Limit DNS Querys

I receive a distributed DoS/DDoS UDP attack to a DNS Service, how can I detect and filter dinamically ?. I supposed from /ip firewall filter with “limit”, but I can´t do it.

Thanks a Lot