Cortex XSOAR service limits
Describes the service limits for Cortex XSOAR 8 SaaS.
Cortex XSOAR supports one or more tenants per customer: one for production, and one or more for development. The development tenant allows you to develop and test components (such as playbooks, automation scripts, and screen layouts) before they are deployed to production.
Indicator volume support differs between customers who own a TIM license and those who do not own a TIM license.
Cortex XSOAR production environment supports:
Incidents per day
24,000
24,000
Total indicators stored
3,000,000
100,000,000
Cortex XSOAR development environment supports:
Incidents per day
2000
5000
Total indicators stored
500,000
10,000,000
The development tenant has different technical specifications and should not be used for a production environment or stress testing.
Note
You need to comply with any Guard Rail Alerts. For more information, see View Guard Rails warnings and errors.
If you exceed the maximum number of incidents stored and ingested per day, you may experience slowness (if there are too many incidents being processed) and playbook executions and automations may be queued until there are sufficient resources available.
For multi-tenant deployments, the same service limits apply to each child tenant.
If you require a higher ingestion rate, contact Customer Support.
Last updated
Was this helpful?
