↳ GitHub sourceSolution

Orca Security Alerts

Description

The [Orca Security Alerts](https://orca.security/) solution for Microsoft Sentinel enables you to ingest Orca Security Alerts into Microsoft Sentinel. Orca Security enables the detection and prioritization of cloud security risks through their agentless cloud security and compliance solution for AWS, Azure, Google Cloud, and Kubernetes. **Underlying Microsoft Technologies used:** This solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs: a. [Azure Monitor Logs Ingestion API](https://learn.microsoft.com/azure/azure-monitor/logs/logs-ingestion-api-overview) with [Data Collection Rules (DCR) and Endpoints (DCE)](https://learn.microsoft.com/azure/azure-monitor/essentials/data-collection-rule-overview) - used by the recommended Microsoft Entra ID based connector. b. [Azure Monitor HTTP Data Collector API](https://docs.microsoft.com/azure/azure-monitor/logs/data-collector-api) - used by the legacy Shared Key based connector (deprecated by Microsoft; retained for backward compatibility). Both connectors ingest alerts into the same OrcaAlerts_CL table. New deployments should use the Microsoft Entra ID based connector.
Version
3.0.1
Declared author / publisher
Orca Security
Support tier
Partner

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
orca_security_alerts_mss
Additional source files 2Solutions/Orca Security Alerts/Data/Solution_Orca Security Alerts.jsonsolution-manifest ↗Solutions/Orca Security Alerts/SolutionMetadata.jsonsolution-metadata ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.