Custom detection in MDE

Ankush Kumar 35 Reputation points
2024-04-23T12:01:01.1433333+00:00

I am trying to create Custom Detection in Microsoft Security Center where my query has multiple Join and summarize statements.

Whenever I am running query its providing results but after saving in Custom Detection form and under its results section its giving below message, although I already have Timestamp, ReportId, DeviceId as an output coming.

"No events match the given event identifiers (a combination of ReportId, AlertId, BehaviorId, or DeviceId and Timestamp). Edit the query's aggregation expressions for these columns and try again."

Can anyone help me to understand how I can fix the above issue?

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
3,832 questions
Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,758 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,202 questions
{count} votes

Accepted answer
  1. Givary-MSFT 28,321 Reputation points Microsoft Employee
    2024-04-24T06:29:13.7966667+00:00

    @Ankush Kumar Thank you for reaching out to us, for better understanding of the issue, if you can share the screenshot/query which you are trying to execute.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful