counttable operator - Search Language Test (REST)
- search test: counttable operator through the /v3/splunk/search REST interface.
comment splunk> /v3/splunk/search - 'empty'
openAndWait /v3/splunk/search?q=page%200-100%20500%20[search]%20|%20outputxml Perform an empty search via REST
comment Validate result 'empty'
verifyAttribute //envelope/searchResults/results/@type empty
comment **** counttable failure; simple case, no args ****
openAndWait /v3/splunk/search?q=page%200-100%20500%20[search%20index::_internal%20|%20counttable]%20|%20outputxml Perform search via REST interface
comment Expect and validate error notification due to missing args
verifyAttribute //envelope/messages/msg/@type ERROR
verifyText //envelope/messages/msg Error*