timechart operator - Search Language Test (oxiclean)
- search test: timechart operator through the UI.
comment splunk> start with '/'
open / (open the main interface)
comment Wait for server response 'completed'
waitForDispatchCompleted 5000
comment Clear search and hit report tab
type //textarea[@id='entry']
click //input[@id='entrySubmit'] (Click submit button)
comment Wait for query to load
waitForDispatchCompleted 10000
comment **** Timechart Simple Case ****
type //textarea[@id='entry'] index::_internal | timechart avg(instantaneous_*)
click //input[@id='entrySubmit'] (Click submit button)
comment Wait for query to load
waitForDispatchCompleted 10000
comment Validate columns _time, avg(instantaneous_eps) and avg(instantaneous_kbps) appear in the report
verifyText //table[@id='reportTable']//th[@id='rpc1']//a[@class='reportColumnLabel'] _time
verifyText //table[@id='reportTable']//th[@id='rpc2']//a[@class='reportColumnLabel'] avg(instantaneous_eps)
verifyText //table[@id='reportTable']//th[@id='rpc3']//a[@class='reportColumnLabel'] avg(instantaneous_kbps)
comment Clear search and hit report tab
type //textarea[@id='entry']
click //input[@id='entrySubmit'] (Click submit button)
comment Wait for query to load
waitForDispatchCompleted 10000
comment Select 'All Time'
select //select[@id='timelineValues'] value=ALL_TIME
comment Wait for page to load up
waitForDispatchCompleted 5000
pause 5000
comment **** Timechart count(_raw) ****
type //textarea[@id='entry'] index::sampledata sourcetype::access_combined | timechart count(_raw) by useragent
click //input[@id='entrySubmit'] (Click submit button)
comment Wait for query to load
waitForDispatchCompleted 50000
comment Validate FlashChartLoaded
verifyFlashChartLoaded
comment Clear search and hit report tab
type //textarea[@id='entry']
click //input[@id='entrySubmit'] (Click submit button)
comment Wait for query to load
waitForDispatchCompleted 10000
comment Select 'All Time'
select //select[@id='timelineValues'] value=ALL_TIME
comment Wait for page to load up
waitForDispatchCompleted 5000
pause 5000
comment **** Timechart count (sans _raw) ****
type //textarea[@id='entry'] index::sampledata sourcetype::access_combined | timechart count by useragent
click //input[@id='entrySubmit'] (Click submit button)
comment Wait for query to load
waitForDispatchCompleted 10000
comment Validate FlashChartLoaded
verifyFlashChartLoaded
comment Clear search and hit report tab
type //textarea[@id='entry']
click //input[@id='entrySubmit'] (Click submit button)
comment Wait for query to load
waitForDispatchCompleted 10000
comment Select 'All Time'
select //select[@id='timelineValues'] value=ALL_TIME
comment Wait for page to load up
waitForDispatchCompleted 5000
pause 5000
comment **** Timechart indexed data over time ****
type //textarea[@id='entry'] index::_internal source::*metrics.log group=per_index_thruput | timechart span=1d sum(kb)
click //input[@id='entrySubmit'] (Click submit button)
comment Wait for query to load
waitForDispatchCompleted 10000
comment Validate FlashChartLoaded
verifyFlashChartLoaded
comment **** Timechart failure; simple case, no args ****
type //textarea[@id='entry'] index::_internal | timechart
click //input[@id='entrySubmit'] (Click submit button)
comment Expect and validate error notification due to missing args
waitForText //div[@id='msgNotificationContainer']//td[@class='ERROR'] Error*
verifyText //div[@id='msgNotificationContainer']//td[@class='ERROR'] *Must specify data field*
comment **** Timechart failure; simple case, invalid args ****
type //textarea[@id='entry'] index::_internal | timechart timechart
click //input[@id='entrySubmit'] (Click submit button)
comment Expect and validate error notification due to invalid args
waitForText //div[@id='msgNotificationContainer']//td[@class='ERROR'] Error*
verifyText //div[@id='msgNotificationContainer']//td[@class='ERROR'] *Invalid argument*