Identify hot spots

In this topic, you will learn how to use the Crime Analysis solution by exploring the analytical workflows in the Identify hot spots task item in the Crime Analysis Desktop ArcGIS Pro project.

Identify repeat problem locations with 80/20 analysis

Repeat problem locations in policing are specific locations that consistently generate a disproportionate number of police incidents, such as crime reports or calls for service. This concept, known as the Pareto principle or the 80/20 rule, posits that within a jurisdiction, a small number of locations (for example, 20 percent) account for a majority of incidents (for example, 80 percent). Recognizing these locations is vital for law enforcement agencies because it enables them to focus resources and interventions where they are most needed, often resulting in more effective crime prevention and improved community safety. Operationally, agencies use information about repeat problem locations to guide patrol deployment, inform problem-oriented policing strategies, and support collaborative efforts with community partners.

This workflow uses the 80/20 Analysis tool in ArcGIS Pro, applying the Pareto principle to help agencies quickly identify the small percentage of locations responsible for the majority of incidents. By visualizing and prioritizing these problem locations, the tool empowers agencies to make data-driven decisions and allocate resources efficiently for maximum operational impact.

What you need

This workflow requires a point layer of incidents, such as crimes, calls for service, or arrests.

Workflow steps

The workflow contains the following steps:

  1. Understand the workflow: Review how the 80/20 Analysis tool identifies repeat problem locations and confirm that you have an incident point layer to analyze.
  2. Prepare the analysis map: Create a new map, add the incident layer to be analyzed, and rename the map to reflect the analysis being performed.
  3. Select incidents (optional): Use Select Layer By Attribute to narrow the incident layer to the specific subset of records (for example, crime type) to analyze.
  4. Select timeframe (optional): Use Select Layer By Date And Time to further narrow the selection to incidents occurring within a specific date range.
  5. Run 80/20 Analysis tool: Run the 80/20 Analysis tool to generate an output point layer of repeat problem locations.
  6. Adjust drawing order and visibility (optional): Reorder layers or turn layer visibility on or off in the Contents pane to make the map easier to read.
  7. Interpret results: Open the output attribute table to review incident counts, percentages, and cumulative percentages for each location, ranked from highest to lowest.
  8. Modify default colors (optional): Change the color ramp or class colors used to symbolize the repeat problem locations.
  9. Add labels (optional): Add an Arcade expression-based label showing the address and incident count/percentage for each location.
  10. Hide locations with lower incident counts (optional): Apply a definition query to display only locations at or above a chosen incident-count threshold.
  11. Create an information product (optional): Share the results as a map layout, report, or web layer for stakeholders.

What you get

Completion of the workflow results in the following outputs:

  • A map of your analysis results that can be used to create stakeholder information products.
  • A repeat problem locations layer. This layer is symbolized by graduated color and size to emphasize the top 20 percent of locations by incident count. The layer attribute table is sorted by incident count in descending order so that the highest-volume locations appear first. For each location, you can view the incident count and the percentage of overall incidents that count represents. In addition, each location has a Cumulative Incident Percentage value and a Cumulative Location Percentage value. The values in these fields represent the cumulative total for that location and all other locations with a higher incident count. For example, if the location with the 20th-highest incident count total has a Cumulative Incident Percentage value of 80.2, the top 20 locations collectively account for 80.2 percent of all incidents in the data set. Likewise, if that location has a Cumulative Location Percentage of 20.7, those top 20 locations together account for only 20.7 percent of unique locations in the data set.

References

  • Clarke, Ronald V., and John E. Eck. 2005. Crime Analysis for Problem Solvers in 60 Small Steps. Washington, DC: Office of Community Oriented Policing Services, U.S. Department of Justice.
  • Weisburd, David, Elizabeth R. Groff, and Sue-Ming Yang. 2012. The Criminology of Place: Street Segments and Our Understanding of the Crime Problem. New York: Oxford University Press.

Identify hot streets with 80/20 analysis

One of the most consistent findings in environmental criminology is that a large majority of crime and disorder incidents occur along a small proportion of street segments within a municipality. Known as "hot streets," these locations help law enforcement agencies prioritize their intervention efforts and are easy to communicate because they correspond to the street network officers use every day. This approach supports the broader body of place-based policing research, including studies of crime concentration at micro-places (Weisburd, Groff, and Yang 2012). To identify hot streets, crime analysts use the 80/20 Analysis tool in ArcGIS Pro.

