{
  "name": "ti_domaintools",
  "title": "DomainTools Feeds",
  "version": "1.6.0",
  "release": "ga",
  "source": {
    "license": "Elastic-2.0"
  },
  "description": "DomainTools Feeds provide data on the different stages of the domain lifecycle: from first-observed in the wild, to newly re-activated after a period of quiet.",
  "type": "integration",
  "download": "/epr/ti_domaintools/ti_domaintools-1.6.0.zip",
  "path": "/package/ti_domaintools/1.6.0",
  "icons": [
    {
      "src": "/img/logo.png",
      "path": "/package/ti_domaintools/1.6.0/img/logo.png",
      "title": "DomainTools logo",
      "size": "250x250",
      "type": "image/svg+xml"
    }
  ],
  "conditions": {
    "kibana": {
      "version": "^8.19.2 || ^9.0.5"
    },
    "elastic": {
      "subscription": "basic"
    }
  },
  "owner": {
    "type": "partner",
    "github": "elastic/security-service-integrations"
  },
  "categories": [
    "security",
    "threat_intel"
  ],
  "signature_path": "/epr/ti_domaintools/ti_domaintools-1.6.0.zip.sig",
  "format_version": "3.3.2",
  "readme": "/package/ti_domaintools/1.6.0/docs/README.md",
  "license": "basic",
  "screenshots": [
    {
      "src": "/img/ti_domaintools_overview-dashboard.png",
      "path": "/package/ti_domaintools/1.6.0/img/ti_domaintools_overview-dashboard.png",
      "title": "DomainTools Real Time Unified Feeds Overview Dashboard",
      "size": "600x600",
      "type": "image/png"
    }
  ],
  "assets": [
    "/package/ti_domaintools/1.6.0/LICENSE.txt",
    "/package/ti_domaintools/1.6.0/changelog.yml",
    "/package/ti_domaintools/1.6.0/manifest.yml",
    "/package/ti_domaintools/1.6.0/validation.yml",
    "/package/ti_domaintools/1.6.0/docs/README.md",
    "/package/ti_domaintools/1.6.0/img/logo.png",
    "/package/ti_domaintools/1.6.0/img/ti_domaintools_overview-dashboard.png",
    "/package/ti_domaintools/1.6.0/data_stream/domaindiscovery_feed/lifecycle.yml",
    "/package/ti_domaintools/1.6.0/data_stream/domaindiscovery_feed/manifest.yml",
    "/package/ti_domaintools/1.6.0/data_stream/domaindiscovery_feed/sample_event.json",
    "/package/ti_domaintools/1.6.0/data_stream/domainhotlist_feed/lifecycle.yml",
    "/package/ti_domaintools/1.6.0/data_stream/domainhotlist_feed/manifest.yml",
    "/package/ti_domaintools/1.6.0/data_stream/domainhotlist_feed/sample_event.json",
    "/package/ti_domaintools/1.6.0/data_stream/domainrdap_feed/lifecycle.yml",
    "/package/ti_domaintools/1.6.0/data_stream/domainrdap_feed/manifest.yml",
    "/package/ti_domaintools/1.6.0/data_stream/domainrdap_feed/sample_event.json",
    "/package/ti_domaintools/1.6.0/data_stream/domainrisk_feed/lifecycle.yml",
    "/package/ti_domaintools/1.6.0/data_stream/domainrisk_feed/manifest.yml",
    "/package/ti_domaintools/1.6.0/data_stream/domainrisk_feed/sample_event.json",
    "/package/ti_domaintools/1.6.0/data_stream/nad_feed/lifecycle.yml",
    "/package/ti_domaintools/1.6.0/data_stream/nad_feed/manifest.yml",
    "/package/ti_domaintools/1.6.0/data_stream/nad_feed/sample_event.json",
    "/package/ti_domaintools/1.6.0/data_stream/nod_feed/lifecycle.yml",
    "/package/ti_domaintools/1.6.0/data_stream/nod_feed/manifest.yml",
    "/package/ti_domaintools/1.6.0/data_stream/nod_feed/sample_event.json",
    "/package/ti_domaintools/1.6.0/kibana/dashboard/ti_domaintools-7ad9a714-58db-45e3-ba84-1e2dff1eb9a5.json",
    "/package/ti_domaintools/1.6.0/kibana/search/ti_domaintools-0003128e-b815-468e-913d-b091a156a805.json",
    "/package/ti_domaintools/1.6.0/kibana/search/ti_domaintools-653c19ae-f37b-4414-8fc9-ebc1b3abe29b.json",
    "/package/ti_domaintools/1.6.0/kibana/search/ti_domaintools-7f96fd28-25f1-4e44-9825-2617faa05217.json",
    "/package/ti_domaintools/1.6.0/kibana/search/ti_domaintools-8ac2e86f-4c5b-4bbf-b3af-a39cc710f84e.json",
    "/package/ti_domaintools/1.6.0/kibana/search/ti_domaintools-8fa9ed20-de47-4226-9e75-cd7cbf8e9141.json",
