Splunk Search

Encode time series data in a single field


Good day everyone. I am looking for a way to be able to send a single event that would include some timeseries data for the last few days.

    "service": "A",
    "series": <???>

Is there a way for Splunk to look at a single field/attribute and pull out time series data? For example something simple like -

4|                  x
3|         x
2|      x       x
1|  x
    t0  t1  t2  t3  t4

I am flexible on the client side and could encode the payload in whatever format is needed.

0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!