File tree Expand file tree Collapse file tree 1 file changed +4
-1
lines changed
articles/sentinel/includes Expand file tree Collapse file tree 1 file changed +4
-1
lines changed Original file line number Diff line number Diff line change @@ -16,7 +16,10 @@ The following limit applies to analytics rules in Microsoft Sentinel.
1616| --------- | --------- | --------- |
1717| Number of * enabled* rules | 512 rules | None |
1818| Number of near-real-time (NRT) rules | 50 NRT rules | None |
19+ | Entity mappings | 10 mappings per rule | None |
20+ | Entities identified per alert<br >(Divided equally among the mapped entities) | 500 entities per alert | None |
21+ | Entities cumulative size limit | 64 KB | None |
1922| Custom details | 20 details per rule | None |
2023| Custom details cumulative size limit | 2 KB | None |
2124| Alerts per rule<br >Applicable when * Event grouping* is set to * Trigger an alert for each event* | 150 alerts | None |
22- | Alerts per rule for NRT rules | 30 alerts | None |
25+ | Alerts per rule for NRT rules | 30 alerts | None |
You can’t perform that action at this time.
0 commit comments