Splunk Search

What are the top hours

Stives
Explorer

Dear Splunkers,
running version 9.3.1 and I would like to perform a search in which I would like to identify what are the most common hours trucks have been visiting my site location.
My search query is following:

| addinfo
| eval _time = strptime(Start_time,"%m/%d/%Y %H:%M")
| addinfo
| where _time>=info_min_time AND (_time<=info_max_time OR info_max_time="+Infinity")
| search Plate!=0
| search Location="*"
| timechart span=1h count by Plate limit=50


Like this Im able see trucks visiting location by time in a span.
How to continue to display what are the most common hours during which my trucks visiting locations.
Thank you

Labels (3)
0 Karma

dural_yyz
Motivator

Can you provide an anonymized sample of what this search displays and an example record of what you want the final output to be?

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Also you should define what is your synonym for “common hours”?
0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...