In this workflow, you will create a layer that identifies hot streets, which can be used to support focused police and community interventions designed to reduce and prevent crime.

What you need

This workflow requires:

  • A point layer of incidents (For example, crimes, calls for service, or arrests.)
  • A line layer of street segments.

Workflow steps

The workflow contains the following steps:

  1. Understand the workflow: Review how the 80/20 Analysis tool identifies hot street segments and confirm that you have an incident layer to analyze.
  2. Prepare the analysis map: Create a new map, add the incident layer to be analyzed, and rename the map to reflect the analysis being performed.
  3. Select incidents (optional): Use Select Layer By Attribute to narrow the incident layer to the specific subset of records to analyze.
  4. Select timeframe (optional): Use Select Layer By Date And Time to further narrow the selection to a specific date range.
  5. Run 80/20 Analysis tool: Run the 80/20 Analysis tool with the Closest Feature aggregation method against the street segments layer to generate an output line layer of hot street segments.
  6. Interpret results: Open the output attribute table to review incident counts, percentages, cumulative percentages, and incidents-per-mile/kilometer for each street segment.
  7. Modify default colors (optional): Change the color ramp or class colors used to symbolize the hot streets.
  8. Add labels (optional): Add an Arcade expression-based label showing the address range, street name, and incident count/percentage for each segment.
  9. Hide locations with lower incident counts (optional): Apply a definition query to display only street segments at or above a chosen incident-count threshold.
  10. Create an information product: Share the results as a map layout, report, or web layer for stakeholders.

What you get

Completion of the workflow results in the following outputs:

  • A map of your analysis results that can be used to create stakeholder information products.
  • A hot streets layer. This line layer is symbolized by graduated color and size to emphasize the top 20 percent of streets by incident count. The attribute table of this layer is sorted by incident count in descending order so that the highest-volume street segments appear first. For each street segment, you can view the count of incidents occurring on that street segment and the percentage of overall incidents that count represents. In addition, each street segment has a Cumulative Incident Percentage value and a Cumulative Location Percentage value. The values in these fields represent the cumulative total for that street segment plus all other street segments with a higher incident count. For example, if a street segment with the 20th-highest incident count total has a Cumulative Incident Percentage value of 80.2, the top 20 street segments collectively account for 80.2 percent of all incidents in the data set. Likewise, if that street segment has a Cumulative Location Percentage of 20.7, those top 20 street segments together account for only 20.7 percent of unique locations in the data set.

Workflow notes

  • By default, the hot streets layer is symbolized by the Incident Count field, which counts the number of incidents occurring on each segment. However, because all street segments are not all equal in length, longer street segments can naturally have more incidents. To account for variation in street segment length, you can change the symbolization to the Incidents Per Mile or Incidents Per Kilometer field. These fields divide the number of incidents by the length of the street segment to provide a normalized value for comparing incident frequency among street segments.
  • The 80/20 Analysis tool includes Attribute Matching, an optional parameter that can be used to further refine your results. By default, the tool snaps each incident to the nearest street segment it finds; however in some cases, such as where streets intersect at an acute angle, the nearest street segment may differ from the street on which the incident actually occurred. To ensure that the incident location is matched properly to the correct street segment, you can use this parameter to require the street name field in the incident layer to correspond to the street name field in the street segments layer. For this parameter to work as expected, the values in both fields must match exactly.

References

  • Clarke, Ronald V., and John E. Eck. 2005. Crime Analysis for Problem Solvers in 60 Small Steps. Washington, DC: Office of Community Oriented Policing Services, U.S. Department of Justice.

  • Weisburd, David, Elizabeth R. Groff, and Sue-Ming Yang. 2012. The Criminology of Place: Street Segments and Our Understanding of the Crime Problem. New York: Oxford University Press.

Summarize incidents by area (hot areas)

Hot areas analysis is an aggregate approach to hot spot identification that counts incidents within existing administrative boundaries such as census tracts, beats, reporting districts, or patrol divisions. Because the results align directly with an agency's existing command and resource-allocation structure, this method is often used for high-level strategic planning, resource deployment across patrol areas, and performance reporting to command staff or external stakeholders. Comparing incident volumes across these administrative geographies helps commanders identify which areas may require additional staffing, overtime, or targeted crime-reduction strategies.

