logo
search
Others

Fix Microsoft Defender Custom Detection Query Returns No Results

Guest WriterGuest Writer Sep 28, 2026 869 views

Question details

The user's Kusto query works correctly in the Microsoft Defender advanced hunting interface but fails to return any results when configured as a custom detection rule.

How to Fix Microsoft Defender Custom Detection Query Returning No Results
Product
Microsoft Defender for Endpoint
Device & OS
not provided
Scenario
Creating a new custom detection rule based on a validated advanced hunting Kusto query.
Observed behavior
The custom detection returns zero results and triggers no alerts, despite the exact same query yielding data in the hunting interface.
Before you start

Ensure you have the necessary security administrator or custom detection management permissions in Microsoft Defender for Endpoint before modifying query rules.

Solution 1Recommended

Verify and Preserve Required Event Identifier Fields

Custom detection queries require specific ID fields to generate actionable alerts. If you use operators like join or summarize, these essential fields might be dropped.

Microsoft Defender custom detection rules require specific event identifiers to tie an alert to a machine, file, or event. Essential fields include DeviceId, ReportId, Timestamp, AlertId, and BehaviorId.

1
Open Advanced Hunting

Log into the Microsoft Defender portal and navigate to your Advanced Hunting query.

2
Review Data-Shaping Operators

Check your Kusto query for operators like 'summarize', 'join', or 'project' that might be stripping out required columns.

3
Modify the Query Output

Adjust these operators to explicitly include DeviceId, ReportId, and Timestamp in their output (e.g., using 'project DeviceId, ReportId, Timestamp' or adding them to the 'by' clause in summarize).

4
Validate and Save

Run the query again in the hunting interface to confirm the required columns are present in the final results table, then save it as a custom detection.

Verify and Preserve Required Event Identifier Fields
Required Identifier Fields: Without these exact fields, the Defender portal cannot map the query results to actionable alerts, resulting in zero custom detection matches.
Free Microsoft Office alternative

Need a Lightweight Alternative to Microsoft Office?

While you troubleshoot enterprise security settings in Microsoft Defender, you might also be looking for a more efficient and cost-effective office suite for your daily document workflows. WPS Office provides a highly compatible, all-in-one alternative to Microsoft Office.

  1. 1. Download the Installer: Visit the official WPS Office website and download the free installer for your operating system.
  2. 2. Install WPS Office: Run the downloaded file and follow the simple on-screen prompts to complete the installation.
  3. 3. Open Your Documents: Launch WPS Office and instantly open or edit your existing Microsoft Word, Excel, or PowerPoint files without formatting issues.
Fully compatible with Microsoft Office formats like .docx, .xlsx, and .pptx.Lightweight design that uses minimal system resources.Familiar user interface for a seamless transition and zero learning curve.Built-in PDF editing, conversion, and cloud collaboration tools.
microsoft office alternative - wps office

Frequently Asked Questions

Why does my Kusto query work in Advanced Hunting but not in Custom Detection?

Advanced Hunting simply retrieves and displays data rows based on your query, while Custom Detection uses those rows to trigger actionable alerts. Custom Detections require specific entity identifier columns (like DeviceId and Timestamp) to map the alert to a device or user. If your query drops these columns, the custom detection will fail to generate alerts.

Which identifier fields are strictly required for Defender custom detections?

At a minimum, you must include a Timestamp and a primary entity identifier such as DeviceId (for devices), AccountObjectId (for users), or FileSHA1 (for files). Including ReportId is also highly recommended to properly track the specific event record.

Can I use the summarize operator in a custom detection query?

Yes, but you must ensure that the aggregation explicitly preserves the required identifier fields. You can include them in the 'by' clause (for example, 'summarize count() by DeviceId, Timestamp') so they are passed properly to the final output.