where operator - Search Language Test (oxiclean)
- search test: where operator through the UI.
comment splunk> start with '/'
open / (open the main interface)
comment Wait for server response 'completed'
waitForDispatchCompleted 5000
comment Change time line to 'All Time'
select //select[@id='timelineValues'] value=ALL_TIME
comment Clear search and hit report tab
type //textarea[@id='entry']
click //input[@id='entrySubmit'] (Click submit button)
comment Wait for server response 'completed'
waitForDispatchCompleted 10000
comment **** Where Simple Case (match value of single field)****
type //textarea[@id='entry'] index::sampledata sourcetype::db2_diag | where PID="2120"
click //input[@id='entrySubmit'] (Click submit button)
comment Wait for server response 'completed'
waitForDispatchCompleted 10000
verifyAttribute //span[@id="eventCount"]/@count 24
comment Clear search and hit report tab
type //textarea[@id='entry']
click //input[@id='entrySubmit'] (Click submit button)
comment Wait for server response 'completed'
waitForDispatchCompleted 8000
comment **** Where following replace operator ****
type //textarea[@id='entry'] index::_internal | replace *host with NEW_HOST_NAME in host | where host="NEW_HOST_NAME"
click //input[@id='entrySubmit'] (Click submit button)
comment Wait for server response 'completed'
waitForDispatchCompleted 100000
verifyText //div[@id='r0']//div[@class='metaData'] *HOST=*NEW_HOST_NAME*
verifyText //div[@id='r1']//div[@class='metaData'] *HOST=*NEW_HOST_NAME*
verifyText //div[@id='r2']//div[@class='metaData'] *HOST=*NEW_HOST_NAME*
comment Clear search and hit report tab
type //textarea[@id='entry']
click //input[@id='entrySubmit'] (Click submit button)
comment Wait for server response 'completed'
waitForDispatchCompleted 8000
comment **** where failure; simple case, invalid args ****
type //textarea[@id='entry'] index::_internal | where *
click //input[@id='entrySubmit'] (Click submit button)
comment Expect and validate error notification due to invalid args
waitForText //div[@id='msgNotificationContainer']//td[@class='ERROR'] Error*
verifyText //div[@id='msgNotificationContainer']//td[@class='ERROR'] *Error evaluating expression*