Splunk Search

How to extract domain and top level domain?

moayadalghamdi
Path Finder

Dears

 

 I need your help in extracting the domain and top level domain from dns queries where:

 

Query Field                  |         extracted field

Account.fb.com         .         Fb.com

Aa.bb.cc.com              .         Cc.com

Www.google.com      .        Google.com

 

 

 

Thanks in advance 

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| rex field=queryField ".*\.(?<extractedField>\w+\.\w+)"

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust
| eval extractedField=mvjoin(mvindex(split(queryField,"."),-2,2),".")
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| rex field=queryField ".*\.(?<extractedField>\w+\.\w+)"
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...