Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Publisher | Orca Security |
| Support Tier | Partner |
| Support Link | https://orca.security/about/contact/ |
| Categories | Security - Threat Protection,Security - Cloud Security |
| Version | 3.0.0 |
| Author | Orca Security |
| First Published | 2022-05-10 |
| Solution Folder | Orca Security Alerts |
| Marketplace | Azure Marketplace · Popularity: 🔵 Medium (58%) |
The Orca Security Alerts solution for Microsoft Sentinel enables you to ingest Orca Security Alerts into Microsoft Sentinel. Orca Security enables the detection and prioritization of cloud security risks through their agentless cloud security and compliance solution for AWS, Azure, Google Cloud, and Kubernetes.
Underlying Microsoft Technologies used:
This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:
a. Azure Monitor Logs Ingestion API with Data Collection Rules (DCR) and Endpoints (DCE) - used by the recommended Microsoft Entra ID based connector.
b. Azure Monitor HTTP Data Collector API - used by the legacy Shared Key based connector (deprecated by Microsoft; retained for backward compatibility).
Both connectors ingest alerts into the same OrcaAlerts_CL table. New deployments should use the Microsoft Entra ID based connector.
This solution provides 2 data connector(s):
This solution uses 1 table(s):
| Table | Used By Connectors | Used By Content |
|---|---|---|
OrcaAlerts_CL |
Orca Security Alerts, Orca Security Alerts (via Microsoft Entra ID) | Workbooks |
This solution includes 1 content item(s):
| Content Type | Count |
|---|---|
| Workbooks | 1 |
| Name | Tables Used |
|---|---|
| OrcaAlerts | OrcaAlerts_CL |
| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.0.0 | 23-06-2026 | Added Orca Security Alerts data connector using Microsoft Entra ID authentication (Push CCF connector with DCR/DCE and the Azure Monitor Logs Ingestion API). Updated the connector logo. The legacy Shared Key based connector is retained for backward compatibility and both connectors ingest into the same OrcaAlerts_CL table. |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