regex operator - Search Language Test (oxiclean)
- search test: regex operator through the UI.
comment splunk> start with '/'
open / (open the main interface)
comment Wait for server response 'completed'
waitForDispatchCompleted 5000
comment Change time line to 'All Time'
select //select[@id='timelineValues'] value=ALL_TIME
comment Clear search and hit report tab
type //textarea[@id='entry']
click //input[@id='entrySubmit'] (Click submit button)
comment Wait for server response 'completed'
waitForDispatchCompleted 10000
comment **** Regex Simple Case (match all)****
type //textarea[@id='entry'] index::sampledata source::syslogsample.log.sample | regex _raw = "^.+$"
click //input[@id='entrySubmit'] (Click submit button)
comment Wait for server response 'completed'
waitForDispatchCompleted 10000
verifyAttribute //span[@id="eventCount"]/@count 4593
comment **** Regex Simple Case (matching keyward and IP)****
type //textarea[@id='entry'] index::sampledata | regex _raw = "critical.+61\.\d+\.\d+\.\d+"
click //input[@id='entrySubmit'] (Click submit button)
comment Wait for server response 'completed'
waitForDispatchCompleted 10000
verifyText //div[@id='r0']//pre *system-critical*Src IP session limit! From 61.129.90.106*
verifyText //div[@id='r1']//pre *system-critical*Src IP session limit! From 61.129.90.106*
verifyText //div[@id='r2']//pre *system-critical*Src IP session limit! From 61.129.90.106*
verifyText //div[@id='r3']//pre *system-critical*Src IP session limit! From 61.129.90.106*
verifyText //div[@id='r4']//pre *system-critical*Src IP session limit! From 61.129.90.106*