Skip to content

Commit 41137d5

Browse files
committed
Learn Editor: Update map-data-fields-to-entities.md
1 parent f72ffe0 commit 41137d5

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

articles/sentinel/map-data-fields-to-entities.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -52,7 +52,7 @@ The procedure detailed below is part of the analytics rule creation wizard. It's
5252
> - ***Up to 500 entities collectively* can be identified in a single alert, divided equally across all entity mappings defined in the rule**.
5353
> - For example, if two entity mappings are defined in the rule, each mapping can identify up to 250 entities; if five mappings are defined, each one can identify 100 entities, and so on.
5454
> - Multiple mappings of a single entity type (say, source IP and destination IP) each count separately.
55-
> - If an alert contains items in excess of this limit, those excess items will not be recognized and extracted as entities. Because of the internal logic of the entity extraction engine, ...
55+
> - If an alert contains items in excess of this limit, those excess items will not be recognized and extracted as entities.
5656
>
5757
> - **The size limit for the entire *entities* field of an alert is *64 KB***.
5858
> - *Entities* fields that grow larger than 64 KB will be truncated. As entities are identified, they are added to the alert one by one until the field size reaches 64 KB, and any entities yet unidentified are dropped from the alert.
@@ -70,3 +70,4 @@ In this document, you learned how to map data fields to entities in Microsoft Se
7070
- Get the complete picture on [scheduled query analytics rules](detect-threats-custom.md).
7171
- Learn more about [entities in Microsoft Sentinel](entities.md).
7272

73+

0 commit comments

Comments
 (0)