Subsearches
-Asserts that you can use a subsearch to dynamically retrieve and filter based on extracted field values.
setTimeout 120000
comment Reset the field picker preference
open /v3/prefs/set?selectedKeys=host%20sourcetype%20source
comment Open the main interface
openAndWait /
comment Wait for page to load up
waitForDispatchCompleted 120000
comment switch to searching All Time
select timelineValues value=ALL_TIME
comment Check subsearches within where clauses
type entry source="*access.combined.log" sourcetype="access_combined" | where [search source="*access.combined.log" sourcetype="access_combined" | top 4 clientip | fields clientip | format]
click entrySubmit (Click submit button)
comment Wait for query to load
pause 500
waitForDispatchCompleted 60000
comment Verify we're starting with the right number of events
verifyText eventCount 4,131 results
click allFiltersTab
pause 500
waitForDispatchCompleted 60000
comment check 'clientip'
click //div[@id='allFiltersFilterLayer']//label[@term='clientip'] check the clientip checkbox.
click fieldApply Click the apply button to re-run the search.
pause 500
waitForDispatchCompleted 60000
pause 200
verifyElementPresent //div[@id='filterTabs']//div[@searchkey='clientip']
verifyText //div[@id='filterTabs']//div[@searchkey='clientip'] clientip (4)
comment verify that filtering works for indexed fields
comment Check a second subsearch in a where clause
type entry source="*access.combined.log" sourcetype="access_combined" | where [search source="*access.combined.log" sourcetype="access_combined" | stats count by clientip | where count < 50 | fields clientip | format]
click entrySubmit (Click submit button)
comment Wait for query to load
pause 500
waitForDispatchCompleted 60000
pause 500
verifyText eventCount 72 results
verifyElementPresent //div[@id='filterTabs']//div[@searchkey='clientip']
verifyText //div[@id='filterTabs']//div[@searchkey='clientip'] clientip (3)
comment Check a subsearch as sole member of a search clause
type entry [search source="*access.combined.log" sourcetype="access_combined" punct::*\"* | rare 10 punct | fields punct | format]
click entrySubmit (Click submit button)
comment Wait for query to load
pause 500
waitForDispatchCompleted 60000
pause 1000
comment Make sure the eventCount is visible.
verifyVisible eventCount
verifyText eventCount 10 results
comment check a subsearch living alongside other terms in the search clause
type entry source="*access.combined.log" sourcetype="access_combined" [search source="*access.combined.log" sourcetype="access_combined" punct::*\"* | rare 10 punct | fields punct | format]
click entrySubmit (Click submit button)
comment Wait for query to load
pause 500
waitForDispatchCompleted 60000
pause 500
comment Make sure the eventCount is visible.
verifyVisible eventCount
verifyText eventCount 10 results
comment Check a third subsearch in a where clause
type entry source="*access.combined.log" sourcetype="access_combined" punct::*\"* | where [search source="*access.combined.log" sourcetype="access_combined" punct::*\"* | top 1 punct | fields punct | format]
click entrySubmit (Click submit button)
comment Wait for query to load
pause 500
waitForDispatchCompleted 60000
pause 1000
verifyText eventCount 1,824 results