@@ -20,11 +20,11 @@ The following limit applies to analytics rules in Microsoft Sentinel.
20
20
| --------- | --------- | --------- |
21
21
| Number of * enabled* rules | 512 rules | None |
22
22
| Number of near-real-time (NRT) rules | 50 NRT rules | None |
23
- | [ Entity mappings] ( ../ map-data-fields-to-entities.md) | 10 mappings per rule | None |
24
- | [ Entities] ( ../ map-data-fields-to-entities.md) identified per alert<br >(Divided equally among the mapped entities) | 500 entities per alert | None |
25
- | [ Entities] ( ../ map-data-fields-to-entities.md) cumulative size limit | 64 KB | None |
26
- | [ Custom details] ( ../ surface-custom-details-in-alerts.md) | 20 details per rule | None |
27
- | [ Custom details] ( ../ surface-custom-details-in-alerts.md) and [ alert details] ( ../ customize-alert-details.md) <br >combined cumulative size limit | 64 KB | None |
23
+ | [ Entity mappings] ( map-data-fields-to-entities.md ) | 10 mappings per rule | None |
24
+ | [ Entities] ( map-data-fields-to-entities.md ) identified per alert<br >(Divided equally among the mapped entities) | 500 entities per alert | None |
25
+ | [ Entities] ( map-data-fields-to-entities.md ) cumulative size limit | 64 KB | None |
26
+ | [ Custom details] ( surface-custom-details-in-alerts.md ) | 20 details per rule | None |
27
+ | [ Custom details] ( surface-custom-details-in-alerts.md ) and [ alert details] ( customize-alert-details.md ) <br >combined cumulative size limit | 64 KB | None |
28
28
| Alerts per rule<br >Applicable when * Event grouping* is set to * Trigger an alert for each event* | 150 alerts | None |
29
29
| Alerts per rule for NRT rules | 30 alerts | None |
30
30
@@ -77,7 +77,7 @@ The following limit applies to multiple workspaces in Microsoft Sentinel. Limits
77
77
| Description | Limit | Dependency|
78
78
-------------------------|--------------------|--------------------|
79
79
| Incident view | 100 concurrently displayed workspaces | |
80
- | Log query | 100 Sentinel workspaces | [ Log Analytics] ( ../../ azure-monitor/logs/cross-workspace-query.md#limitations ) |
80
+ | Log query | 100 Sentinel workspaces | [ Log Analytics] ( ../azure-monitor/logs/cross-workspace-query.md#limitations ) |
81
81
| Analytics rules | 20 Sentinel workspaces per query | |
82
82
83
83
## Notebook limits
0 commit comments