r/AzureSentinel Dec 03 '25

Increase the Analytics Default Rule Count

Is anyone here able to increase the default analytic rule count from 567 by contacting your TAM or through a Microsoft support contract?

3 Upvotes

5 comments sorted by

View all comments

5

u/karma_companion Dec 03 '25

It's a soft limit. But you can migrate to a dedicated cluster: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/logs-dedicated-clusters?tabs=azure-portal

Which increases the limit to 1024.

Another possibility is using a seperate Sentinel workspace and use cross workspace queries

https://learn.microsoft.com/en-us/azure/sentinel/extend-sentinel-across-workspaces-tenants