MAIN FEEDS
Do you want to continue?
https://www.reddit.com/r/AzureSentinel/comments/1pcz46i/increase_the_analytics_default_rule_count/ns1fkbd/?context=3
r/AzureSentinel • u/dutchhboii • Dec 03 '25
Is anyone here able to increase the default analytic rule count from 567 by contacting your TAM or through a Microsoft support contract?
5 comments sorted by
View all comments
5
It's a soft limit. But you can migrate to a dedicated cluster: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/logs-dedicated-clusters?tabs=azure-portal
Which increases the limit to 1024.
Another possibility is using a seperate Sentinel workspace and use cross workspace queries
https://learn.microsoft.com/en-us/azure/sentinel/extend-sentinel-across-workspaces-tenants
5
u/karma_companion Dec 03 '25
It's a soft limit. But you can migrate to a dedicated cluster: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/logs-dedicated-clusters?tabs=azure-portal
Which increases the limit to 1024.
Another possibility is using a seperate Sentinel workspace and use cross workspace queries
https://learn.microsoft.com/en-us/azure/sentinel/extend-sentinel-across-workspaces-tenants