Skip to content

Commit 9113fd5

Browse files
authored
Merge pull request #194918 from cwatson-cat/4-12-22-srv-lmts
Sentinel - service limits
2 parents 5ec25a0 + 4d05dc5 commit 9113fd5

9 files changed

+184
-0
lines changed

articles/sentinel/TOC.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -350,6 +350,8 @@
350350
href: sap-deploy-troubleshoot.md
351351
- name: Reference
352352
items:
353+
- name: Service limits
354+
href: sentinel-service-limits.md
353355
- name: Microsoft Sentinel REST-API
354356
href: /rest/api/securityinsights/
355357
- name: Management references
Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
---
2+
title: Microsoft Sentinel service limits
3+
description: This article provides a list of service limits for Microsoft Sentinel.
4+
author: yelevin
5+
ms.topic: conceptual
6+
ms.date: 04/27/2022
7+
ms.author: yelevin
8+
---
9+
10+
# Service limits for Microsoft Sentinel
11+
12+
This article lists the most common service limits you might encounter as you use Microsoft Sentinel. For other limits that might impact services or features you use, see [Azure subscription and service limits, quotas, and constraints](../azure-resource-manager/management/azure-subscription-service-limits.md).
13+
14+
## Analytics rule limits
15+
16+
[!INCLUDE [sentinel-service-limits](../../includes/sentinel-limits-analytics-rules.md)]
17+
18+
## Incident limits
19+
20+
[!INCLUDE [sentinel-service-limits](../../includes/sentinel-limits-incidents.md)]
21+
22+
## Machine learning-based limits
23+
24+
[!INCLUDE [sentinel-service-limits](../../includes/sentinel-limits-machine-learning.md)]
25+
26+
## Notebook limits
27+
28+
[!INCLUDE [sentinel-service-limits](../../includes/sentinel-limits-notebooks.md)]
29+
30+
## Threat intelligence limits
31+
32+
[!INCLUDE [sentinel-service-limits](../../includes/sentinel-limits-threat-intelligence.md)]
33+
34+
## Watchlist limits
35+
36+
[!INCLUDE [sentinel-service-limits](../../includes/sentinel-limits-watchlists.md)]
37+
38+
## User and Entity Behavior Analytics (UEBA) limits
39+
40+
[!INCLUDE [sentinel-service-limits](../../includes/sentinel-limits-ueba.md)]
41+
42+
## Next steps
43+
44+
[Azure subscription and service limits, quotas, and constraints](../azure-resource-manager/management/azure-subscription-service-limits.md)
Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
---
2+
title: "include file"
3+
description: "include file"
4+
services: microsoft-sentinel
5+
author: cwatson-cat
6+
tags: azure-service-management
7+
ms.topic: "include"
8+
ms.date: 04/27/2022
9+
ms.author: cwatson
10+
ms.custom: "include file"
11+
---
12+
13+
The following limit applies to analytics rules in Microsoft Sentinel.
14+
15+
|Description |Limit |Dependency|
16+
|---------|---------|---------|
17+
|Number of rules | 512 rules |None|
18+

includes/sentinel-limits-incidents.md

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
---
2+
title: "include file"
3+
description: "include file"
4+
services: microsoft-sentinel
5+
author: cwatson-cat
6+
tags: azure-service-management
7+
ms.topic: "include"
8+
ms.date: 04/27/2022
9+
ms.author: cwatson
10+
ms.custom: "include file"
11+
---
12+
13+
The following limits apply to incidents in Microsoft Sentinel.
14+
15+
|Description |Limit |Dependency|
16+
|---------|---------|-------|
17+
|Investigation experience availability | 90 days from the incident last update time |None|
18+
|Number of automation rules | 512 rules |None|
19+
|Number of actions | 20 actions |None|
20+
|Number of characters per comment | 30 K characters |None|
21+
|Number of comments per incident | 100 comments |None|
22+
|Number of conditions | 50 conditions |None|
Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
---
2+
title: "include file"
3+
description: "include file"
4+
services: microsoft-sentinel
5+
author: cwatson-cat
6+
tags: azure-service-management
7+
ms.topic: "include"
8+
ms.date: 04/27/2022
9+
ms.author: cwatson
10+
ms.custom: "include file"
11+
---
12+
13+
The following limits apply to machine learning-based features in Microsoft Sentinel like customizable anomalies and Fusion.
14+
15+
| Description | Limit |Dependency|
16+
|---------------------------------------------------------------|-------------------------------------------------|-------|
17+
| Number of anomalies published per anomaly type | Top 3000 ranked by anomaly score |None|
18+
| Number of alerts and/or anomalies in a single Fusion incident | 100 alerts and/or anomalies |None|