The primary ArcGIS Pro geoprocessing tool used is the Summarize Incident Count tool (part of the Crime Analysis toolset), which counts incident points falling within each polygon of the chosen administrative boundary layer.

What you need

  • An incident (point) layer that contains the crime or disorder events to be analyzed.
  • A polygon layer that represents the administrative area boundaries to be used for the analysis (for example, beats, districts, census tracts).

Workflow steps

  1. Understand the workflow: Review how the Summarize Incident Count tool aggregates incidents by administrative area and confirm that you have both an incident layer and an area boundary layer.
  2. Prepare the analysis map: Create a new map, add both the incident layer and the administrative area polygon layer, and rename the map to reflect the analysis being performed.
  3. Select incidents (optional): Use Select Layer By Attribute to narrow the incident layer to the specific subset of records to analyze.
  4. Select timeframe (optional): Use Select Layer By Date And Time to further narrow the selection to a specific date range.
  5. Run Summarize Incident Count tool: Run the Summarize Incident Count tool to count incidents within each administrative area, optionally grouping counts by an attribute such as year or crime type.
  6. Adjust drawing order and visibility (optional): Reorder layers or turn layer visibility on or off to make the map easier to read.
  7. Interpret results: Review the output layer, which is symbolized with graduated colors based on the total incident count for each area.
  8. Modify default colors (optional): Change the color ramp, classification method (for example, Equal Interval, Standard Deviation), or number of classes.
  9. Add labels (optional): Add an Arcade expression-based label showing the area name and total incident count.
  10. Add a chart symbol (optional): Add a bar chart symbology layer to visualize grouped incident counts (for example, by year) alongside the graduated color map.
  11. Create an information product (optional): Share the results as a map layout, report, or web layer for stakeholders.

What you get

The workflow produces a polygon layer of administrative areas symbolized by total (and optionally grouped) incident counts using a graduated color scheme. Police leadership can use this output to compare crime volumes across beats, districts, or other administrative boundaries, informing staffing decisions, resource allocation, patrol area redesign, and reporting to city leadership or the community about where crime is concentrated at a strategic level.

Workflow notes

  • Because administrative areas frequently vary in size and population, analysts should be cautious about directly comparing raw incident counts across areas of very different size; normalizing by area or population may be appropriate for some comparisons.
  • Analysts commonly use Equal Interval or Standard Deviation classification methods in addition to Natural Breaks, and five or fewer classes are recommended for map readability.

Create kernel density hot spots

Kernel density estimation (KDE) is one of the most widely used methods for identifying microlevel crime hot spots—small geographic areas of concentrated incident activity that do not correspond to administrative boundaries or street segments. Research on hot spots policing, including the systematic reviews by Braga, Papachristos, and Hureau (2014), has consistently found that police interventions focused on small, high-activity places are among the most effective crime-reduction strategies available to agencies, often producing measurable reductions without merely displacing crime to nearby areas. This workflow creates a continuous density surface that highlights where incidents cluster most intensely, which analysts can use to identify micro hot spots for focused patrol, problem-solving, or investigative resource deployment.

What you need

  • An ArcGIS Spatial Analyst extension license. For licensing and access information, see Enable the Spatial Analyst extension.
  • An incident (point or polyline) layer that contains the crime or disorder events to be analyzed.
  • Optionally, a barrier feature layer (line or polygon), such as a municipal boundary, to constrain the analysis extent.

Workflow steps

  1. Understand the workflow: Review how the Kernel Density tool identifies micro hot spots and confirm that the Spatial Analyst extension is available.
  2. Prepare the analysis map: Create a new map, add the incident layer to be analyzed, and rename the map to reflect the analysis being performed.
  3. Select incidents (optional): Use Select Layer By Attribute to narrow the incident layer to a specific subset of records.
  4. Select timeframe (optional): Use Select Layer By Date And Time to further narrow the selection to a specific date range.
  5. Run Kernel Density tool: Run the Kernel Density tool with a chosen cell size, search radius, area units, and calculation method to generate a density raster.
  6. Style micro hot spots raster layer: Reclassify the raster into four Equal Interval classes, label and color the classes to emphasize areas of high and highest density, and adjust transparency and resampling for a smoother appearance.
  7. Convert raster layer to polygons (optional): Use the Value Percentile Contour tool to convert the top percentile of the density raster into a polygon hot spot layer.
  8. Convert multipart polygon to single part polygon: Use the Multipart To Singlepart tool to split the combined multipart polygon output into individual hot spot features.
  9. Style hot spot polygon layer (optional): Remove the fill color and adjust the outline of the polygon hot spot layer for better visibility.
  10. Count incidents in polygons (optional): Use the Summarize Incident Count tool to count incidents occurring within each polygon hot spot.
  11. Adjust drawing order and visibility (optional): Reorder layers or turn layer visibility on or off to make the map easier to read.
  12. Create an information product (optional): Share the results as a map layout, report, or web layer for stakeholders.

