Splunk Search

## How to report a peak count per day based on a per minute count?

I'm trying to determine a way to report a peak per minute count per day (in this case, the last 30 days)

If i run this for a full 24 hour day, i get the peak for that one day:

index=foo source=bar
| bucket span=1m _time
| stats count by _time
| sort -count

But if i run this for the last 5 days, i'll just get a single per minute peak for the total 5 day period, and what i need is the per-day peak tabled.

My ultimate goal in the end would be to average that 30d per minute peak, but that might need to be done in a separate search.

Solution
Try this:

index=foo source=bar | timechart span=1m count | timechart span=1d max(count). This will give you the max count per minute for each day.

Hi @karlduncans

Is there a way how to get also a minute in which maximum happened? I am struggling to even come with and idea how to get it there.

@Vebloud @allanw_splunk - Are you able to figure it out how to add the minute in the table. I am also facing the same problem and wanting to know if you have figured out any solution for this

