# How to get the domain name from a fully qualified hostname via GROK

**URL:** <https://discuss.elastic.co/t/how-to-get-the-domain-name-from-a-fully-qualified-hostname-via-grok/205429>\
**Category:** Logstash\
**Created:** [October 28, 2019, 9:04am UTC](https://discuss.elastic.co/t/how-to-get-the-domain-name-from-a-fully-qualified-hostname-via-grok/205429 "2019-10-28T09:04:39Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![aolvikash](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@aolvikash](https://discuss.elastic.co/u/aolvikash)\
**Post date:** [October 28, 2019, 9:04am UTC](https://discuss.elastic.co/t/how-to-get-the-domain-name-from-a-fully-qualified-hostname-via-grok/205429/1 "2019-10-28T09:04:39Z")

</div>

How to get the domain name from a fully qualified hostname via GROK.

I have used the pipeline to extract a couple of details from filebeat and getting one of the fields as hostname, needs to fetch the domain name from a fully qualified hostname.

Here are a couple of examples:

Fully qualified hostname could be:

[host1.co.us](http://host1.co.us)  
[host2.ins.co.uk](http://host2.ins.co.uk)  
host3.ar.uk.local

The domain name for the above hostname should be as follows:

[co.us](http://co.us)  
[ins.co.uk](http://ins.co.uk)  
ar.uk.local

Thanks for your help in advance.

---

<div class="post-metadata">

**Author:** ![Michael\_Madden](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael_madden/32/46640_2.png) [@Michael\_Madden](https://discuss.elastic.co/u/Michael_Madden)\
**Post date:** [October 28, 2019, 2:18pm UTC](https://discuss.elastic.co/t/how-to-get-the-domain-name-from-a-fully-qualified-hostname-via-grok/205429/2 "2019-10-28T14:18:12Z")

</div>

Hello,

Thanks for reaching out. Just to clarify, are you using a logstash pipeline? If so would a grok pattern like the following work to break up the host name and domain name?

`%{DATA:host}\.%{GREEDYDATA:domain}`

Thanks.

---

<div class="post-metadata">

**Author:** ![aolvikash](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@aolvikash](https://discuss.elastic.co/u/aolvikash)\
**Post date:** [October 28, 2019, 2:25pm UTC](https://discuss.elastic.co/t/how-to-get-the-domain-name-from-a-fully-qualified-hostname-via-grok/205429/3 "2019-10-28T14:25:42Z")

</div>

Thanks a lot Michael. It works exactly what i need.

Have a great day !!

---

<div class="post-metadata">

**Author:** ![aolvikash](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@aolvikash](https://discuss.elastic.co/u/aolvikash)\
**Post date:** [October 29, 2019, 7:52am UTC](https://discuss.elastic.co/t/how-to-get-the-domain-name-from-a-fully-qualified-hostname-via-grok/205429/4 "2019-10-29T07:52:32Z")

</div>

Hi,

I have tried the above pattern in GROK debugger and it is working fine however when adding as ELK via dev toll then getting error on tild slice before dot "`%{DATA:host}\.%{GREEDYDATA:domain}`" any suggestion could be really helpfull.

![image](https://us1.discourse-cdn.com/elastic/original/3X/8/5/858c9dc2cdc23ab16e996b78c52a3eeb54e846e6.png)

---

<div class="post-metadata">

**Author:** ![aolvikash](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@aolvikash](https://discuss.elastic.co/u/aolvikash)\
**Post date:** [October 29, 2019, 9:07am UTC](https://discuss.elastic.co/t/how-to-get-the-domain-name-from-a-fully-qualified-hostname-via-grok/205429/5 "2019-10-29T09:07:21Z")

</div>

No worries, I have resolved the above issue !! Thanks for checking.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 26, 2019, 9:07am UTC](https://discuss.elastic.co/t/how-to-get-the-domain-name-from-a-fully-qualified-hostname-via-grok/205429/6 "2019-11-26T09:07:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