What you get

The workflow produces a density raster layer highlighting micro hot spots, which can optionally be converted into a polygon layer with incident counts for each discrete hot spot area. Police agencies use these outputs to identify precise locations for directed patrol, hot spot policing initiatives, and problem-oriented policing projects, concentrating limited officer time on the specific micro-places responsible for the greatest share of crime and disorder.

Workflow notes

  • Search radius and cell size significantly affect results; analysts should test multiple combinations, starting with a search radius of approximately 300 meters (1,000 feet) and the data-driven recommended cell size, and adjust as needed.
  • The Value Percentile Contour percentile value (for example, 99.9) should be adjusted based on the number and distribution of hot spots found in the study area.

References

  • Braga, Anthony A., Andrew V. Papachristos, and David M. Hureau. 2014. “The Effects of Hot Spots Policing on Crime: An Updated Systematic Review and Meta-Analysis.” Justice Quarterly 31 (4): 633–63. https://doi.org/10.1080/07418825.2012.673632.

Identify hot spots using density-based clustering

Density-based clustering offers an alternative to kernel density estimation for identifying microlevel crime hot spots. Rather than producing a continuous raster surface, this machine-learning approach uses algorithms such as DBSCAN, HDBSCAN, or OPTICS to group individual incidents into discrete clusters based on a minimum number of points and a search distance, and it produces a point output that can be immediately joined to the original incident data for further analysis. This approach avoids some of the interpretive challenges of kernel density (such as translating cell size and search radius into intuitive parameters) and can also incorporate a time dimension to detect space-time clusters, which can help identify emerging crime series or short-term hot spots that a static density surface might not reveal as clearly. The primary ArcGIS Pro geoprocessing tool used is Density-based Clustering. This workflow does not require the Spatial Analyst extension, which makes it a useful alternative for agencies without that license.

What you need

  • An incident (point) layer that contains the crime or disorder events to be analyzed.

Workflow steps

  1. Understand the workflow: Review how the Density-based Clustering tool identifies clusters of incidents and confirm that you have an incident layer to analyze.
  2. Prepare the analysis map: Create a new map, add the incident layer to be analyzed, and rename the map to reflect the analysis being performed.
  3. Select incidents (optional): Use Select Layer By Attribute to narrow the incident layer to a specific subset of records.
  4. Select timeframe (optional): Use Select Layer By Date And Time to further narrow the selection to a specific date range.
  5. Run Density-based Clustering tool: Run the tool (typically using the DBSCAN method) with a minimum features per cluster and search distance, and optionally a time field and interval, to assign each incident to a cluster ID.
  6. Join density cluster layer to incident layer: Use the Add Join tool to join the cluster output back to the original incident layer by Object ID/Source ID so cluster membership is visible on each incident record.
  7. Filter for cluster incidents: Apply a definition query excluding records with a Cluster ID of -1 so that only clustered incidents are displayed.
  8. Create density cluster polygons (optional): Use the Minimum Bounding Geometry tool to draw an envelope polygon around each cluster for use as a response or briefing area.
  9. Remove fill color from polygon layer (optional): Adjust the cluster polygon symbology to show only an outline for better visibility.
  10. Adjust drawing order and visibility (optional): Reorder layers or turn layer visibility on or off to make the map easier to read.
  11. Create an information product (optional): Share the results as a map layout, report, or web layer for stakeholders (noting joined layers must first be exported before publishing).

What you get

The workflow produces a point layer identifying which incidents belong to a spatial (or space-time) cluster, joined to the original incident attributes, plus an optional bounding polygon layer around each cluster. Police agencies can use these outputs to identify emerging or established hot spots without needing a specialized extension license, define response or deployment areas around each cluster, and track incident volumes within those areas over time.

