Orca Security Alerts
by Orca Security, Inc.
This is Orca integration app - connecting between Azure and Orca Cloud Security platform
The Orca Security Alerts solution for Microsoft Sentinel enables you to ingest Orca Security Alerts into Microsoft Sentinel. Orca Security enables the detection and prioritization of cloud security risks through their agentless cloud security and compliance solution for AWS, Azure, Google Cloud, and Kubernetes.
Underlying Microsoft Technologies used:
This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:
- Azure Monitor Logs Ingestion API with Data Collection Rules (DCR) and Endpoints (DCE) - used by the recommended Microsoft Entra ID based connector.
- Azure Monitor HTTP Data Collector API - used by the legacy Shared Key based connector (deprecated by Microsoft; retained for backward compatibility).
Both connectors ingest alerts into the same OrcaAlerts_CL table. New deployments should use the Microsoft Entra ID based connector.
What’s new in version 3.0.1:
The Microsoft Entra ID based connector now ingests additional Orca alert attributes into the OrcaAlerts_CL table, enabling richer filtering, correlation, and routing in Microsoft Sentinel:
- Asset tags - custom_tags (user-defined Orca asset tags) and account_tags, alongside the existing cloud provider tags, so alerts can be filtered and routed by ownership, environment, or cost center.
- Alert context - alert_category, rule_id, rule_type, max_cvss_score, security_domains, related_compliances, and alert_ui_link (a direct link to the alert in the Orca platform).
- Alert timeline - created_at, last_seen, and last_updated timestamps for deduplication and aging logic.
- Asset and account context - asset_category, asset_labels, asset_regions, asset_vendor_id, asset_vpcs, resource_group_name, cloud_provider, account_id, and business_units.
The update is purely additive: existing columns, queries, and workbooks are unaffected. Existing deployments of the connector continue to work unchanged; to receive the new fields, redeploy the connector (or add the new columns to the existing custom table and DCR stream declaration as described in the release notes).
The Orca Security Alerts solution for Microsoft Sentinel enables you to ingest Orca Security Alerts into Microsoft Sentinel. Orca Security enables the detection and prioritization of cloud security risks through their agentless cloud security and compliance solution for AWS, Azure, Google Cloud, and Kubernetes.
Underlying Microsoft Technologies used:
This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:
- Azure Monitor Logs Ingestion API with Data Collection Rules (DCR) and Endpoints (DCE) - used by the recommended Microsoft Entra ID based connector.
- Azure Monitor HTTP Data Collector API - used by the legacy Shared Key based connector (deprecated by Microsoft; retained for backward compatibility).
Both connectors ingest alerts into the same OrcaAlerts_CL table. New deployments should use the Microsoft Entra ID based connector.
What’s new in version 3.0.1:
The Microsoft Entra ID based connector now ingests additional Orca alert attributes into the OrcaAlerts_CL table, enabling richer filtering, correlation, and routing in Microsoft Sentinel:
- Asset tags - custom_tags (user-defined Orca asset tags) and account_tags, alongside the existing cloud provider tags, so alerts can be filtered and routed by ownership, environment, or cost center.
- Alert context - alert_category, rule_id, rule_type, max_cvss_score, security_domains, related_compliances, and alert_ui_link (a direct link to the alert in the Orca platform).
- Alert timeline - created_at, last_seen, and last_updated timestamps for deduplication and aging logic.
- Asset and account context - asset_category, asset_labels, asset_regions, asset_vendor_id, asset_vpcs, resource_group_name, cloud_provider, account_id, and business_units.