Map Data Fields to Microsoft Sentinel Entities
In brief
The article now explicitly covers adding or changing entity mappings in existing analytics rules and while creating new scheduled analytics rules. It also updates formatting, metadata, and related-content links.
What Defender admins need to know
Administrators can use the revised instructions; no configuration change or migration is stated.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Map data fields to entities in Microsoft Sentinel
Entity mapping is an integral part of the configuration of scheduled analytics rules. It enriches the rules' output (alerts and incidents) with essential information that serves as the building blocks of any investigative processes and remedial actions that follow.
TheUse the following procedure is part of the analytics rule creation wizard. It's treated here independently to address the scenario of addingadd or changingchange entity mappings in an existing analytics rule, or while creating a new scheduled analytics rule.
:::image type="content" source="media/map-data-fields-to-entities/choose-entity-type.png" alt-text="Choose an entity type":::
Select an identifier for the entity. Identifiers are attributes of an entity that can sufficiently identify it. Choose one from the Identifier drop-down list, and then choose a data field from the Value drop-down list that will correspond to the identifier. With some exceptions, the Value list is populated by the data fields in the table defined as the subject of the rule query.
You can define up to three identifiers for a given entity mapping. Some identifiers are required, others are optional. You must choose at least one required identifier. If you don't, a warning message will instruct you which identifiers are required. For best results—for maximum unique identification—you should use strong identifiers whenever possible, and using multiple strong identifiers will enable greater correlation between data sources. See the full list of available entities and identifiers.
:::image type="content" source="media/map-data-fields-to-entities/map-entities.png" alt-text="Map fields to entities":::
Select Add new entity to map more entities. You can define up to
ten10 entity mappings in a single analytics rule. You can also map more than one of the same type. For example, you can map two IP entities, one from a source IP address field and one from a destination IP address field.This wayBy mapping both fields, you can trackthem both.both IP entities.If you change your mind, or if you made a mistake, you can remove an entity mapping by clicking the trash can icon next to the entity drop-down list.
When you have finished mapping entities, click the Review and create tab. Once the rule validation is successful, click Save.
Notes on the new version
The entity mapping experience was updated from an older version. Keep the following backward-compatibility details in mind:
As the new version is now generally available (GA), the feature-flag workaround to use the old version is no longer available.
If you had previously defined entity mappings for this analytics rule using the old version, they will be automatically converted to the new version.
Related content
- Surface custom event details in alerts in Microsoft Sentinel
- Customize alert details in Microsoft Sentinel
@@ -1,30 +1,30 @@ ----title: Map data fields to Microsoft Sentinel entities+title: Map Data Fields to Microsoft Sentinel Entities description: Map table data fields to Microsoft Sentinel entities in scheduled analytics rules to enrich alerts and incidents with structured investigation data. Includes guidance for adding or updating entity mappings in existing rules. ms.author: guywild author: guywi-ms ms.reviewer: noak ms.topic: how-to-ms.date: 06/15/2026+ms.date: 07/02/2026 ms.collection: usx-security appliesto: - Microsoft Sentinel in the Microsoft Defender portal - Microsoft Sentinel in the Azure portal ai-usage: ai-assisted-ms.custom: msecd-doc-authoring-1014+ms.custom: msecd-doc-authoring-1016 #Customer intent: As a security analyst, I want to map data fields to entities in analytics rules so that I can enrich alerts and incidents with essential information for effective investigation and remediation. --- -# Map data fields to entities in Microsoft Sentinel +# Map data fields to entities in Microsoft Sentinel Entity mapping is an integral part of the configuration of [scheduled analytics rules](scheduled-rules-overview.md). It enriches the rules' output (alerts and incidents) with essential information that serves as the building blocks of any investigative processes and remedial actions that follow. -The following procedure is part of the analytics rule creation wizard. It's treated here independently to address the scenario of adding or changing entity mappings in an existing analytics rule.+Use the following procedure to add or change entity mappings in an existing analytics rule, or while creating a new scheduled analytics rule. > [!IMPORTANT]->+ > - See [Notes on the new version](#notes-on-the-new-version) for important information about backward compatibility and differences between the new and old versions of entity mapping. > - [!INCLUDE [unified-soc-preview-without-alert](includes/unified-soc-preview-without-alert.md)] @@ -60,41 +60,38 @@ To map entities in an analytics rule, perform the following steps: :::image type="content" source="media/map-data-fields-to-entities/choose-entity-type.png" alt-text="Choose an entity type"::: -1. Select an **identifier** for the entity. Identifiers are attributes of an entity that can sufficiently identify it. Choose one from the **Identifier** drop-down list, and then choose a data field from the **Value** drop-down list that will correspond to the identifier. With some exceptions, the **Value** list is populated by the data fields in the table defined as the subject of the rule query.