    "/package/ti_domaintools/1.6.0/kibana/search/ti_domaintools-ae844224-f834-43ed-b62e-8c67926d1ddd.json",
    "/package/ti_domaintools/1.6.0/data_stream/domaindiscovery_feed/fields/base-fields.yml",
    "/package/ti_domaintools/1.6.0/data_stream/domaindiscovery_feed/fields/ecs.yml",
    "/package/ti_domaintools/1.6.0/data_stream/domaindiscovery_feed/fields/fields.yml",
    "/package/ti_domaintools/1.6.0/data_stream/domaindiscovery_feed/fields/is-ioc-transform-source-true.yml",
    "/package/ti_domaintools/1.6.0/data_stream/domainhotlist_feed/fields/base-fields.yml",
    "/package/ti_domaintools/1.6.0/data_stream/domainhotlist_feed/fields/ecs.yml",
    "/package/ti_domaintools/1.6.0/data_stream/domainhotlist_feed/fields/fields.yml",
    "/package/ti_domaintools/1.6.0/data_stream/domainhotlist_feed/fields/is-ioc-transform-source-true.yml",
    "/package/ti_domaintools/1.6.0/data_stream/domainrdap_feed/fields/base-fields.yml",
    "/package/ti_domaintools/1.6.0/data_stream/domainrdap_feed/fields/ecs.yml",
    "/package/ti_domaintools/1.6.0/data_stream/domainrdap_feed/fields/fields.yml",
    "/package/ti_domaintools/1.6.0/data_stream/domainrdap_feed/fields/is-ioc-transform-source-true.yml",
    "/package/ti_domaintools/1.6.0/data_stream/domainrisk_feed/fields/base-fields.yml",
    "/package/ti_domaintools/1.6.0/data_stream/domainrisk_feed/fields/ecs.yml",
    "/package/ti_domaintools/1.6.0/data_stream/domainrisk_feed/fields/fields.yml",
    "/package/ti_domaintools/1.6.0/data_stream/domainrisk_feed/fields/is-ioc-transform-source-true.yml",
    "/package/ti_domaintools/1.6.0/data_stream/nad_feed/fields/base-fields.yml",
    "/package/ti_domaintools/1.6.0/data_stream/nad_feed/fields/ecs.yml",
    "/package/ti_domaintools/1.6.0/data_stream/nad_feed/fields/fields.yml",
    "/package/ti_domaintools/1.6.0/data_stream/nad_feed/fields/is-ioc-transform-source-true.yml",
    "/package/ti_domaintools/1.6.0/data_stream/nod_feed/fields/base-fields.yml",
    "/package/ti_domaintools/1.6.0/data_stream/nod_feed/fields/ecs.yml",
    "/package/ti_domaintools/1.6.0/data_stream/nod_feed/fields/fields.yml",
    "/package/ti_domaintools/1.6.0/data_stream/nod_feed/fields/is-ioc-transform-source-true.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_domaindiscovery/manifest.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_domaindiscovery/transform.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_domainhotlist/manifest.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_domainhotlist/transform.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_domainrdap/manifest.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_domainrdap/transform.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_domainrisk/manifest.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_domainrisk/transform.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_nad/manifest.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_nad/transform.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_nod/manifest.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_nod/transform.yml",
    "/package/ti_domaintools/1.6.0/data_stream/domaindiscovery_feed/agent/stream/cel.yml.hbs",
    "/package/ti_domaintools/1.6.0/data_stream/domaindiscovery_feed/elasticsearch/ilm/default_policy.json",
    "/package/ti_domaintools/1.6.0/data_stream/domaindiscovery_feed/elasticsearch/ingest_pipeline/default.yml",
    "/package/ti_domaintools/1.6.0/data_stream/domainhotlist_feed/agent/stream/cel.yml.hbs",
    "/package/ti_domaintools/1.6.0/data_stream/domainhotlist_feed/elasticsearch/ilm/default_policy.json",
    "/package/ti_domaintools/1.6.0/data_stream/domainhotlist_feed/elasticsearch/ingest_pipeline/default.yml",
    "/package/ti_domaintools/1.6.0/data_stream/domainrdap_feed/agent/stream/cel.yml.hbs",
    "/package/ti_domaintools/1.6.0/data_stream/domainrdap_feed/elasticsearch/ilm/default_policy.json",
