DOCA Argus Runtime Security Operations
Deploy Argus on BlueField to detect runtime threats and forward findings to an existing SIEM.
The skill clearly scopes BlueField, Argus, and SIEM use, forbids silent detector disabling, and requires calibration. However, least privilege, user confirmation, credential handling, data-flow detail, and rollback are not concretely specified; reliance on external SIEM and host observation warrants deductions.
It provides a layered failure model, version checks, and failure-oriented workflows. Yet image names, configuration keys, commands, and log formats are delegated to an external public guide, with no executable test suite supplied; static evidence does not justify a higher score.
Audience, trigger phrases, supported scenarios, and exclusions are relatively clear. Chinese-language support is absent, and deployment depends on NGC, public documentation, and an external SIEM whose mainland-China reachability is not addressed, so points are deducted.
The material is well layered and includes loading order, tasks, limitations, version guidance, and related skills. However, license metadata is inconsistent, author/version/signature fields are missing or TBD, recommended sections are absent, paths conflict with the benchmark report, and maintenance ownership is unclear.
It supplies configuration decisions, deployment sequencing, and diagnostic structure, but intentionally omits image tags, configuration examples, SIEM configurations, and complete commands. Users must consult external guidance and fill substantial gaps, limiting static effectiveness.
The files cite a public guide and include a benchmark report, but the evaluation dataset is unavailable and there is no reproducible test suite, CI coverage, or independent corroboration. Only limited auditability is supported.
- Do not treat the benchmark PASS or NVIDIA provenance as a substitute for evidence of this skill's actual reliability or safety; the report says the evaluation dataset was unavailable.
- Before deployment, verify the matching DOCA/container version, public guide, configuration schema, image source, credential scope, and SIEM reachability; these critical facts are not fully contained in the skill files.
- The skill provides no Chinese-language operational material and does not establish availability of NGC, public documentation, or SIEM services from mainland-China networks.
What does this skill do, and when should you use it?
This skill supports security operators and platform teams running the DOCA Argus Service container on BlueField Arm. It guides decisions across detection policy, forwarding, sampling, and host coverage, then helps validate the full path from finding emission to SIEM review. Argus observes the BlueField and attached host for suspicious activity, integrity violations, and operational anomalies. It assumes DOCA is already installed and does not cover DOCA installation or custom security-tool development against a lower-level library.
Guides operators in obtaining and starting the Argus container from NVIDIA NGC on BlueField Arm; selecting detection policy, local or SIEM forwarding, sampling sensitivity, and host coverage; inspecting container logs and the documented finding feed; validating delivery through a forwarder into Splunk, ELK, Sentinel, or syslog; and diagnosing missing findings, excessive findings, forwarding failures, and performance impact.
- A security operations team needs runtime security for production BlueField-3 hosts.
- A platform team has a healthy Argus container but no findings have reached its SIEM for 24 hours.
- Security analysts are receiving a noisy stream of findings and need to tune policy or sampling.
- An enterprise needs to connect Argus findings to an existing Splunk, ELK, Sentinel, or syslog workflow.
- An operator needs to complete smoke testing and a calibration period before trusting the channel for production decisions.
What are this skill's strengths and limitations?
- Covers the four central configuration axes: detection, forwarding, sampling, and host coverage.
- Addresses end-to-end validation from the Argus container to the security operations surface.
- Clearly separates the Argus service from the lower-level App Shield library.
- Includes guidance for missing findings, noisy findings, forwarding problems, and performance impact.
- Promotes calibration and explicitly avoids silently disabling findings.
- Provides guidance rather than copy-ready production configs, image tags, detection-rule packs, or SIEM ingest definitions.
- Requires BlueField Arm, an installed DOCA environment, NGC access, and the BlueField OS container runtime.
- Does not install DOCA and is not intended for metrics observability or custom security-program development.
- The supplied material does not establish support or testing for particular hardware models, DOCA versions, or deployments.
How do you install this skill?
Install the skill with the NVIDIA skills CLI: npx skills add nvidia/skills --skill doca-argus --yes. This installs the guidance only; the Argus container still must be deployed on a properly prepared BlueField Arm environment from NVIDIA NGC.
How do you use this skill?
After installation, use a task-specific prompt such as: “The Argus container on BlueField is healthy, but no findings are arriving in Splunk. Help me troubleshoot it layer by layer.” Use this skill for Argus configuration, operation, testing, and debugging after DOCA is installed. DOCA installation, detailed SIEM-side ingest configuration, and custom App Shield tool development are out of scope.
How does this skill compare with similar options?
Compared with the older DOCA App Shield library, Argus is a packaged service container for production runtime-security operations; App Shield is a lower-level library for building custom DPU-side security tooling and is outside this bundle. Compared with DOCA Telemetry, Argus focuses on runtime-security findings, while Telemetry addresses metrics observability.