Splunk Search

Help with segmenters.conf search.

khalidewaidah
Explorer

I tried to segment the log below using \s but it does not work, even after modifying segmenters.conf and props.conf.

2020-05-13 19:27:35,921  INFO com.edifecs.shared.events.transport.rmi.RmiBusesPublisher - Failed to obtain a reference to remote EventBus. Connection to rmi://BCKCMD1:1050/EventBus refused.

/opt/splunk/etc/apps/search/local/props.conf
[test]
.
.
.
.
.
.
SEGMENTATION = inner
SEGMENTATION-full= inner

/opt/splunk/etc/apps/search/local/segmenters.conf
[inner]
MAJOR = \s
MINOR =
0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!