| where operator - Search Language Test (REST)
- search test: where operator through the /v3/splunk/search REST interface. | ||
| comment | splunk> /v3/splunk/search - 'empty' | |
| openAndWait | /v3/splunk/search?q=page%200-100%20500%20[search]%20|%20outputxml | Perform an empty search via REST |
| comment | Validate result 'empty' | |
| verifyAttribute | //envelope/searchResults/results/@type | empty |
| comment | **** Where Simple Case (match value of single field)**** | |
| openAndWait | /v3/splunk/search?q=page%200-100%20500%20[search%20index::sampledata%20sourcetype::db2_diag%20|%20where%20PID=%222120%22]%20|%20outputxml | Perform search via REST interface - 'index::sampledata sourcetype::db2_diag | where PID="2120"' |
| comment | Validate PID 2120 matches a result | |
| verifyText | //envelope/searchResults/results/r | *PID*2120* |
| comment | **** Where following replace operator **** | |
| openAndWait | /v3/splunk/search?q=page%200-100%20500%20[search%20index::_internal%20|%20replace%20*host%20with%20NEW_HOST_NAME%20in%20host%20|%20where%20host=%22NEW_HOST_NAME%22]%20|%20outputxml | Perform search via REST interface - 'index::_internal | replace *host with NEW_HOST_NAME in host | where host="NEW_HOST_NAME"' |
| comment | Validate NEW_HOST_NAME matches a result | |
| verifyText | //envelope/searchResults/results/r | *NEW_HOST_NAME* |
| comment | **** where failure; simple case, invalid args **** | |
| openAndWait | /v3/splunk/search?q=page%200-100%20500%20[search%20index::_internal%20|%20where%20*]%20|%20outputxml | Perform search via REST interface - 'index::_internal | where *' |
| comment | Expect and validate error notification due to invalid args | |
| verifyAttribute | //envelope/messages/msg/@type | ERROR |
| verifyText | //envelope/messages/msg | *Unable to evaluate* |