Dears
I need your help in extracting the domain and top level domain from dns queries where:
Query Field | extracted field
Account.fb.com . Fb.com
Aa.bb.cc.com . Cc.com
Www.google.com . Google.com
Thanks in advance
| eval extractedField=mvjoin(mvindex(split(queryField,"."),-2,2),".")
| rex field=queryField ".*\.(?<extractedField>\w+\.\w+)"