Пропустить и перейти к основному содержимому
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/orcasecurityinc1621870991703.orca_security_alerts_mss-f1a32d32-3407-4c2d-a163-801cd9bb706f/image2_orcaa.png

Orca Security Alerts

Автор: Orca Security, Inc.

This is Orca integration app - connecting between Azure and Orca Cloud Security platform

Who this solution is for

The Orca Security Alerts solution for Microsoft Sentinel is intended for security operations (SOC) teams, security analysts, and cloud security engineers who use Microsoft Sentinel as their SIEM and want to bring Orca Security findings into their centralized detection and response workflows. It requires an active Orca Security subscription.

What it does and why it's valuable

Orca Security is an agentless cloud security platform that detects and prioritizes risks — vulnerabilities, malware, misconfigurations, and compliance issues — across AWS, Azure, Google Cloud, and Kubernetes environments. This solution streams Orca Security alerts into your Microsoft Sentinel workspace as they are created and updated, so your SOC can triage, correlate, and respond to cloud security risks alongside all other security signals in one place, without deploying agents or building custom ingestion pipelines.

Data connectors included

  1. Orca Security Alerts (via Microsoft Entra ID) — recommended. A push connector built on the Azure Monitor Logs Ingestion API with Data Collection Rules (DCR) and Data Collection Endpoints (DCE), authenticated through a Microsoft Entra ID application.
  2. Orca Security Alerts (legacy, Shared Key) — based on the Azure Monitor HTTP Data Collector API, retained for backward compatibility with existing deployments.

Both connectors ingest alerts into the same OrcaAlerts_CL custom table, so existing queries and workbooks continue to work when you migrate from the legacy connector.

Solution content: Data Connectors: 2 | Workbooks: 1 (Orca Alerts — visual insights into your ingested Orca Security alerts)

Supported Microsoft products and technologies

  • Microsoft Sentinel
  • Azure Monitor / Log Analytics, including the Logs Ingestion API with Data Collection Rules and Endpoints (recommended connector) and the HTTP Data Collector API (legacy connector)
  • Microsoft Entra ID (application-based authentication for the recommended connector)

Prerequisites

  • An active Orca Security subscription with permission to configure integrations in the Orca platform
  • A Microsoft Sentinel–enabled Log Analytics workspace
  • For the recommended connector: permissions to create a Microsoft Entra ID application registration and Data Collection Rules/Endpoints in your Azure subscription
  • Data ingestion into the Log Analytics workspace is billed per standard Azure Monitor pricing

Limitations and conditions

  • The solution ingests Orca Security alerts only; it does not ingest full asset inventory or other Orca platform data.
  • The legacy Shared Key connector depends on the Azure Monitor HTTP Data Collector API, which Microsoft has deprecated; it is provided for backward compatibility only, and new deployments should use the Microsoft Entra ID based connector.
  • Alert delivery requires the corresponding integration to be configured on the Orca Security side.

For the full change history, see the Release Notes. Learn more about Microsoft Sentinel.

Русский (Казахстан)
Значок отказа для ваших вариантов выбора параметров конфиденциальности Ваши варианты выбора параметров конфиденциальности
Конфиденциальность медицинских сведений потребителей Sitemap Contact Us Privacy & Cookies Terms of Use Trademarks About our ads Manage cookies