Skip to content

Commit d79110a

Browse files
committed
Learn Editor: Update map-data-fields-to-entities.md
1 parent 44e2c34 commit d79110a

File tree

1 file changed

+3
-2
lines changed

1 file changed

+3
-2
lines changed

articles/sentinel/map-data-fields-to-entities.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -50,11 +50,11 @@ The procedure detailed below is part of the analytics rule creation wizard. It's
5050

5151
> [!NOTE]
5252
> - ***Up to 500 entities collectively* can be identified in a single alert, divided equally across all entity mappings defined in the rule**.
53-
> - For example, if two entity mappings are defined in the rule, each mapping can identify up to 250 entities; if five mappings are defined, each one can identify 100 entities, and so on.
53+
> - For example, if two entity mappings are defined in the rule, each mapping can identify up to 250 entities; if five mappings are defined, each one can identify up to 100 entities, and so on.
5454
> - Multiple mappings of a single entity type (say, source IP and destination IP) each count separately.
5555
> - If an alert contains items in excess of this limit, those excess items will not be recognized and extracted as entities.
5656
>
57-
> - **The size limit for the entire *entities* field of an alert is *64 KB***.
57+
> - **The size limit for the entire *entities* area of an alert (the *Entities* field) is *64 KB***.
5858
> - *Entities* fields that grow larger than 64 KB will be truncated. As entities are identified, they are added to the alert one by one until the field size reaches 64 KB, and any entities yet unidentified are dropped from the alert.
5959
6060
## Notes on the new version
@@ -71,3 +71,4 @@ In this document, you learned how to map data fields to entities in Microsoft Se
7171
- Learn more about [entities in Microsoft Sentinel](entities.md).
7272

7373

74+

0 commit comments

Comments
 (0)