Splunk Search

What are the top hours

Stives
Explorer

Dear Splunkers,
running version 9.3.1 and I would like to perform a search in which I would like to identify what are the most common hours trucks have been visiting my site location.
My search query is following:

| addinfo
| eval _time = strptime(Start_time,"%m/%d/%Y %H:%M")
| addinfo
| where _time>=info_min_time AND (_time<=info_max_time OR info_max_time="+Infinity")
| search Plate!=0
| search Location="*"
| timechart span=1h count by Plate limit=50


Like this Im able see trucks visiting location by time in a span.
How to continue to display what are the most common hours during which my trucks visiting locations.
Thank you

Labels (3)
0 Karma

dural_yyz
Motivator

Can you provide an anonymized sample of what this search displays and an example record of what you want the final output to be?

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Also you should define what is your synonym for “common hours”?
0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...