Summary rules - Limit on total aggregated size

Khanna, Keshav 20 Reputation points
2024-12-19T14:16:00.4066667+00:00

Folks,

I'm trying to use summary rules to aggregate firewall logs. There's a hard size limit from MS per result of 100 MB which I think is not up to the mark for firewall logs. While summarizing I'm creating two sets and grouping by 7 other fields (I need for alarms). The summary rule works 60% of the time, 40% of the time it fails because of a spike in logs that leads to the size exceeding 100 MB. I can't think of a way to workaround this. Anybody figured it out yet?

Probably can create a limit in kql to check for size and ignore anything above 100 MB but I can't think of a way I can do this in kql.

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,195 questions
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.