# DGA integration with packetbeat

**URL:** <https://discuss.elastic.co/t/dga-integration-with-packetbeat/370232>\
**Category:** Elastic Security\
**Created:** [November 8, 2024, 2:55pm UTC](https://discuss.elastic.co/t/dga-integration-with-packetbeat/370232 "2024-11-08T14:55:31Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Miguel\_Martinez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miguel_martinez/32/123421_2.png) [@Miguel\_Martinez](https://discuss.elastic.co/u/Miguel_Martinez)\
**Post date:** [November 8, 2024, 2:55pm UTC](https://discuss.elastic.co/t/dga-integration-with-packetbeat/370232/1 "2024-11-08T14:55:31Z")

</div>

I am currently doing the DGA integration but I can't install elastic Defender, I have read that it can be done with packetbeat, can you help me how to do it, according to this DGA documentation I have done up to step 5 but from here on I don't know what to do,  
can you help me what I have to do, or if you have documentation of what are the next steps to do it with packetbeat.

Thank you very much.

---

<div class="post-metadata">

**Author:** ![Gus\_Carlock](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gus_carlock/32/139098_2.png) [@Gus\_Carlock](https://discuss.elastic.co/u/Gus_Carlock)\
**Post date:** [November 11, 2024, 3:52pm UTC](https://discuss.elastic.co/t/dga-integration-with-packetbeat/370232/2 "2024-11-11T15:52:20Z")

</div>

Hi @Miguel_Martinez ,

For Packetbeat, start with the normal instructions as you did, but when you get to the pipeline configuration step, use the following steps.

In Kibana, navigate to **Management \> Dev Tools** and run the following to create a new component template:

```auto
PUT _component_template/packetbeat-dga-{DGA_VERSION}
{
  "template": {
    "mappings": {
      "properties": {
        "ml_is_dga": {
          "type": "object",
          "properties": {
            "malicious_prediction": {
              "type": "long"
            },
            "malicious_probability": {
              "type": "float"
            }
          }
        }
      }
    },
    "settings": {
      "index": {
        "final_pipeline": "{DGA_VERSION}-ml_dga_ingest_pipeline"
      }
    }
  }
}

```

Be sure to change `{DGA_VERSION}` to the version of the Domain Generation Algorithm Detection integration you are using.

Then navigate to **Stack Management \> Data \> Index Management \> Index Templates**. Find the index template `packetbeat-{PACKETBEAT_VERSION}` for the Packetbeat version that you are using and click **Edit**. Then click on **Component templates**. Add the `packetbeat-dga-{DGA_VERSION}` component template that was created in the previous step. Click **Review template** then **Save template**.

Finally, roll over that index in **Dev Tools** :

```auto
POST packetbeat-{PACKETBEAT_VERSION}/_rollover

```

You should now see the mapped fields under `ml_is_dga` and new predictions being generated.

Gus

---

<div class="post-metadata">

**Author:** ![Miguel\_Martinez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miguel_martinez/32/123421_2.png) [@Miguel\_Martinez](https://discuss.elastic.co/u/Miguel_Martinez)\
**Post date:** [November 26, 2024, 9:05pm UTC](https://discuss.elastic.co/t/dga-integration-with-packetbeat/370232/3 "2024-11-26T21:05:40Z")

</div>

Thank you very much I was able to solve it thanks to you,  
These were the steps I followed,

1. Pipeline creation:

```auto
PUT _ingest/pipeline/logs-endpoint.events.network@custom
{
  "processors": [
    {
      "pipeline": {
        "name": "2.0.4-ml_dga_ingest_pipeline",
        "ignore_missing_pipeline": true,
        "ignore_failure": true
      }
    }
  ]
}

```

1. Template creation:

```auto
PUT _component_template/packetbeat-dga-2.0.4
{
  "template": {
    "mappings": {
      "properties": {
        "ml_is_dga": {
          "type": "object",
          "properties": {
            "malicious_prediction": {
              "type": "long"
            },
            "malicious_probability": {
              "type": "float"
            }
          }
        }
      }
    },
    "settings": {
      "index": {
        "final_pipeline": "2.0.4-ml_dga_ingest_pipeline"
      }
    }
  }
}

```

1. Index Creation and Alias Assignment:

```auto
PUT packetbeat-8.8.2-000001
{
  "aliases": {
    "packetbeat-dga-alias": {
      "is_write_index": true
    }
  }
}

```

1. Install packetbeat:  
/etc/packetbeat/packetbeat.yml

```auto
packetbeat.interfaces.device: any
packetbeat.protocols:
  - type: dns
    ports: [53]
    include_authorities: true
    include_additionals: true
cloud.id: "cloud_id"
output.elasticsearch:
  api_key: "id:api_key"
  pipeline: "logs-endpoint.events.network@custom"
  index: "packetbeat-dga-alias"

setup.template.name: "packetbeat-dga-2.0.4"
setup.template.pattern: "packetbeat-dga-*"
setup.template.enabled: true
setup.template.settings:
  index:
    final_pipeline: "2.0.4-ml_dga_ingest_pipeline" 

```

1. rollover  
POST packetbeat-dga-alias/\_rollover

And it all worked

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 24, 2024, 9:06pm UTC](https://discuss.elastic.co/t/dga-integration-with-packetbeat/370232/4 "2024-12-24T21:06:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
