Skip to content

Commit 8a51b37

Browse files
authored
Update near-real-time-rules.md
------- cc: @yelevin
1 parent 9ed7951 commit 8a51b37

File tree

1 file changed

+4
-0
lines changed

1 file changed

+4
-0
lines changed

articles/sentinel/near-real-time-rules.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -34,6 +34,10 @@ The following limitations currently govern the use of NRT rules:
3434

3535
1. No more than 20 rules can be defined per customer at this time.
3636

37+
1. By design, NRT rules will only work properly on log sources with an **ingestion delay of less than 12 hours**.
38+
39+
(Since the NRT rule type is supposed to approximate **real-time** data ingestion, it doesn't afford you any advantage to use NRT rules on log sources with significant ingestion delay, even if it's far less than 12 hours.)
40+
3741
1. As this type of rule is new, its syntax is currently limited but will gradually evolve. Therefore, at this time the following restrictions are in effect:
3842

3943
1. The query defined in an NRT rule can reference **only one table**. Queries can, however, refer to multiple watchlists and to threat intelligence feeds.

0 commit comments

Comments
 (0)