Query Limits 🔗
Live Endpoint Search is only available for devices with the Sophos Endpoint Agent.
We limit Live Endpoint Search queries to protect device and service performance.
Limits on the Number of Queries🔗
We put limits on the number of queries you can run in a set time. Each tenant has the following query limits:
-
Scheduled and API queries combined:
- Up to 1,000 queries per day.
- Up to 10 queries per minute.
-
Queries run in the Live Endpoint Search interface:
- No limit on queries per day.
- Up to 15 queries per minute.
If your tenant exceeds a limit, the Device Telemetry tab shows an error message stating this.
Guardrails🔗
Devices and Secureworks® Taegis™ XDR apply guardrails to limit query resource use and returned data.
Guardrails on Devices🔗
Devices apply these guardrails:
- Watchdog: Devices have a watchdog that ends a query if it exceeds 30 percent of the device's available CPU for 12 seconds or uses more than 256 MB of memory.
- Return data size limit: A device can return up to 10 MB of data for a query.
- Single row data size limit: A single result row can contain up to 1 MB of data.
Note
If a result row exceeds 1 MB, the device might report that it returned data, but Taegis doesn't show the result. A query can exceed the limit when looking for the content of a PowerShell event or registry key.
Guardrail on Secureworks® Taegis™ XDR🔗
Taegis limits the number of rows from all responding devices to a maximum of 100,000 rows. When the query reaches this limit, Taegis discards additional rows and tells devices that are still processing the query to stop returning data.