Since you are dropping the file before indexing, your regex needs to match the syntax of the raw event data, not the formatted data.
So if your domain you want to drop is company.com, this will look something like this in the logs:
(3)company(2)com(0)
So you may want to have a regex like this:
\(\d\)company\(\d\)com
... View more