| select operator - Search Language Test (REST)
- search test: select operator through the /v3/splunk/search REST interface. | ||
| comment | splunk> /v3/splunk/search - 'empty' | |
| openAndWait | /v3/splunk/search?q=page%200-100%20500%20[search]%20|%20outputxml | Perform an empty search via REST |
| comment | Validate result 'empty' | |
| verifyAttribute | //envelope/searchResults/results/@type | empty |
| comment | **** Select Simple Case "from results" **** | |
| openAndWait | /v3/splunk/search?q=page%200-100%20500%20[search%20index::_internal%20|%20select%20_punct%20from%20results]%20|%20outputxml | Perform search via REST interface - index::_internal | select _punct from results |
| comment | Validate field _PUNCT appears in the results | |
| verifyAttribute | //envelope/searchResults/results/@type | report |
| verifyAttribute | //envelope/searchResults/results/cols/col/@key | punct |
| verifyText | //envelope/searchResults/results/cols/col[@cd='1'] | punct |
| comment | **** Select Simple Case "from resultstable" **** | |
| openAndWait | /v3/splunk/search?q=page%200-100%20500%20[search%20index::_internal%20|%20select%20_punct%20from%20resultstable]%20|%20outputxml | Perform search via REST interface - 'index::_internal | select _punct from resultstable' |
| comment | Validate field _PUNCT appears in the results | |
| verifyAttribute | //envelope/searchResults/results/@type | report |
| verifyAttribute | //envelope/searchResults/results/cols/col/@key | punct |
| verifyText | //envelope/searchResults/results/cols/col[@cd='1'] | punct |
| comment | **** Select (7) fields using DB2 data **** | |
| openAndWait | /v3/splunk/search?q=page%200-100%20500%20[search%20index::sampledata%20|%20select%20_LEVEL,%20_TID,%20_FUNCTION,%20_NODE,%20_APPLICATION,%20_START,%20_STOP%20from%20results]%20|%20outputxml | Perform search via REST interface - 'index::sampledata | select _LEVEL, _TID, _FUNCTION, _NODE, _APPLICATION, _START, _STOP from results' |
| comment | Validate field _LEVEL appears in the results | |
| verifyText | //envelope/searchResults/results/cols/col[@cd='1'] | LEVEL |
| comment | Validate field _TID appears in the results | |
| verifyText | //envelope/searchResults/results/cols/col[@cd='2'] | TID |
| comment | Validate field _FUNCTION appears in the results | |
| verifyText | //envelope/searchResults/results/cols/col[@cd='3'] | FUNCTION |
| comment | Validate field _NODE appears in the results | |
| verifyText | //envelope/searchResults/results/cols/col[@cd='4'] | NODE |
| comment | Validate field _APPLICATION appears in the results | |
| verifyText | //envelope/searchResults/results/cols/col[@cd='5'] | APPLICATION |
| comment | Validate field _START appears in the results | |
| verifyText | //envelope/searchResults/results/cols/col[@cd='6'] | START |
| comment | Validate field _STOP appears in the results | |
| verifyText | //envelope/searchResults/results/cols/col[@cd='7'] | STOP |
| comment | **** Select failure; simple case, invalid args **** | |
| openAndWait | /v3/splunk/search?q=page%200-100%20500%20[search%20index::_internal%20|%20select%20_punct%20from]%20|%20outputxml | index::_internal | select _punct from |
| comment | Expect and validate error notification due to missing args | |
| verifyAttribute | //envelope/messages/msg/@type | ERROR |
| verifyText | //envelope/messages/msg | *error* |