sof-elk
sof-elk copied to clipboard
Pull TLD from domains
can we pull TLD from domain data? Would be useful for pivoting to other intel sources, etc.
Prefect thing to write a new logstash filter plugin
https://github.com/weppos/publicsuffix-ruby
https://github.com/logstash-plugins/logstash-filter-tld
Enjoy!
also consider publicsuffix.org
going to close this one since wildcard matching in KQL has been viable for a while.