Workflow notes

  • Joined layers cannot be published directly to a web layer; use the Export Features tool first to create a standalone layer for sharing.
  • The Minimum Bounding Geometry tool will also create a bounding polygon for the 'no cluster' value (-1); apply a definition query to hide it.

Find overlapping hot spots shared by two layers

Some law enforcement and public safety agencies pursue strategies that address multiple categories of risk simultaneously, focusing resources on locations where more than one type of safety concern overlaps: for example, areas where both violent crime and traffic crashes cluster together. Targeting these shared hot spots can make proactive interventions more efficient, since a single location-based strategy (such as increased visibility patrol or environmental modifications) may simultaneously reduce multiple types of harm. This approach reflects broader hot spots policing research showing that a small number of places generate a disproportionate share of many different types of incidents (Weisburd et al., 2012), and extends that concept to cross-category analysis.

The primary ArcGIS Pro geoprocessing tools used are Kernel Density, run separately on each incident layer; Value Percentile Contours, used to extract the hottest areas of each layer; and Pairwise Intersect, used to find the overlap.

What you need

  • An ArcGIS Spatial Analyst extension license (for the Kernel Density and Value Percentile Contours tools). For licensing and access information, see Enable the Spatial Analyst extension.
  • Two separate incident (point or polyline) layers that represent the two categories of safety concern to be compared (for example, a crime incident layer and a traffic crash layer).

Workflow steps

  1. Understand the workflow: Review how kernel density and intersection analysis can identify hot spots common to two incident layers, and confirm that the Spatial Analyst extension is available.
  2. Prepare the analysis map: Create a new map, add both incident layers to be analyzed, and rename the map to reflect the analysis being performed.
  3. Select incidents from first layer (optional): Use Select Layer By Attribute to narrow the first incident layer to a specific subset of records.
  4. Select timeframe from first layer (optional): Use Select Layer By Date And Time to further narrow the first layer's selection to a specific date range.
  5. Run Kernel Density tool on first layer: Run the Kernel Density tool on the first incident layer to produce a density raster, noting the cell size used for reuse on the second layer.
  6. Run Value Percentile Contours tool on first density layer: Convert the first density raster into a polygon layer that represents the top percentile (for example, top 1 percent) of hot spot values.
  7. Select incidents from second layer (optional): Use Select Layer By Attribute to narrow the second incident layer to a specific subset of records.
  8. Select timeframe from second layer (optional): Use Select Layer By Date And Time to further narrow the second layer's selection to a specific date range.
  9. Run Kernel Density tool on second layer: Run the Kernel Density tool on the second incident layer using the same cell size and comparable parameters as the first layer.
  10. Run Value Percentile Contours tool on second density layer: Convert the second density raster into a polygon layer that represents the same top percentile of hot spot values.
  11. Run Pairwise Intersect tool: Intersect the two top-percentile polygon layers to identify the areas where both layers' hot spots overlap.
  12. Style overlapping hot spots polygon layer: Remove the polygon fill color and increase the outline width to make the shared hot spot boundaries stand out.
  13. Adjust drawing order and visibility (optional): Reorder layers or turn layer visibility on or off to make the map easier to read.
  14. Create an information product (optional): Share the results as a map layout, report, or web layer for stakeholders.

What you get

The workflow produces a polygon layer that represents the specific areas where the hottest micro hot spots of two different incident types overlap. Police agencies (often in coordination with traffic safety, code enforcement, or other public safety partners) can use this shared hot spot layer to design combined operational detail zones, deploy multi-purpose patrol or enforcement strategies, and prioritize locations where addressing one category of risk may have collateral benefits for another.

Workflow notes

  • The same cell size and comparable search radius should be used for both Kernel Density runs to ensure a valid comparison between the two density surfaces.
  • The Value Percentile Contours percentile threshold (default 99, using the Geodesic method) may need to be adjusted upward or downward depending on whether the resulting shared hot spots are too large or too small.

References

  • Weisburd, David, Elizabeth R. Groff, and Sue-Ming Yang. 2012. The Criminology of Place: Street Segments and Our Understanding of the Crime Problem. New York: Oxford University Press.