includes/sentinel-limits-notebooks.md

Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
---
2+
title: "include file"
3+
description: "include file"
4+
services: microsoft-sentinel
5+
author: cwatson-cat
6+
tags: azure-service-management
7+
ms.topic: "include"
8+
ms.date: 04/27/2022
9+
ms.author: cwatson
10+
ms.custom: "include file"
11+
---
12+
13+
The following limits apply to notebooks in Microsoft Sentinel. The limits are related to the dependencies on other services used by notebooks.
14+
15+
|Description|Limit |Dependency|
16+
|-------|-------|-------|
17+
| Total count of these assets per machine learning workspace: datasets, runs, models, and artifacts |10 million assets |Azure Machine Learning|
18+
| Default limit for total compute clusters per region. Limit is shared between a training cluster and a compute instance. A compute instance is considered a single-node cluster for quota purposes. | 200 compute clusters per region|Azure Machine Learning|
19+
|Storage accounts per region per subscription|250 storage accounts|Azure Storage|
20+
|Maximum size of a file share by default|5 TB|Azure Storage|
21+
|Maximum size of a file share with large file share feature enabled|100 TB|Azure Storage|
22+
|Maximum throughput (ingress + egress) for a single file share by default|60 MB/sec|Azure Storage|
23+
|Maximum throughput (ingress + egress) for a single file share with large file share feature enabled|300 MB/sec|Azure Storage|
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
---
2+
title: "include file"
3+
description: "include file"
4+
services: microsoft-sentinel
5+
author: cwatson-cat
6+
tags: azure-service-management
7+
ms.topic: "include"
8+
ms.date: 04/27/2022
9+
ms.author: cwatson
10+
ms.custom: "include file"
11+
---
12+
13+
The following limit applies to threat intelligence in Microsoft Sentinel. The limit is related to the dependency on an API used by threat intelligence.
14+
15+
|Description | Limit |Dependency|
16+
-------------------------|--------------------|--------------------|
17+
| Indicators per call that use Graph security API | 100 indicators |Microsoft Graph security API|

includes/sentinel-limits-ueba.md

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
---
2+
title: "include file"
3+
description: "include file"
4+
services: microsoft-sentinel
5+
author: cwatson-cat
6+
tags: azure-service-management
7+
ms.topic: "include"
8+
ms.date: 04/27/2022
9+
ms.author: cwatson
10+
ms.custom: "include file"
11+
---
12+
13+
The following limit applies to UEBA in Microsoft Sentinel. The limit for UEBA in Microsoft Sentinel is related to dependencies on another service.
14+
15+
|Description |Limit |Dependency|
16+
|---------|---------|---------|
17+
|Lowest retention configuration in days for the [IdentityInfo](/azure/azure-monitor/reference/tables/identityinfo) table. All data stored on the IdentityInfo table in Log Analytics is refreshed every 14 days. | 14 days |Log Analytics|
Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
---
2+
title: "include file"
3+
description: "include file"
4+
services: microsoft-sentinel
5+
author: cwatson-cat
6+
tags: azure-service-management
7+
ms.topic: "include"
8+
ms.date: 04/27/2022
9+
ms.author: cwatson
10+
ms.custom: "include file"
11+
---
12+
13+
The following limits apply to watchlists in Microsoft Sentinel. The limits are related to the dependencies on other services used by watchlists.
14+
15+
|Description | Limit |Dependency|
16+
|--|-------------------------|--------------------|
17+
|Upload size for local file| 3.8 MB per file |Azure Resource Manager
18+
|Line entry in the CSV file |10,240 characters per line|Azure Resource Manager|
19+
|Upload size for files in Azure Storage |500 MB per file|Azure Storage|
20+
|Total number of active watchlist items per workspace. When the max count is reached, delete some existing items to add a new watchlist.|10 million active watchlist items|Log Analytics|
21+
|Refresh of the status for a large watchlist in seconds. Customers won't see the latest progress of an upload until the next refresh.|15 seconds|Azure Cosmos DB|
22+
|Number of large watchlist uploads per workspace at a time|One large watchlist|Azure Cosmos DB|
23+
|Number of large watchlist deletions per workspace at a time|One large watchlist|Azure Cosmos DB|

0 commit comments

Comments
 (0)