File tree Expand file tree Collapse file tree 1 file changed +4
-1
lines changed
articles/sentinel/includes Expand file tree Collapse file tree 1 file changed +4
-1
lines changed Original file line number Diff line number Diff line change @@ -16,7 +16,10 @@ The following limit applies to analytics rules in Microsoft Sentinel.
16
16
| --------- | --------- | --------- |
17
17
| Number of * enabled* rules | 512 rules | None |
18
18
| Number of near-real-time (NRT) rules | 50 NRT rules | None |
19
+ | Entity mappings | 10 mappings per rule | None |
20
+ | Entities identified per alert<br >(Divided equally among the mapped entities) | 500 entities per alert | None |
21
+ | Entities cumulative size limit | 64 KB | None |
19
22
| Custom details | 20 details per rule | None |
20
23
| Custom details cumulative size limit | 2 KB | None |
21
24
| Alerts per rule<br >Applicable when * Event grouping* is set to * Trigger an alert for each event* | 150 alerts | None |
22
- | Alerts per rule for NRT rules | 30 alerts | None |
25
+ | Alerts per rule for NRT rules | 30 alerts | None |
You can’t perform that action at this time.
0 commit comments