According to the official documentation, the multi-event rules capacity under the “Enterprise” license is 125 rules. However, we have noticed that in a few of our customer environments licensed under the Enterprise license, the multi-event rules quota has been increased to 200. Is this an official update? If so, why has it not been mentioned in any of the release notes or official documentation yet?
Best answer by kylechamplin
@ihenakaarachchi - hopefully this was a pleasant surprise! We rolled out a change in the last couple of weeks that increased limits for Enterprise and Enterprise+ SecOps customers. The increases are as follows:
Looks like the docs updates/changes didn’t get published, I’ll check on that this week. The main impetus for this change was a extremely positive increase in the adoption of composite detections (which consumes ME rule quota):
@ihenakaarachchi - hopefully this was a pleasant surprise! We rolled out a change in the last couple of weeks that increased limits for Enterprise and Enterprise+ SecOps customers. The increases are as follows:
Looks like the docs updates/changes didn’t get published, I’ll check on that this week. The main impetus for this change was a extremely positive increase in the adoption of composite detections (which consumes ME rule quota):