Skip to content

Commit 11d394e

Browse files
authored
Update near-real-time-rules.md
------- cc: @yelevin
1 parent 932f0da commit 11d394e

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

articles/sentinel/near-real-time-rules.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -50,7 +50,7 @@ The following limitations currently govern the use of NRT rules:
5050

5151
1. Queries can run only within a single workspace. There is no cross-workspace capability.
5252

53-
1. Event grouping is not configurable. NRT rules produce a single alert that groups all the applicable events.
53+
1. Event grouping is now configurable to a limited degree. NRT rules can produce up to 30 single-event alerts. A rule with a query that results in more than 30 events will produce alerts for the first 29, then a 30th alert that summarizes all the applicable events.
5454

5555
## Next steps
5656

0 commit comments

Comments
 (0)