    "/package/ti_domaintools/1.6.0/data_stream/domainrdap_feed/elasticsearch/ingest_pipeline/default.yml",
    "/package/ti_domaintools/1.6.0/data_stream/domainrisk_feed/agent/stream/cel.yml.hbs",
    "/package/ti_domaintools/1.6.0/data_stream/domainrisk_feed/elasticsearch/ilm/default_policy.json",
    "/package/ti_domaintools/1.6.0/data_stream/domainrisk_feed/elasticsearch/ingest_pipeline/default.yml",
    "/package/ti_domaintools/1.6.0/data_stream/nad_feed/agent/stream/cel.yml.hbs",
    "/package/ti_domaintools/1.6.0/data_stream/nad_feed/elasticsearch/ilm/default_policy.json",
    "/package/ti_domaintools/1.6.0/data_stream/nad_feed/elasticsearch/ingest_pipeline/default.yml",
    "/package/ti_domaintools/1.6.0/data_stream/nod_feed/agent/stream/cel.yml.hbs",
    "/package/ti_domaintools/1.6.0/data_stream/nod_feed/elasticsearch/ilm/default_policy.json",
    "/package/ti_domaintools/1.6.0/data_stream/nod_feed/elasticsearch/ingest_pipeline/default.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_domaindiscovery/fields/base-fields.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_domaindiscovery/fields/beats.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_domaindiscovery/fields/ecs.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_domaindiscovery/fields/fields.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_domaindiscovery/fields/is-ioc-transform-source-false.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_domainhotlist/fields/base-fields.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_domainhotlist/fields/beats.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_domainhotlist/fields/ecs.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_domainhotlist/fields/fields.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_domainhotlist/fields/is-ioc-transform-source-false.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_domainrdap/fields/base-fields.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_domainrdap/fields/beats.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_domainrdap/fields/ecs.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_domainrdap/fields/fields.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_domainrdap/fields/is-ioc-transform-source-false.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_domainrisk/fields/base-fields.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_domainrisk/fields/beats.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_domainrisk/fields/ecs.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_domainrisk/fields/fields.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_domainrisk/fields/is-ioc-transform-source-false.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_nad/fields/base-fields.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_nad/fields/beats.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_nad/fields/ecs.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_nad/fields/fields.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_nad/fields/is-ioc-transform-source-false.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_nod/fields/base-fields.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_nod/fields/beats.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_nod/fields/ecs.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_nod/fields/fields.yml",
    "/package/ti_domaintools/1.6.0/elasticsearch/transform/latest_nod/fields/is-ioc-transform-source-false.yml"
  ],
  "policy_templates": [
    {
      "name": "domaintools",
      "title": "DomainTools Feeds",
      "description": "The DomainTools Feed provides real-time access to newly registered and observed domains, enabling proactive threat detection and defense.",
      "inputs": [
        {
          "type": "cel",
          "title": "Collect DomainTools Feeds",
          "description": "The DomainTools Feed provides real-time access to newly registered and observed domains, enabling proactive threat detection and defense."
