs for Corelight?
I have a fortunate experience with pricing, setup costs, and licensing of Corelight Open NDR, as being a principal architect, I get to sit outside of that conversation and just choose the best prod...
What needs improvement with Corelight?
Corelight Open NDR does not need any improvements or additional features in the next releases. The product is excellent at what it does, and I believe what they have done with it, taking an open-so...
What is your primary use case for Corelight?
I have been using Corelight Open NDR solution for approximately three years. I leverage the Suricata engine heavily for alerting on indicators of compromise as my main use case for this solution.
 

Also Known As

Check Point Intrusion Prevention System
Corelight Open NDR
 

Overview

 

Sample Customers

Morton Salt, Medical Advocacy and Outreach, BH Telecom, Lightbeam Health Solutions, X by Orange, Cadence, Nihondentsu, Datastream Connexion, Good Sam, Omnyway, FIASA, Pacific Life, Banco del Pacifico, Control Southern, Xero, Centrify
CarrefourEdnonGrand Canyon EducationSektorCERTTietoevryVolkswagen Financial Services
Find out what your peers are saying about Check Point IPS vs. Corelight Open NDR and other solutions. Updated: September 2026.
915,341 professionals have used our research since 2012.