when we use this grok:
match => { "message" => "^%{URIHOST:domain}" }
It successfully matches domains like so:
domain: mydomain.net
however when creating a visualization any 2LD's with a trailing number is separated into separate variables.
For instance in the visual the above domain is displayed like this:
domain: mydomain.net
However this domain "mydomain1.net" is being separated into two domains, the 2LD and the SLD, displayed like this:
domain: mydomain1
domain: net
why is this happening and how can I fix it?
Thank you.