Hi I followed the setup guide of DGA app and after all is done, I still don't know how to use it with my real world traffic. I have dns data and I want to use DGA to detect if there is any botnet or other bad traffic in my dns traffic. So how to get started ?
The DGA app gives me a fabulous picture of creating machine learning model but never mention a word how to use it in practise. That's a pity. Hope someone have the answer and share it out.
HI @kimikoyan please see my detailed answer posted here https://answers.splunk.com/answers/711128/how-to-apply-these-trained-data-models-to-actual-d.html