| regex operator - Search Language Test (oxiclean)
- search test: regex operator through the UI. | ||
| comment | splunk> start with '/' | |
| open | / | (open the main interface) |
| comment | Wait for server response 'completed' | |
| waitForDispatchCompleted | 5000 | |
| comment | Change time line to 'All Time' | |
| select | //select[@id='timelineValues'] | value=ALL_TIME |
| comment | Clear search and hit report tab | |
| type | //textarea[@id='entry'] | |
| click | //input[@id='entrySubmit'] | (Click submit button) |
| comment | Wait for server response 'completed' | |
| waitForDispatchCompleted | 10000 | |
| comment | **** Regex Simple Case (match all)**** | |
| type | //textarea[@id='entry'] | index::sampledata source::syslogsample.log.sample | regex _raw = "^.+$" |
| click | //input[@id='entrySubmit'] | (Click submit button) |
| comment | Wait for server response 'completed' | |
| waitForDispatchCompleted | 10000 | |
| verifyAttribute | //span[@id="eventCount"]/@count | 4593 |
| comment | **** Regex Simple Case (matching keyward and IP)**** | |
| type | //textarea[@id='entry'] | index::sampledata | regex _raw = "critical.+61\.\d+\.\d+\.\d+" |
| click | //input[@id='entrySubmit'] | (Click submit button) |
| comment | Wait for server response 'completed' | |
| waitForDispatchCompleted | 10000 | |
| verifyText | //div[@id='r0']//pre | *system-critical*Src IP session limit! From 61.129.90.106* |
| verifyText | //div[@id='r1']//pre | *system-critical*Src IP session limit! From 61.129.90.106* |
| verifyText | //div[@id='r2']//pre | *system-critical*Src IP session limit! From 61.129.90.106* |
| verifyText | //div[@id='r3']//pre | *system-critical*Src IP session limit! From 61.129.90.106* |
| verifyText | //div[@id='r4']//pre | *system-critical*Src IP session limit! From 61.129.90.106* |