| Subsearches
-Asserts that you can use a subsearch to dynamically retrieve and filter based on extracted field values. | ||
| setTimeout | 120000 | |
| comment | Reset the field picker preference | |
| open | /v3/prefs/set?selectedKeys=host%20sourcetype%20source | |
| comment | Open the main interface | |
| openAndWait | / | |
| comment | Wait for page to load up | |
| waitForDispatchCompleted | 120000 | |
| comment | switch to searching All Time | |
| select | timelineValues | value=ALL_TIME |
| comment | Check subsearches within where clauses | |
| type | entry | source="*access.combined.log" sourcetype="access_combined" | where [search source="*access.combined.log" sourcetype="access_combined" | top 4 clientip | fields clientip | format] |
| click | entrySubmit | (Click submit button) |
| comment | Wait for query to load | |
| pause | 500 | |
| waitForDispatchCompleted | 60000 | |
| comment | Verify we're starting with the right number of events | |
| verifyText | eventCount | 4,131 results |
| click | allFiltersTab | |
| pause | 500 | |
| waitForDispatchCompleted | 60000 | |
| comment | check 'clientip' | |
| click | //div[@id='allFiltersFilterLayer']//label[@term='clientip'] | check the clientip checkbox. |
| click | fieldApply | Click the apply button to re-run the search. |
| pause | 500 | |
| waitForDispatchCompleted | 60000 | |
| pause | 200 | |
| verifyElementPresent | //div[@id='filterTabs']//div[@searchkey='clientip'] | |
| verifyText | //div[@id='filterTabs']//div[@searchkey='clientip'] | clientip (4) |
| comment | verify that filtering works for indexed fields | |
| comment | Check a second subsearch in a where clause | |
| type | entry | source="*access.combined.log" sourcetype="access_combined" | where [search source="*access.combined.log" sourcetype="access_combined" | stats count by clientip | where count < 50 | fields clientip | format] |
| click | entrySubmit | (Click submit button) |
| comment | Wait for query to load | |
| pause | 500 | |
| waitForDispatchCompleted | 60000 | |
| pause | 500 | |
| verifyText | eventCount | 72 results |
| verifyElementPresent | //div[@id='filterTabs']//div[@searchkey='clientip'] | |
| verifyText | //div[@id='filterTabs']//div[@searchkey='clientip'] | clientip (3) |
| comment | Check a subsearch as sole member of a search clause | |
| type | entry | [search source="*access.combined.log" sourcetype="access_combined" punct::*\"* | rare 10 punct | fields punct | format] |
| click | entrySubmit | (Click submit button) |
| comment | Wait for query to load | |
| pause | 500 | |
| waitForDispatchCompleted | 60000 | |
| pause | 1000 | |
| comment | Make sure the eventCount is visible. | |
| verifyVisible | eventCount | |
| verifyText | eventCount | 10 results |
| comment | check a subsearch living alongside other terms in the search clause | |
| type | entry | source="*access.combined.log" sourcetype="access_combined" [search source="*access.combined.log" sourcetype="access_combined" punct::*\"* | rare 10 punct | fields punct | format] |
| click | entrySubmit | (Click submit button) |
| comment | Wait for query to load | |
| pause | 500 | |
| waitForDispatchCompleted | 60000 | |
| pause | 500 | |
| comment | Make sure the eventCount is visible. | |
| verifyVisible | eventCount | |
| verifyText | eventCount | 10 results |
| comment | Check a third subsearch in a where clause | |
| type | entry | source="*access.combined.log" sourcetype="access_combined" punct::*\"* | where [search source="*access.combined.log" sourcetype="access_combined" punct::*\"* | top 1 punct | fields punct | format] |
| click | entrySubmit | (Click submit button) |
| comment | Wait for query to load | |
| pause | 500 | |
| waitForDispatchCompleted | 60000 | |
| pause | 1000 | |
| verifyText | eventCount | 1,824 results |