Maybe you can clarify "translate the splunk index data." Do you mean to dump raw Splunk data into JSON? How is that useful? In any case, you can always use tojson command after any search you do. For example, splunk search "index=_* earliest=-4h |stats count by index |tojson" >count.json
... View more