        }
      ],
      "multiple": true,
      "deployment_modes": {
        "default": {
          "enabled": true
        },
        "agentless": {
          "enabled": true,
          "release": "beta"
        }
      }
    }
  ],
  "data_streams": [
    {
      "type": "logs",
      "dataset": "ti_domaintools.domaindiscovery_feed",
      "ilm_policy": "logs-ti_domaintools.domaindiscovery_feed-default_policy",
      "title": "DomainTools Domain Discovery Feed",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "api_url",
              "type": "text",
              "title": "DomainTools API URL",
              "description": "The URL of the DomainTools API.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "https://api.domaintools.com/v1"
            },
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Interval at which the feed will be pulled. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "10m"
            },
            {
              "name": "api_username",
              "type": "text",
              "title": "DomainTools API Username",
              "description": "DomainTools API Username",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "DomainTools API Username"
            },
            {
              "name": "api_key",
              "type": "password",
              "title": "DomainTools API Key",
              "description": "DomainTools API Key",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "session_id",
              "type": "text",
              "title": "Session ID",
              "description": "The Session ID to use in requesting feed.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "DomainToolsElasticSID"
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. Disabling the request tracer will delete any stored traces. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-cel.html#_resource_tracer_enable) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "DomainTools Domain Discovery Feed",
          "description": "Subscribe to DomainTools Domain Discovery Feed",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "ti_domaintools",
      "path": "domaindiscovery_feed"
    },
    {
      "type": "logs",
      "dataset": "ti_domaintools.domainhotlist_feed",
      "ilm_policy": "logs-ti_domaintools.domainhotlist_feed-default_policy",
      "title": "DomainTools Domain Hotlist Feed",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "api_url",
              "type": "text",
              "title": "DomainTools API URL",
              "description": "The URL of the DomainTools API.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "https://api.domaintools.com/v1"
            },
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Interval at which the feed will be pulled. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "10m"
            },
            {
              "name": "api_username",
              "type": "text",
              "title": "DomainTools API Username",
              "description": "DomainTools API Username",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "DomainTools API Username"
            },
            {
              "name": "api_key",
              "type": "password",
              "title": "DomainTools API Key",
              "description": "DomainTools API Key",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "session_id",
              "type": "text",
              "title": "Session ID",
              "description": "The Session ID to use in requesting feed.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "DomainToolsElasticSID"
            },
            {
              "name": "top",
              "type": "text",
              "title": "Top",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "300"
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. Disabling the request tracer will delete any stored traces. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-cel.html#_resource_tracer_enable) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "DomainTools Domain Hotlist Feed",
          "description": "Subscribe to DomainTools Domain Hotlist Feed",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "ti_domaintools",
      "path": "domainhotlist_feed"
    },
    {
      "type": "logs",
      "dataset": "ti_domaintools.domainrdap_feed",
      "ilm_policy": "logs-ti_domaintools.domainrdap_feed-default_policy",
      "title": "DomainTools Domain RDAP Feed",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "api_url",
              "type": "text",
              "title": "DomainTools API URL",
              "description": "The URL of the DomainTools API.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "https://api.domaintools.com/v1"
            },
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Interval at which the feed will be pulled. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "10m"
            },
            {
              "name": "api_username",
              "type": "text",
              "title": "DomainTools API Username",
              "description": "DomainTools API Username",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "DomainTools API Username"
            },
            {
              "name": "api_key",
              "type": "password",
              "title": "DomainTools API Key",
              "description": "DomainTools API Key",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "session_id",
              "type": "text",
              "title": "Session ID",
              "description": "The Session ID to use in requesting feed.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "DomainToolsElasticSID"
            },
            {
              "name": "top",
              "type": "text",
              "title": "Top",
              "description": "Limits the number of results in the response payload.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "100"
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. Disabling the request tracer will delete any stored traces. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-cel.html#_resource_tracer_enable) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "DomainTools Domain RDAP Feed",
