{
  "Name": "Orca Security Alerts",
  "Author": "Orca Security",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/OrcaSecurityLogo.svg\" width=\"75px\" height=\"75px\">",
  "Description": "The [Orca Security Alerts](https://orca.security/) solution for Microsoft Sentinel enables you to ingest Orca Security Alerts into Microsoft Sentinel. Orca Security enables the detection and prioritization of cloud security risks through their agentless cloud security and compliance solution for AWS, Azure, Google Cloud, and Kubernetes.\n\n**Underlying Microsoft Technologies used:**\n\nThis solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs:\n\na. [Azure Monitor Logs Ingestion API](https://learn.microsoft.com/azure/azure-monitor/logs/logs-ingestion-api-overview) with [Data Collection Rules (DCR) and Endpoints (DCE)](https://learn.microsoft.com/azure/azure-monitor/essentials/data-collection-rule-overview) - used by the recommended Microsoft Entra ID based connector.\n\nb. [Azure Monitor HTTP Data Collector API](https://docs.microsoft.com/azure/azure-monitor/logs/data-collector-api) - used by the legacy Shared Key based connector (deprecated by Microsoft; retained for backward compatibility).\n\nBoth connectors ingest alerts into the same OrcaAlerts_CL table. New deployments should use the Microsoft Entra ID based connector.",
  "WorkbookDescription": "The workbook installed with the Orca Security Alerts solution provide insights into login failures, application activities and network applications. After installing the solution, start using the workbook in Manage solution view.",
  "Data Connectors": [
    "Data Connectors/OrcaSecurityAlerts.json",
    "Data Connectors/OrcaSecurityAlertsCCF/OrcaSecurityAlerts_ConnectorDefinition.json"
  ],
  "Workbooks": [
    "Workbooks/OrcaAlerts.json"
  ],
  "Metadata": "SolutionMetadata.json",
  "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\Orca Security Alerts",
  "Version": "3.0.1",
  "TemplateSpec": true,
  "Is1PConnector": false,
  "StaticDataConnectorIds": []
}
