Skip to content

Commit 0353993

Browse files
authored
Update sentinel-service-limits.md
1 parent 9371053 commit 0353993

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

articles/sentinel/sentinel-service-limits.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -23,8 +23,8 @@ The following limit applies to analytics rules in Microsoft Sentinel.
2323
| [Entity mappings](map-data-fields-to-entities.md) | 10 mappings per rule | None |
2424
| [Entities](map-data-fields-to-entities.md) identified per alert<br>(Divided equally among the mapped entities) | 500 entities per alert | None |
2525
| [Entities](map-data-fields-to-entities.md) cumulative size limit | 64 KB | None |
26-
| [Custom details](surface-custom-details-in-alerts.md) | 20 details per rule | None |
27-
| [Custom details](surface-custom-details-in-alerts.md) and [alert details](customize-alert-details.md)<br>combined cumulative size limit | 64 KB | None |
26+
| [Custom details](surface-custom-details-in-alerts.md) | 20 details per rule<br>50 values per detail<br>2 KB cumulative size | None |
27+
| [Alert details](customize-alert-details.md) | 50 values per overridden field<br>5 KB per field for `Description` and collections<br>256 bytes per field for `AlertName` and non-collections | None |
2828
| Alerts per rule<br>Applicable when *Event grouping* is set to *Trigger an alert for each event* | 150 alerts | None |
2929
| Alerts per rule for NRT rules | 30 alerts | None |
3030

0 commit comments

Comments
 (0)