Finding full domain that is triggering IPS alert for a blocked TLD

Hello,

We’re getting a burst of IPS alerts from a device on our network trying to query a domain with a .to TLD. However, I’m not able to locate anywhere that shows the domain that’s actually being queried, only the alert that says a .to domain is being queried, and the related Suricata logs which are too long to display in the Alta portal. Is there somewhere I can go that shows the full logs and what the actual domain triggering this rule is?

This is the alerts we get:

And these are what I can see when searching logs for the destination IP of the device that’s attempting these queries, even if I export these from the GUI they’re still cut off around the “wire/pcap” point so exporting doesn’t give any information that’s not displayed here:

Thanks in advance for anyone that has any advice