Identify statistically significant hot spots

When police agencies focus resources on high-crime areas, they often need to demonstrate with statistical rigor that the areas selected truly have elevated, nonrandom concentrations of crime, particularly when requesting additional funding, applying for grant programs, or defending resource allocation decisions to city leadership or the community. This workflow uses the Getis-Ord Gi* statistic to identify statistically significant hot and cold spots, which means that the observed clustering of incidents is very unlikely to have occurred by chance. The result provides a defensible, evidence-based justification for directing police resources to specific areas and can support both operational deployment decisions and grant or funding applications.

The primary ArcGIS Pro geoprocessing tool used is the Optimized Hot Spot Analysis tool, which automatically builds an analysis grid, aggregates incident counts, and calculates the Gi* statistic for each cell.

What you need

  • An incident (point) layer that contains the crime or disorder events to be analyzed.
  • Optionally, a polygon layer that defines the bounding area where incidents can occur (for example, a jurisdiction or administrative boundary).

Workflow steps

  1. Understand the workflow: Review how the Optimized Hot Spot Analysis tool uses the Gi* statistic to identify statistically significant hot and cold spots.
  2. Prepare the analysis map: Create a new map, add the incident layer to be analyzed, and rename the map to reflect the analysis being performed.
  3. Select incidents (optional): Use Select Layer By Attribute to narrow the incident layer to a specific subset of records.
  4. Select timeframe (optional): Use Select Layer By Date And Time to further narrow the selection to a specific date range.
  5. Run Optimized Hot Spot Analysis tool: Run the tool using a hexagon grid aggregation method (and optionally a bounding polygon) to calculate statistically significant hot and cold spots.
  6. Adjust drawing order and visibility (optional): Reorder layers or turn layer visibility on or off to make the map easier to read.
  7. Adjust hot spot layer transparency (optional): Reduce the layer's transparency so the underlying basemap remains visible.
  8. Hide non-significant cells (optional): Set the 'Not Significant' class symbol to no color and no outline so only significant hot/cold spots are visible.
  9. Create an information product (optional): Share the results as a map layout, report, or web layer for stakeholders.

What you get

The workflow produces a polygon (grid cell) layer symbolized to show statistically significant hot spots and cold spots based on the Gi* statistic. Because the clustering shown is statistically validated rather than simply visual, police agencies can use this output as defensible evidence to justify the geographic focus of patrol, investigative, or crime-reduction resources, and to support funding requests or strategic crime-reduction grant applications.

Workflow notes

  • By default, the tool automatically determines cell size and neighborhood search distance from the distribution of the data; these can be manually adjusted if the resulting hot spots are too large or too small.
  • Providing a bounding polygon (such as a jurisdiction boundary) helps ensure the statistical analysis only considers areas where incidents could plausibly occur.

Create hot spot predictions using repeat/near-repeat victimization analysis

Repeat and near-repeat (RNR) victimization analysis is based on the well-established criminological finding that after a crime occurs at a location, that location and nearby locations experience a statistically elevated risk of victimization for a limited period, with that risk declining as time and distance from the originating incident increase (Johnson and Bowers 2004; Ratcliffe and Rengert 2008). This pattern is well documented for offenses such as residential burglary and shootings. When RNR patterns are confirmed in an agency's data, they can be used to generate short-term crime-risk predictions that direct patrol, investigative, and community resources to places that are more likely to experience a related incident in the near future, which supports efforts to apprehend active offenders and prevent repeat victimization.

This multitool workflow uses the Export Near Repeat Calculator Table tool, the standalone Near Repeat Calculator application, and the Calculate Prediction Zones tool (and optionally, the Repeat and Near Repeat Classification tool) to generate the final risk prediction layer.

What you need

  • An ArcGIS Spatial Analyst extension license. For licensing and access information, see Enable the Spatial Analyst extension.
  • The free, grant-funded Near Repeat Calculator application developed by Jerry Radcliffe.
  • An incident (point) layer that contains the crime events to be analyzed (ideally a specific, narrowly defined offense type, such as residential burglary).
  • A Professional Plus user type for the optional historical-pattern visualization.

