Splunk Search

Help with segmenters.conf search.

khalidewaidah
Explorer

I tried to segment the log below using \s but it does not work, even after modifying segmenters.conf and props.conf.

2020-05-13 19:27:35,921  INFO com.edifecs.shared.events.transport.rmi.RmiBusesPublisher - Failed to obtain a reference to remote EventBus. Connection to rmi://BCKCMD1:1050/EventBus refused.

/opt/splunk/etc/apps/search/local/props.conf
[test]
.
.
.
.
.
.
SEGMENTATION = inner
SEGMENTATION-full= inner

/opt/splunk/etc/apps/search/local/segmenters.conf
[inner]
MAJOR = \s
MINOR =
0 Karma
Get Updates on the Splunk Community!

Splunk APM & RUM | Upcoming Planned Maintenance

There will be planned maintenance of the streaming infrastructure for Splunk APM and Splunk RUM in the coming ...

Part 2: Diving Deeper With AIOps

Getting the Most Out of Event Correlation and Alert Storm Detection in Splunk IT Service Intelligence   Watch ...

User Groups | Upcoming Events!

If by chance you weren't already aware, the Splunk Community is host to numerous User Groups, organized ...