select operator - Search Language Test (REST)
- search test: select operator through the /v3/splunk/search REST interface.
comment splunk> /v3/splunk/search - 'empty'
openAndWait /v3/splunk/search?q=page%200-100%20500%20[search]%20|%20outputxml Perform an empty search via REST
comment Validate result 'empty'
verifyAttribute //envelope/searchResults/results/@type empty
comment **** Select Simple Case "from results" ****
openAndWait /v3/splunk/search?q=page%200-100%20500%20[search%20index::_internal%20|%20select%20_punct%20from%20results]%20|%20outputxml Perform search via REST interface - index::_internal | select _punct from results
comment Validate field _PUNCT appears in the results
verifyAttribute //envelope/searchResults/results/@type report
verifyAttribute //envelope/searchResults/results/cols/col/@key punct
verifyText //envelope/searchResults/results/cols/col[@cd='1'] punct
comment **** Select Simple Case "from resultstable" ****
openAndWait /v3/splunk/search?q=page%200-100%20500%20[search%20index::_internal%20|%20select%20_punct%20from%20resultstable]%20|%20outputxml Perform search via REST interface - 'index::_internal | select _punct from resultstable'
comment Validate field _PUNCT appears in the results
verifyAttribute //envelope/searchResults/results/@type report
verifyAttribute //envelope/searchResults/results/cols/col/@key punct
verifyText //envelope/searchResults/results/cols/col[@cd='1'] punct
comment **** Select (7) fields using DB2 data ****
openAndWait /v3/splunk/search?q=page%200-100%20500%20[search%20index::sampledata%20|%20select%20_LEVEL,%20_TID,%20_FUNCTION,%20_NODE,%20_APPLICATION,%20_START,%20_STOP%20from%20results]%20|%20outputxml Perform search via REST interface - 'index::sampledata | select _LEVEL, _TID, _FUNCTION, _NODE, _APPLICATION, _START, _STOP from results'
comment Validate field _LEVEL appears in the results
verifyText //envelope/searchResults/results/cols/col[@cd='1'] LEVEL
comment Validate field _TID appears in the results
verifyText //envelope/searchResults/results/cols/col[@cd='2'] TID
comment Validate field _FUNCTION appears in the results
verifyText //envelope/searchResults/results/cols/col[@cd='3'] FUNCTION
comment Validate field _NODE appears in the results
verifyText //envelope/searchResults/results/cols/col[@cd='4'] NODE
comment Validate field _APPLICATION appears in the results
verifyText //envelope/searchResults/results/cols/col[@cd='5'] APPLICATION
comment Validate field _START appears in the results
verifyText //envelope/searchResults/results/cols/col[@cd='6'] START
comment Validate field _STOP appears in the results
verifyText //envelope/searchResults/results/cols/col[@cd='7'] STOP
comment **** Select failure; simple case, invalid args ****
openAndWait /v3/splunk/search?q=page%200-100%20500%20[search%20index::_internal%20|%20select%20_punct%20from]%20|%20outputxml index::_internal | select _punct from
comment Expect and validate error notification due to missing args
verifyAttribute //envelope/messages/msg/@type ERROR
verifyText //envelope/messages/msg *error*