replace operator - Search Language Test (oxiclean)
- search test: replace operator through the UI.
comment splunk> start with '/'
open / (open the main interface)
comment Wait for server response 'completed'
waitForDispatchCompleted 5000
comment Change time line to 'All Time'
select //select[@id='timelineValues'] value=ALL_TIME
comment Clear search and hit report tab
type //textarea[@id='entry']
click //input[@id='entrySubmit'] (Click submit button)
comment Wait for server response 'completed'
waitForDispatchCompleted 10000
comment **** Replace Simple Case, single field value ****
type //textarea[@id='entry'] index::_internal | replace splunkd with SPLUNKD_PROCESS in sourcetype
click //input[@id='entrySubmit'] (Click submit button)
comment Wait for server response 'completed'
waitForDispatchCompleted 100000
waitForText //div[@id='r0']//div[@class='metaData'] *sourcetype=SPLUNKD_PROCESS*
verifyText //div[@id='r1']//div[@class='metaData'] *sourcetype=SPLUNKD_PROCESS*
verifyText //div[@id='r2']//div[@class='metaData'] *sourcetype=SPLUNKD_PROCESS*
comment Clear search and hit report tab
type //textarea[@id='entry']
click //input[@id='entrySubmit'] (Click submit button)
comment Wait for server response 'completed'
waitForDispatchCompleted 8000
comment **** replace failure; simple case, no args ****
type //textarea[@id='entry'] index::_internal | replace
click //input[@id='entrySubmit'] (Click submit button)
comment Expect and validate error notification due to missing args
waitForText //div[@id='msgNotificationContainer']//td[@class='ERROR'] Error*
verifyText //div[@id='msgNotificationContainer']//td[@class='ERROR'] *Error*operator*