# Tips to create a Machine Larning job

**URL:** https://discuss.elastic.co/t/tips-to-create-a-machine-larning-job/230244
**Category:** Kibana
**Tags:** elastic-stack-machine-learning
**Created:** [April 28, 2020, 7:28pm UTC](https://discuss.elastic.co/t/tips-to-create-a-machine-larning-job/230244 "2020-04-28T19:28:13Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)
#### Post date: [April 29, 2020, 3:13pm UTC](https://discuss.elastic.co/t/tips-to-create-a-machine-larning-job/230244/2 "2020-04-29T15:13:04Z")

</div>

You're going to most likely use the `count` function to track the occurrence rate of these types of messages over time.

You probably should pre-filter the types of messages you want to track (i.e. `dns.answers.type:"Malware" and dns.answers.type:"whatever else" and ...` ) and save that filter as a Saved Search (in Kibana). Then, use that saved search as the basis for your ML job (instead of every document in the index).

Probably a multi-metric job - again, using `count` ("Count(Event rate)") as the thing you track, and choose `dns.answers.type` as the "split field".

There are more advanced ML techniques that can be employed on DNS data (including DNS Tunnelling/Exfiltration detection, etc.). Look at the same jobs within the SIEM app and other examples on this forum (like this one: [Security Analytics Recipes - DNS Data Exfiltration](https://discuss.elastic.co/t/security-analytics-recipes-dns-data-exfiltration/226868))

---

_[View the full topic](https://discuss.elastic.co/t/tips-to-create-a-machine-larning-job/230244)._
