Integrate Orca Security
You can integrate Orca Security with Sophos XDR so that it sends data to Sophos for analysis.
Key steps
The key steps in an Orca Security integration are as follows:
- Get an API key and base URL from Orca Security.
- Configure the integration in Sophos XDR.
Requirements
The following is required for Orca Security configuration:
- An administrator account in Orca Security with the same rights that are needed to perform the API's actions. The API key inherits its user role and permissions from the signed-in admin.
Add an Orca Security integration
To integrate Orca Security, you must first gather certain details from Orca Security, then provide them in Sophos XDR.
Get an API key and base URL
To get the Orca Security API details you need for integration, do as follows:
- Sign in to Orca Security.
- In the Orca dashboard, go to Settings > Modules.
- Select the Integrations tab.
- Click Generate Key.
- Copy and save the API key.
- In the Swagger tile, click View.
- Make a note of the Base URL at the top of the page. For example,
https://app.us.orcasecurity.io.
Next, you configure an integration in Sophos XDR.
Configure the integration in Sophos XDR
To integrate Orca Security with Sophos XDR, do as follows:
- In Sophos Fusion, go to Security Operations > Integrations > Marketplace.
-
Click Orca Security.
The Orca Security page opens. You can configure integrations here and see a list of any you've already configured.
-
In Configured integrations, click Add new.
-
In Add an integration, do as follows:
- Enter a name for the integration.
- Enter the Base URL and the API Key that you got from Orca Security.
-
Click Done.
The new integration appears under Configured integrations. If its status icon is a green tick, your data should appear in the Sophos Data Lake after validation.
Additional resources
For more information on configuring Orca Security, see the following documents: