Microsoft Sentinel service limits (2024)

  • Article

This article lists the most common service limits you might encounter as you use Microsoft Sentinel. For other limits that might impact services or features you use, like Azure Monitor, see Azure subscription and service limits, quotas, and constraints.

Analytics rule limits

The following limit applies to analytics rules in Microsoft Sentinel.

DescriptionLimitDependency
Number of enabled rules512 rulesNone
Number of near-real-time (NRT) rules50 NRT rulesNone
Entity mappings10 mappings per ruleNone
Entities identified per alert
(Divided equally among the mapped entities)
500 entities per alertNone
Entities cumulative size limit64 KBNone
Custom details20 details per rule
50 values per detail
2 KB cumulative size
None
Alert details50 values per overridden field
5 KB per field for Description and collections
256 bytes per field for AlertName and non-collections
None
Alerts per rule
Applicable when Event grouping is set to Trigger an alert for each event
150 alertsNone
Alerts per rule for NRT rules30 alertsNone

Hunts limits

The following limits apply to Hunts in Microsoft Sentinel.

DescriptionLimitDependency
Number of Hunts100None

Incident limits

The following limits apply to incidents in Microsoft Sentinel.

DescriptionLimitDependency
Investigation experience availability90 days from the incident last update timeNone
Number of alerts150 alertsNone
Number of automation rules512 rulesNone
Number of automation rule actions20 actionsNone
Number of automation rule conditions50 conditionsNone
Number of bookmarks20 bookmarksNone
Number of characters for automation rule name500 charactersNone
Number of characters for description5,000 charactersNone
Number of characters per comment30,000 charactersNone
Number of comments per incident100 commentsNone
Number of tasks40 tasksNone
Number of incidents returned by API to list request1,000 incidents maximumNone
Number of incidents per day (per workspace)See explanation after tableDatabase capacity

Number of incidents per day: There isn't a formal, hard limit on the number of incidents that can be created per day. A workspace's actual capacity for incidents depends on the storage capacity of the incident database, so the size of the incidents is as much a factor as their number.

However, a SOC that experiences the creation of more than around 3,000 new incidents per day will most likely find itself unable to keep up, and the database capacity will quickly be reached. In this situation, the SOC needs to find and fix any rules that create large numbers of incidents, to get the count of daily new incidents to manageable levels.

Machine learning-based limits

The following limits apply to machine learning-based features in Microsoft Sentinel like customizable anomalies and Fusion.

DescriptionLimitDependency
Number of anomalies published per anomaly typeTop 3000 ranked by anomaly scoreNone
Number of alerts and/or anomalies in a single Fusion incident100 alerts and/or anomaliesNone

Multi workspace limits

The following limit applies to multiple workspaces in Microsoft Sentinel. Limits here are applied when working with Sentinel features across more than workspace at a time.

DescriptionLimitDependency
Incident view100 concurrently displayed workspaces
Log query100 Sentinel workspacesLog Analytics
Analytics rules20 Sentinel workspaces per query

Notebook limits

The following limits apply to notebooks in Microsoft Sentinel. The limits are related to the dependencies on other services used by notebooks.

DescriptionLimitDependency
Total count of these assets per machine learning workspace: datasets, runs, models, and artifacts10 million assetsAzure Machine Learning
Default limit for total compute clusters per region. Limit is shared between a training cluster and a compute instance. A compute instance is considered a single-node cluster for quota purposes.200 compute clusters per regionAzure Machine Learning
Storage accounts per region per subscription250 storage accountsAzure Storage
Maximum size of a file share by default5 TBAzure Storage
Maximum size of a file share with large file share feature enabled100 TBAzure Storage
Maximum throughput (ingress + egress) for a single file share by default60 MB/secAzure Storage
Maximum throughput (ingress + egress) for a single file share with large file share feature enabled300 MB/secAzure Storage

Repositories limits

The following limits apply to repositories in Microsoft Sentinel.

DescriptionLimitDependency
Number of repositories5Sentinel Workspace
Deployment history800Azure Resource Group

Threat intelligence limits

The following limit applies to threat intelligence in Microsoft Sentinel. The limit is related to the dependency on an API used by threat intelligence.

DescriptionLimitDependency
Indicators per call that use Graph security API100 indicatorsMicrosoft Graph security API
CSV indicator file import size50MBnone
JSON indicator file import size250MBnone

TI upload indicators API limits

The following limit applies to the threat intelligence upload indicators API in Microsoft Sentinel.

DescriptionLimitDependency
Indicators per request100 indicators
Requests per minute100

User and Entity Behavior Analytics (UEBA) limits

The following limit applies to UEBA in Microsoft Sentinel. The limit for UEBA in Microsoft Sentinel is related to dependencies on another service.

