chart operator - Search Language Test (REST)
- search test: chart operator through the /v3/splunk/search REST interface.
comment splunk> /v3/splunk/search - 'empty'
openAndWait /v3/splunk/search?q=page%200-100%20500%20[search]%20|%20outputxml Perform an empty search via REST
comment Validate result 'unknown'
verifyAttribute //envelope/searchResults/results/@type unknown
comment **** Chart Simple Case, Timechart Style ****
openAndWait /v3/splunk/search?q=page%200-100%20500%20[search%20index::_internal%20|%20chart%20avg(instantaneous_*)%20by%20_time]%20|%20outputxml Perform search via REST interface
comment Validate columns _time, avg(instantaneous_eps) and avg(instantaneous_kbps) appear in the report
verifyText //envelope/searchResults/results/cols/col[@cd='1'] _time
verifyText //envelope/searchResults/results/cols/col[@cd='2'] avg(instantaneous_eps)
verifyText //envelope/searchResults/results/cols/col[@cd='3'] avg(instantaneous_kbps)
comment **** Chart failure; simple case, invalid args ****
openAndWait /v3/splunk/search?q=page%200-100%20500%20[search%20index::_internal%20|%20chart%20chart]%20|%20outputxml Perform search via REST interface
comment Expect and validate error notification due to invalid args
verifyAttribute //envelope/messages/msg/@type ERROR
verifyText //envelope/messages/msg Error*
comment **** Chart failure; simple case, no args ****
openAndWait /v3/splunk/search?q=page%200-100%20500%20[search%20index::_internal%20|%20chart]%20|%20outputxml Perform search via REST interface
comment Expect and validate error notification due to missing args
verifyAttribute //envelope/messages/msg/@type ERROR
verifyText //envelope/messages/msg Error*