Dynamic Groups AD

I have several untrusted domains feeding into my scom environment via gateways. I want to build a dynamic groups for things like domain controllers for each domain so I can build out dashboards based on these. but I am having trouble figuring out how to make this happen. Everything I have tried so far is not working as I expected.

I have used the domain name (domain. Se) from the DNS name to include machines from other domains into groups. And then use a second condition that the computer has to have the active directory domain controller computer role.

I found a good answer for how to do this. Changed the scope to AD Computer 2016 role and then used netbios domain name equals for my criteria.