Packetbeat on high volume production Windows-AD-DNS-Servers

You could always create a dedicated sensor running packetbeat that gets a copy of the traffic going to your DCs if you don't want to run the software on your DCs