Fix Microsoft Defender Custom Detection Query Returns No Results
Question details
The user's Kusto query works correctly in the Microsoft Defender advanced hunting interface but fails to return any results when configured as a custom detection rule.

- Product
- Microsoft Defender for Endpoint
- Device & OS
- not provided
- Scenario
- Creating a new custom detection rule based on a validated advanced hunting Kusto query.
- Observed behavior
- The custom detection returns zero results and triggers no alerts, despite the exact same query yielding data in the hunting interface.
Ensure you have the necessary security administrator or custom detection management permissions in Microsoft Defender for Endpoint before modifying query rules.
Verify and Preserve Required Event Identifier Fields
Custom detection queries require specific ID fields to generate actionable alerts. If you use operators like join or summarize, these essential fields might be dropped.
Microsoft Defender custom detection rules require specific event identifiers to tie an alert to a machine, file, or event. Essential fields include DeviceId, ReportId, Timestamp, AlertId, and BehaviorId.
Log into the Microsoft Defender portal and navigate to your Advanced Hunting query.
Check your Kusto query for operators like 'summarize', 'join', or 'project' that might be stripping out required columns.
Adjust these operators to explicitly include DeviceId, ReportId, and Timestamp in their output (e.g., using 'project DeviceId, ReportId, Timestamp' or adding them to the 'by' clause in summarize).
Run the query again in the hunting interface to confirm the required columns are present in the final results table, then save it as a custom detection.

Seek Query-Specific Guidance on Microsoft Learn
If your query still returns no results after correctly formatting the output fields, there may be complex syntax or logic issues requiring expert review.
Need a Lightweight Alternative to Microsoft Office?
While you troubleshoot enterprise security settings in Microsoft Defender, you might also be looking for a more efficient and cost-effective office suite for your daily document workflows. WPS Office provides a highly compatible, all-in-one alternative to Microsoft Office.
- 1. Download the Installer: Visit the official WPS Office website and download the free installer for your operating system.
- 2. Install WPS Office: Run the downloaded file and follow the simple on-screen prompts to complete the installation.
- 3. Open Your Documents: Launch WPS Office and instantly open or edit your existing Microsoft Word, Excel, or PowerPoint files without formatting issues.

Frequently Asked Questions
Why does my Kusto query work in Advanced Hunting but not in Custom Detection?
Advanced Hunting simply retrieves and displays data rows based on your query, while Custom Detection uses those rows to trigger actionable alerts. Custom Detections require specific entity identifier columns (like DeviceId and Timestamp) to map the alert to a device or user. If your query drops these columns, the custom detection will fail to generate alerts.
Which identifier fields are strictly required for Defender custom detections?
At a minimum, you must include a Timestamp and a primary entity identifier such as DeviceId (for devices), AccountObjectId (for users), or FileSHA1 (for files). Including ReportId is also highly recommended to properly track the specific event record.
Can I use the summarize operator in a custom detection query?
Yes, but you must ensure that the aggregation explicitly preserves the required identifier fields. You can include them in the 'by' clause (for example, 'summarize count() by DeviceId, Timestamp') so they are passed properly to the final output.




