# Elastic Machine Learning for CyberSecurity Training Question

**URL:** https://discuss.elastic.co/t/elastic-machine-learning-for-cybersecurity-training-question/159249
**Category:** Elastic Training
**Created:** [December 3, 2018, 9:22pm UTC](https://discuss.elastic.co/t/elastic-machine-learning-for-cybersecurity-training-question/159249 "2018-12-03T21:22:20Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![rudyamid](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rudyamid/32/38393_2.png) [@rudyamid](https://discuss.elastic.co/u/rudyamid)
#### Post date: [December 3, 2018, 9:22pm UTC](https://discuss.elastic.co/t/elastic-machine-learning-for-cybersecurity-training-question/159249/1 "2018-12-03T21:22:20Z")

</div>

Hello,

I’m reviewing the Labs for the new on-demand “Elastic Machine Learning for CyberSecurity” training. In section “Detect DNS Data Exfiltration” , on step 3.m, I cut paste the PUT request on the anomaly\_detectors endpoint in Kibana dev tool, and I get this error:

{  
"error": {  
"root\_cause": [  
{  
"type": "x\_content\_parse\_exception",  
"reason": "[3:3] [datafeed\_config] unknown field [job\_type], parser not found"  
}  
],  
"type": "x\_content\_parse\_exception",  
"reason": "[3:3] [datafeed\_config] unknown field [job\_type], parser not found"  
},  
"status": 400  
}

Am I missing something? I obviously can’t move on to the next step without creating this first ML job.

regards

---

<div class="post-metadata">

### Author: ![raposa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raposa/32/11906_2.png) [@raposa](https://discuss.elastic.co/u/raposa)
#### Post date: [December 3, 2018, 11:01pm UTC](https://discuss.elastic.co/t/elastic-machine-learning-for-cybersecurity-training-question/159249/2 "2018-12-03T23:01:40Z")

</div>

Hi Rudy,

There is a typo in the lab instructions. The URL in the instructions has

```auto
PUT _xpack/ml/datafeeds/datafeed-dns_data_exfiltration_api

```

but it should be:

```auto
PUT _xpack/ml/anomaly_detectors/dns_data_exfiltration_api

```

The entire PUT command should look like:

```auto
PUT _xpack/ml/anomaly_detectors/dns_data_exfiltration_api
{
  "description": "",
  "analysis_config": {
    "bucket_span": "5m",
    "detectors": [
      {
        "detector_description": "high_info_content(subdomain) over highest_registered_domain excludefrequent=all",
        "function": "high_info_content",
        "field_name": "subdomain",
        "over_field_name": "highest_registered_domain",
        "exclude_frequent": "all",
        "detector_index": 0
      }
    ],
    "influencers": [
      "beat.hostname",
      "highest_registered_domain"
    ]
  },
  "analysis_limits": {
    "model_memory_limit": "1024mb",
    "categorization_examples_limit": 4
  },
  "data_description": {
    "time_field": "@timestamp",
    "time_format": "epoch_ms"
  }
}

```

---

<div class="post-metadata">

### Author: ![rudyamid](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rudyamid/32/38393_2.png) [@rudyamid](https://discuss.elastic.co/u/rudyamid)
#### Post date: [December 3, 2018, 11:50pm UTC](https://discuss.elastic.co/t/elastic-machine-learning-for-cybersecurity-training-question/159249/3 "2018-12-03T23:50:50Z")

</div>

Cool, thanks. My strigo session expired, so I had to login again, forcing it to recreate my workstation with a new IP address. I have to start over with the labs!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 2, 2019, 11:50pm UTC](https://discuss.elastic.co/t/elastic-machine-learning-for-cybersecurity-training-question/159249/4 "2019-01-02T23:50:52Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
