I have a newly tokenized field of type text for domains. It is a reverse path hierarchy tokenizer on the "."
So a field like "adservice.google.com" becomes the following 3 tokens:
I assumed I could then search the field, from say kibana, with the syntax:
But it finds all fields with a "com" token, so I'll get microsoft.com and amazon.com, etc.
I tried encasing in quotes and escaping the ".", but neither helped.
A single wildcard, or regex both work as expected:
Can someone point me to an explanation of why the original syntax returns unexpected results?
Edit: elastic stack 6.3.2