where operator - Search Language Test (REST)
- search test: where operator through the /v3/splunk/search REST interface.
comment splunk> /v3/splunk/search - 'empty'
openAndWait /v3/splunk/search?q=page%200-100%20500%20[search]%20|%20outputxml Perform an empty search via REST
comment Validate result 'empty'
verifyAttribute //envelope/searchResults/results/@type empty
comment **** Where Simple Case (match value of single field)****
openAndWait /v3/splunk/search?q=page%200-100%20500%20[search%20index::sampledata%20sourcetype::db2_diag%20|%20where%20PID=%222120%22]%20|%20outputxml Perform search via REST interface - 'index::sampledata sourcetype::db2_diag | where PID="2120"'
comment Validate PID 2120 matches a result
verifyText //envelope/searchResults/results/r *PID*2120*
comment **** Where following replace operator ****
openAndWait /v3/splunk/search?q=page%200-100%20500%20[search%20index::_internal%20|%20replace%20*host%20with%20NEW_HOST_NAME%20in%20host%20|%20where%20host=%22NEW_HOST_NAME%22]%20|%20outputxml Perform search via REST interface - 'index::_internal | replace *host with NEW_HOST_NAME in host | where host="NEW_HOST_NAME"'
comment Validate NEW_HOST_NAME matches a result
verifyText //envelope/searchResults/results/r *NEW_HOST_NAME*
comment **** where failure; simple case, invalid args ****
openAndWait /v3/splunk/search?q=page%200-100%20500%20[search%20index::_internal%20|%20where%20*]%20|%20outputxml Perform search via REST interface - 'index::_internal | where *'
comment Expect and validate error notification due to invalid args
verifyAttribute //envelope/messages/msg/@type ERROR
verifyText //envelope/messages/msg *Unable to evaluate*