DescriptionLimitDependency
Lowest retention configuration in days for the IdentityInfo table. All data stored on the IdentityInfo table in Log Analytics is refreshed every 14 days.14 daysLog Analytics

Watchlist limits

The following limits apply to watchlists in Microsoft Sentinel. The limits are related to the dependencies on other services used by watchlists.

DescriptionLimitDependency
Upload size for local file3.8 MB per fileAzure Resource Manager
Line entry in the CSV file10,240 characters per lineAzure Resource Manager
Total size of a single row10 KbLog Analytics
Upload size for files in Azure Storage500 MB per fileAzure Storage
Total number of active watchlist items per workspace. When the max count is reached, delete some existing items to add a new watchlist.10 million active watchlist itemsLog Analytics
Total rate of change of all watchlist items per workspace1% rate of change per monthLog Analytics
Number of large watchlist uploads per workspace at a timeOne large watchlistAzure Cosmos DB
Number of large watchlist deletions per workspace at a timeOne large watchlistAzure Cosmos DB

Workbook limits

Workbook limits for Sentinel are the same result limits found in Azure Monitor. For more information, see Workbooks result limits.

Workspace manager limits

The following limits apply to workspace manager in Microsoft Sentinel.

DescriptionLimitDependency
Number of published operations in a group
Published operations = (member workspaces) * (content items)
2000 published operationsNone

Next steps

  • Azure subscription and service limits, quotas, and constraints
  • Azure Monitor service limits
Microsoft Sentinel service limits (2024)
Top Articles
BulletShield | Bulletproof Window Glazing, Ballistic Window Film Alternative
Avery Help Center
Ups Customer Center Locations
Koopa Wrapper 1 Point 0
Walgreens Pharmqcy
Ffxiv Palm Chippings
COLA Takes Effect With Sept. 30 Benefit Payment
Mychart Mercy Lutherville
Amtrust Bank Cd Rates
From Algeria to Uzbekistan-These Are the Top Baby Names Around the World
Culver's Flavor Of The Day Wilson Nc
The Potter Enterprise from Coudersport, Pennsylvania
Jesse Mckinzie Auctioneer
Mndot Road Closures
Midway Antique Mall Consignor Access
Pollen Count Central Islip
Brenna Percy Reddit
MindWare : Customer Reviews : Hocus Pocus Magic Show Kit
The Cure Average Setlist
Bx11
Mzinchaleft
Walmart stores in 6 states no longer provide single-use bags at checkout: Which states are next?
Adam4Adam Discount Codes
Walgreens Tanque Verde And Catalina Hwy
Jenna Ortega’s Height, Age, Net Worth & Biography
T Mobile Rival Crossword Clue
Does Hunter Schafer Have A Dick
Craigslist Pasco Kennewick Richland Washington
Account Now Login In
Keshi with Mac Ayres and Starfall (Rescheduled from 11/1/2024) (POSTPONED) Tickets Thu, Nov 1, 2029 8:00 pm at Pechanga Arena - San Diego in San Diego, CA
Sinai Sdn 2023
Rugged Gentleman Barber Shop Martinsburg Wv
Account Now Login In
Shauna's Art Studio Laurel Mississippi
Urban Blight Crossword Clue
Kltv Com Big Red Box
Autopsy, Grave Rating, and Corpse Guide in Graveyard Keeper
Blasphemous Painting Puzzle
Yogu Cheshire
Wait List Texas Roadhouse
Davis Fire Friday live updates: Community meeting set for 7 p.m. with Lombardo
Mid America Clinical Labs Appointments
“To be able to” and “to be allowed to” – Ersatzformen von “can” | sofatutor.com
Tattoo Shops In Ocean City Nj
Jamesbonchai
Swoop Amazon S3
Ehc Workspace Login
Noga Funeral Home Obituaries
Deshuesadero El Pulpo
Cars & Trucks near Old Forge, PA - craigslist
99 Fishing Guide
David Turner Evangelist Net Worth
Latest Posts
Article information

Author: Kerri Lueilwitz

Last Updated:

Views: 6176

Rating: 4.7 / 5 (67 voted)

Reviews: 82% of readers found this page helpful

Author information

Name: Kerri Lueilwitz

Birthday: 1992-10-31

Address: Suite 878 3699 Chantelle Roads, Colebury, NC 68599

Phone: +6111989609516

Job: Chief Farming Manager

Hobby: Mycology, Stone skipping, Dowsing, Whittling, Taxidermy, Sand art, Roller skating

Introduction: My name is Kerri Lueilwitz, I am a courageous, gentle, quaint, thankful, outstanding, brave, vast person who loves writing and wants to share my knowledge and understanding with you.