Orca Security App (Public Preview)

The Orca Security App provides a structure for data collected from the Orca Security API.

Viewing Orca Security Data in Observe

Resource Sets

Installing the Orca app provides the following Datasets to use with your data:

Datasets

  • Orca Alert Events - This dataset contains Orca Raw Alerts.

  • Orca Alerts - This dataset contains Orca Shaped Alerts.

  • Orca Log Events - This dataset contains Orca Log Raw Events.

  • Orca Logs - This dataset contains Orca Asset Shaped Events.

  • Orca Asset Events - This dataset contains Orca Asset Raw Events.

Resource Sets

  • Orca Assets - This resource set contains Orca Asset Shaped Events.

Metrics Sets

  • Orca Alert Metrics - This dataset contains Orca Alert Metrics.

  • Orca Authentication Failure Metrics - This dataset contains Orca Log Authentication Failure Metrics.

  • Orca Authentication Success Metrics - This dataset contains Orca Log Authentication Success Metrics.

Dashboards

  • Orca/Orca Data Ingest Status - Displays ingest statistics Alerts, Logs and Asset events.

../../../_images/orca-dashboard-ingest.png

Figure 1 - Orca Data Ingest Status

  • Orca/Orca Alert and Log Data Summary - Displays basic statistics about Alerts and Logs.

../../../_images/orca-data-summary.png

Figure 2 - Orca Alert and Log Data Summary