          "description": "Subscribe to DomainTools Domain RDAP Feed",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "ti_domaintools",
      "path": "domainrdap_feed"
    },
    {
      "type": "logs",
      "dataset": "ti_domaintools.domainrisk_feed",
      "ilm_policy": "logs-ti_domaintools.domainrisk_feed-default_policy",
      "title": "DomainTools Domain Risk Feed",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "api_url",
              "type": "text",
              "title": "DomainTools API URL",
              "description": "The URL of the DomainTools API.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "https://api.domaintools.com/v1"
            },
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Interval at which the feed will be pulled. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "10m"
            },
            {
              "name": "api_username",
              "type": "text",
              "title": "DomainTools API Username",
              "description": "DomainTools API Username",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "DomainTools API Username"
            },
            {
              "name": "api_key",
              "type": "password",
              "title": "DomainTools API Key",
              "description": "DomainTools API Key",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "session_id",
              "type": "text",
              "title": "Session ID",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "DomainToolsElasticSID"
            },
            {
              "name": "top",
              "type": "text",
              "title": "Top",
              "description": "The Session ID to use in requesting feed.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "300"
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. Disabling the request tracer will delete any stored traces. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-cel.html#_resource_tracer_enable) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "DomainTools Domain Risk Feed",
          "description": "Subscribe to DomainTools Domain Risk Feed",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "ti_domaintools",
      "path": "domainrisk_feed"
    },
    {
      "type": "logs",
      "dataset": "ti_domaintools.nad_feed",
      "ilm_policy": "logs-ti_domaintools.nad_feed-default_policy",
      "title": "DomainTools Newly Active Domains Feed",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "api_url",
              "type": "text",
              "title": "DomainTools API URL",
              "description": "The URL of the DomainTools API.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "https://api.domaintools.com/v1"
            },
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Interval at which the feed will be pulled. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "10m"
            },
            {
              "name": "api_username",
              "type": "text",
              "title": "DomainTools API Username",
              "description": "DomainTools API Username",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "DomainTools API Username"
            },
            {
              "name": "api_key",
              "type": "password",
              "title": "DomainTools API Key",
              "description": "DomainTools API Key",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "session_id",
              "type": "text",
              "title": "Session ID",
              "description": "The Session ID to use in requesting feed.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "DomainToolsElasticSID"
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. Disabling the request tracer will delete any stored traces. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-cel.html#_resource_tracer_enable) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "DomainTools Newly Active Domains Feed",
          "description": "Subscribe to DomainTools Newly Active Domains Feed",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "ti_domaintools",
      "path": "nad_feed"
    },
    {
      "type": "logs",
      "dataset": "ti_domaintools.nod_feed",
      "ilm_policy": "logs-ti_domaintools.nod_feed-default_policy",
      "title": "DomainTools Newly Observed Domains Feed",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "api_url",
              "type": "text",
              "title": "DomainTools API URL",
              "description": "The URL of the DomainTools API.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "https://api.domaintools.com/v1"
            },
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Interval at which the feed will be pulled. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "10m"
            },
            {
              "name": "api_username",
              "type": "text",
              "title": "DomainTools API Username",
              "description": "DomainTools API Username",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "DomainTools API Username"
            },
            {
              "name": "api_key",
              "type": "password",
              "title": "DomainTools API Key",
              "description": "DomainTools API Key",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "session_id",
              "type": "text",
              "title": "Session ID",
              "description": "The Session ID to use in requesting feed.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "DomainToolsElasticSID"
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. Disabling the request tracer will delete any stored traces. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-cel.html#_resource_tracer_enable) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "DomainTools Newly Observed Domains Feed",
          "description": "Subscribe to DomainTools Newly Observed Domains Feed",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "ti_domaintools",
      "path": "nod_feed"
    }
  ]
}
