# Detections with custom query

**URL:** <https://discuss.elastic.co/t/detections-with-custom-query/252628>\
**Category:** SIEM\
**Tags:** detection-rules\
**Created:** [October 20, 2020, 5:11am UTC](https://discuss.elastic.co/t/detections-with-custom-query/252628 "2020-10-20T05:11:34Z")\
**Posts on this page:** 1\
**Showing post:** 6

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [October 27, 2020, 5:00am UTC](https://discuss.elastic.co/t/detections-with-custom-query/252628/6 "2020-10-27T05:00:54Z")

</div>

Hi @Anabella_Cristaldi,

Appreciate the sample 🙏 thank you!

> I do not see why is working for threshold but not for custom query (Does they have a different mechanism for quering)?

Yes, they do have different mechanisms. The threshold one is an aggregation and it does not fill in all the values when it creates a signal.

So, some good news is that in the soon to be released 7.10.0 where we improved error handling you will begin to see errors on that rule where before you were not. I just test ran that sample document off of Kibana master and here is the error:

 ![Screen Shot 2020-10-26 at 10.48.56 PM](https://us1.discourse-cdn.com/elastic/original/3X/7/1/7166dc035c9e9ea100e52a5b3b278edd3522d721.png)

It's pointing to your data set at `host`:

```auto
"host" : "srv",

```

Which has a conflict with the signal mapping. `host` has to be an object with inner objects/attributes as outlined here:

> **[Host Fields | Elastic Common Schema (ECS) Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/ecs/current/ecs-host.html#ecs-host)**

Once you fix that and re-index your data it should work. If it doesn't we can look at your mapping and data again. When the soon to be released 7.10.0 ships you will be able to see these error messages so getting these problems fixed sooner will be easier.

You can see the signals mapping here if it helps to find conflicts:

> <https://github.com/elastic/kibana/blob/main/x-pack/plugins/security_solution/server/lib/detection_engine/routes/index/ecs_mapping.json#L985>

We mostly use ECS tooling fwiw:

> <https://github.com/elastic/ecs/blob/main/USAGE.md>

and/or look at their generated outputs:  
[https://github.com/elastic/ecs/blob/master/generated/elasticsearch/7/template.json#L1071](https://github.com/elastic/ecs/blob/master/generated/elasticsearch/7/template.json#L1071)

to try and stay compliant and update along the way.

---

_[View the full topic](https://discuss.elastic.co/t/detections-with-custom-query/252628)._
