MicrosoftDocs / azure-docs

Open source documentation of Microsoft Azure
https://docs.microsoft.com/azure
Creative Commons Attribution 4.0 International
9.98k stars 20.95k forks source link

Unclear limit on max Incidents per Workspace per day #121987

Closed camalloy closed 6 days ago

camalloy commented 1 week ago

I'm seeing a warning message about hitting a limit, however, I can't tell what limit I'm hitting based on this documentation.

Here is the warning from Sentinel:

"Notice: your workspace has generated too many incidents in the last day. If it continues at this rate, you might be unable to create or modify incidents in the future. Please turn off or adjust any rule that might be creating too many incidents."


Document Details

Do not edit this section. It is required for learn.microsoft.com ➟ GitHub issue linking.

PesalaPavan commented 1 week ago

@camalloy Thanks for your feedback! We will investigate and update as appropriate.

SaibabaBalapur-MSFT commented 1 week ago

@camalloy According to the Microsoft Sentinel service limits documentation, there is no specific limit on the maximum number of incidents per workspace per day. However, there are some general limits that apply to incidents, such as the maximum number of incidents that can be displayed concurrently in the Incidents page (100), and the maximum number of incidents that can be exported to a CSV file (10,000). Additionally, there are limits on the number of incidents that can be created or updated by various features, such as analytics rules and playbooks.

Thanks for your contribution. Please add your feedback in below link, so our production team can review it and update the same. Ideas · Community (azure.com)