+1. Select an identifier for the entity. Identifiers are attributes of an entity that can sufficiently identify it. Choose one from the **Identifier** drop-down list, and then choose a data field from the **Value** drop-down list that will correspond to the identifier. With some exceptions, the **Value** list is populated by the data fields in the table defined as the subject of the rule query. - You can define **up to three identifiers** for a given entity mapping. Some identifiers are required, others are optional. You must choose at least one required identifier. If you don't, a warning message will instruct you which identifiers are required. For best results—for maximum unique identification—you should use **strong identifiers** whenever possible, and using multiple strong identifiers will enable greater correlation between data sources. See the full list of available [entities and identifiers](entities-reference.md).+ You can define up to three identifiers for a given entity mapping. Some identifiers are required, others are optional. You must choose at least one required identifier. If you don't, a warning message will instruct you which identifiers are required. For best results—for maximum unique identification—you should use strong identifiers whenever possible, and using multiple strong identifiers will enable greater correlation between data sources. See the full list of available [entities and identifiers](entities-reference.md). :::image type="content" source="media/map-data-fields-to-entities/map-entities.png" alt-text="Map fields to entities"::: -1. Select **Add new entity** to map more entities. You can define **up to ten entity mappings** in a single analytics rule. You can also map more than one of the same type. For example, you can map two **IP** entities, one from a *source IP address* field and one from a *destination IP address* field. This way you can track them both.+1. Select **Add new entity** to map more entities. You can define up to 10 entity mappings in a single analytics rule. You can also map more than one of the same type. For example, you can map two **IP** entities, one from a *source IP address* field and one from a *destination IP address* field. By mapping both fields, you can track both IP entities. If you change your mind, or if you made a mistake, you can remove an entity mapping by clicking the trash can icon next to the entity drop-down list. 1. When you have finished mapping entities, click the **Review and create** tab. Once the rule validation is successful, click **Save**. > [!NOTE]-> - ***Up to 500 entities collectively* can be identified in a single alert, divided equally across all entity mappings defined in the rule**.+> - *Up to 500 entities collectively* can be identified in a single alert, divided equally across all entity mappings defined in the rule. > - For example, if two entity mappings are defined in the rule, each mapping can identify up to 250 entities; if five mappings are defined, each one can identify up to 100 entities, and so on. > - Multiple mappings of a single entity type (say, source IP and destination IP) each count separately. > - If an alert contains items in excess of this limit, those excess items will not be recognized and extracted as entities. >-> - **The size limit for the entire *entities* area of an alert (the *Entities* field) is *64 KB***.+> - The size limit for the entire *entities* area of an alert (the **Entities** field) is *64 KB*. > - *Entities* fields that grow larger than 64 KB will be truncated. As entities are identified, they are added to the alert one by one until the field size reaches 64 KB, and any entities yet unidentified are dropped from the alert. ## Notes on the new version The entity mapping experience was updated from an older version. Keep the following backward-compatibility details in mind: -- As the new version is now generally available (GA), the feature-flag workaround to use the old version is no longer available. +- As the new version is now generally available (GA), the feature-flag workaround to use the old version is no longer available. - If you had previously defined entity mappings for this analytics rule using the old version, they will be automatically converted to the new version. -## Next steps--In this document, you learned how to map data fields to entities in Microsoft Sentinel analytics rules. To learn more about Microsoft Sentinel, see the following articles:+## Related content -- Explore the other ways to enrich your alerts:- - [Surface custom event details in alerts in Microsoft Sentinel](surface-custom-details-in-alerts.md)- - [Customize alert details in Microsoft Sentinel](customize-alert-details.md)-- Get the complete picture on [scheduled query analytics rules](detect-threats-custom.md).-- Learn more about [entities in Microsoft Sentinel](entities.md).+- [Surface custom event details in alerts in Microsoft Sentinel](surface-custom-details-in-alerts.md)+- [Customize alert details in Microsoft Sentinel](customize-alert-details.md)+- [Create a scheduled analytics rule from scratch](create-analytics-rules.md).+- [Entities in Microsoft Sentinel](entities.md). 