You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/whats-new.md
+4-2Lines changed: 4 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -35,11 +35,13 @@ See these [important announcements](#announcements) about recent changes to feat
35
35
### Higher limits for entities in alerts and entity mappings in analytics rules
36
36
37
37
The following limits on entities in alerts and entity mappings in analytics rules have been raised:
38
-
- You can now map**up to ten entities** in an analytics rule (up from five).
38
+
- You can now define**up to ten entity mappings** in an analytics rule (up from five).
39
39
- A single alert can now contain **up to 500 identified entities** in total, divided equally amongst the mapped entities.
40
40
- The *Entities* field in the alert has a **size limit of 64 KB**. (This size limit previously applied to the entire alert record.)
41
41
42
-
For a full description of these limits, see [Map data fields to entities in Microsoft Sentinel](map-data-fields-to-entities.md).
42
+
Learn more about entity mapping, and see a full description of these limits, in [Map data fields to entities in Microsoft Sentinel](map-data-fields-to-entities.md).
43
+
44
+
Learn about other [service limits in Microsoft Sentinel](sentinel-service-limits.md).
43
45
44
46
### Content Hub generally available and centralization changes released
0 commit comments