| Filtering on extracted fields.
-Verifies that the field picker works to remove and add extracted fields -Verifies that the field picker works to filter on extracted fields, add field to search, clear field | ||
| setTimeout | 120000 | |
| comment | Reset the field picker preference | |
| open | /v3/prefs/set?selectedKeys=host%20sourcetype%20source | |
| comment | Open the main interface | |
| openAndWait | / | |
| comment | Wait for page to load up | |
| waitForDispatchCompleted | 60000 | |
| comment | Do a search for some events with lots of keys | |
| type | entry | webdev 10.1.1 ( source="*apache.error.log" OR source="*access.combined.log" ) |
| select | timelineValues | value=ALL_TIME |
| click | entrySubmit | (Click submit button) |
| waitForDispatchCompleted | 60000 | |
| comment | verify that filtering works for extracted fields | |
| click | allFiltersTab | |
| waitForDispatchCompleted | 120000 | |
| pause | 1000 | |
| comment | Check that the field picker loaded. | |
| verifyElementPresent | allFiltersFilterLayer | |
| comment | Check that the field picker menu has at least one field in it. | |
| verifyElementPresent | //div[@id='allFiltersFilterLayer']//ul/li/label | |
| comment | Check that a field called 'module' was extracted. | |
| verifyElementPresent | //div[@id='allFiltersFilterLayer']//label[@term='module'] | |
| comment | check 'module' | |
| click | //div[@id='allFiltersFilterLayer']//label[@term='module'] | |
| comment | Click the Apply button to re-run the search. | |
| click | fieldApply | |
| pause | 500 | |
| waitForDispatchCompleted | 60000 | |
| pause | 500 | |
| comment | Verify that we extracted 6 values for module | |
| verifyText | //div[@id='filterTabs']/div[@searchkey='module'] | module (6) |
| comment | Click the module tab to open the layer. | |
| click | //div[@id='filterTabs']/div[@searchkey='module'] | |
| waitForDispatchCompleted | 60000 | |
| comment | Verify that clicking a filter narrows the search to just those key values | |
| click | //tr[@termkey='module' and @term='articles']/td | |
| pause | 1000 | |
| waitForDispatchCompleted | 60000 | |
| verifyText | currentFilter | Filtering on module="articles" |
| comment | uncheck 'module' | |
| pause | 500 | |
| click | allFiltersTab | |
| waitForDispatchCompleted | 120000 | |
| pause | 500 | |
| comment | Uncheck 'module' | |
| verifyElementPresent | //div[@id='allFiltersFilterLayer']//ul/li/label | |
| click | //div[@id='allFiltersFilterLayer']//label[@term='module'] | Uncheck the module checkbox. |
| click | fieldApply | Click the Apply button to re-run the search. |
| pause | 500 | |
| waitForDispatchCompleted | 60000 | |
| comment | Turn on several more fields, for more complicated cases. | |
| click | allFiltersTab | |
| waitForDispatchCompleted | 120000 | |
| click | //div[@id='allFiltersFilterLayer']//label[@term='module'] | |
| click | //div[@id='allFiltersFilterLayer']//label[@term='func'] | |
| click | //div[@id='allFiltersFilterLayer']//label[@term='sql_query'] | |
| click | fieldApply | Click the Apply button to re-run the search. |
| pause | 500 | |
| waitForDispatchCompleted | 60000 | |
| pause | 200 | |
| comment | Test that adding filter A clears filter B. | |
| click | //div[@id='filterTabs']//div[@searchkey='module'] | |
| click | //tr[@termkey='module' and @term='articles']/td | |
| pause | 1000 | |
| waitForDispatchCompleted | 60000 | |
| verifyText | currentFilter | Filtering on module="articles" |
| click | //tr[@termkey='module' and @term='roles']/td | |
| pause | 1000 | |
| waitForDispatchCompleted | 60000 | |
| verifyText | currentFilter | Filtering on module="roles" |
| comment | Check that the 'add to search' button works for adding 1 extracted field. | |
| click | //div[@id='filterLayers']//div[@key='module']//a[@class='addFilterToSearch'] | |
| waitForDispatchCompleted | 60000 | |
| verifyText | //div[@id='r0']//pre | 10.1.1.002 - - [05/Aug/2005:17:26:35 -0700] "GET /index.php/articles/news/13 HTTP/1.1" 200 6610 "http://webdev:2000/index.php?module=roles&func=showloginform&login_subnav=support_nav&redirecturl=/index.php/articles/news/20" "Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/412.6 (KHTML, like Gecko) Safari/412.2" |
| comment | Filter on another extracted field. | |
| click | //div[@id='filterTabs']//div[@searchkey='func'] | |
| click | //tr[@termkey='func' and @term='showusers']/td | |
| pause | 1000 | |
| waitForDispatchCompleted | 60000 | |
| verifyText | //div[@id='r0']//pre | 10.1.1.015 - - [04/Aug/2005:12:54:51 -0700] "GET //themes/ComBeta/images/splunk.gif HTTP/1.1" 404 304 "http://webdev:2000/index.php?module=roles&type=admin&func=showusers&uid=8" "Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/412 (KHTML, like Gecko) Safari/412" |
| click | //tr[@termkey='func' and @term='updaterole']/td | |
| pause | 1000 | |
| waitForDispatchCompleted | 60000 | |
| pause | 1000 | |
| verifyText | //div[@id='r0']//pre | 10.1.1.015 - - [04/Aug/2005:12:55:12 -0700] "POST /index.php?module=roles&type=admin&func=updaterole HTTP/1.1" 302 5 "http://webdev:2000/index.php?module=roles&type=admin&func=modifyrole&uid=130" "Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/412 (KHTML, like Gecko) Safari/412" |
| comment | Check that the 'add to search' button works for adding a second extracted field. | |
| click | //div[@id='filterLayers']//div[@key='module']//a[@class='addFilterToSearch'] | |
| waitForDispatchCompleted | 60000 | |
| verifyValue | entry | webdev 10.1.1 ( source="*apache.error.log" OR source="*access.combined.log" ) module="roles" func="updaterole" |
| verifyText | eventCount | 5 results |
| comment | Check that the 'add to search' button works for adding an indexed field on top of extracted fields. | |
| click | //div[@id='filterTabs']//div[@searchkey='sourcetype'] | |
| click | //tr[@term='access_combined']/td | |
| pause | 1000 | |
| waitForDispatchCompleted | 60000 | |
| click | //div[@id='filterLayers']//div[@key='sourcetype']//a[@class='addFilterToSearch'] | |
| verifyValue | entry | webdev 10.1.1 ( source="*apache.error.log" OR source="*access.combined.log" ) module="roles" func="updaterole" sourcetype="access_combined" |