Workflow steps

  1. Understand the workflow: Review the concept of repeat and near-repeat victimization and confirm that the Spatial Analyst extension and Near Repeat Calculator application are available.
  2. Prepare the analysis map: Create a new map, add the incident layer to be analyzed, and rename the map to reflect the analysis being performed.
  3. Select incidents (optional): Use Select Layer By Attribute to narrow the incident layer to a specific subset of records.
  4. Select timeframe (optional): Use Select Layer By Date And Time to further narrow the selection to a specific date range.
  5. Prepare data for Near Repeat Calculator: Use the Export Near Repeat Calculator Table tool to export the incident layer to a CSV file that contains date and x,y coordinate fields.
  6. Interpret Near Repeat Calculator results: Review the HTML output report to determine whether statistically significant repeat or near-repeat patterns exist, and at what spatial and temporal bandwidths.
  7. Understand repeat and near-repeat victimization risk predictions: Review how the Calculate Prediction Zones tool uses the confirmed spatial and temporal bandwidths to generate short-term risk prediction areas.
  8. Run Calculate Prediction Zones tool: Run the tool using the statistically significant spatial and temporal bandwidth values to generate raster and polygon risk prediction outputs.
  9. Interpret Calculate Prediction Zones results: Review the raster and polygon risk prediction outputs, which show areas where repeat or near-repeat incidents are most likely to occur in the near future.
  10. Style risk prediction layer: Reclassify the raster into four Equal Interval classes with descriptive labels (for example, Moderate risk, Highest risk), and adjust transparency and resampling.
  11. Explore RNR patterns in historical data (optional): Use the Repeat and Near Repeat Classification tool to classify historical incidents as originators, repeats, or near-repeats and visualize their spatiotemporal linkages, optionally in a 3D scene (requires a Professional Plus user type).
  12. Adjust drawing order and visibility (optional): Reorder layers or turn layer visibility on or off to make the map easier to read.
  13. Create an information product (optional): Share the results as a map layout, report, or web layer for stakeholders.

What you get

The workflow produces a short-term crime risk prediction raster and corresponding polygon layer that highlight where future repeat or near-repeat incidents of a specific crime type are most likely to occur, based on the statistically validated spatial and temporal decay patterns found in the agency's own historical data. Optionally, it also produces a point and connector-line layer showing historically linked repeat/near-repeat incident chains. Police agencies use these risk prediction outputs to inform daily or weekly deployment of proactive patrol and investigative resources aimed at intercepting active offenders and preventing additional victimizations, and can use the historical linkage output to support case-clearance and investigative lead development.

Workflow notes

  • Risk prediction zones are based solely on spatial and temporal proximity to recent incidents; they do not incorporate socioeconomic, demographic, or other structural variables, nor arrest data, and should be interpreted accordingly.
  • Analysts typically test multiple temporal-bandwidth combinations (for example, short-term vs. long-term patterns) to build a complete picture of RNR patterns. Chainey (2021) recommends an iterative testing approach starting with seven 3-day bands.

References

  • Chainey, Spencer. 2021. Understanding Crime: Analyzing the Geography of Crime. Redlands, CA: Esri Press.

  • Johnson, Shane D., and Kate J. Bowers. 2004. “The Burglary as Clue to the Future: The Beginnings of Prospective Hot-Spotting.” European Journal of Criminology 1 (2): 237–55. https://doi.org/10.1177/1477370804041252.

  • Ratcliffe, Jerry H., and George F. Rengert. 2008. “Near-Repeat Patterns in Philadelphia Shootings.” Security Journal 21 (1–2): 58–76. https://doi.org/10.1057/palgrave.sj.8350068.

Explore temporal characteristics of a hot spot

Identifying where crime concentrates is only part of an effective hot spot policing strategy; agencies also need to understand when a given hot spot is most active in order to schedule patrol and other interventions efficiently. This workflow uses a calendar heat chart, combined with an interactive map selection, to reveal hour-of-day and day-of-week patterns for incidents occurring specifically within a chosen hot spot. This temporal profiling supports more precise scheduling of directed patrols, saturation details, or other interventions so that resources are deployed during the times the hot spot is actually most active, rather than uniformly across all shifts.

The primary ArcGIS Pro tool used in this workflow is the Calendar Heat Chart (a native ArcGIS Pro charting capability), combined with the Select By Lasso interactive selection tool.

What you need

  • An existing map that contains a hot spot layer of interest (for example, a kernel density raster or a hot area polygon layer) along with the underlying incident point layer.

Workflow steps

  1. Understand the workflow: Review how a Calendar Heat Chart reveals hour-by-weekday incident patterns and confirm that you have an existing hot spot map to work from.
  2. Open a map with a hot spot: Open an existing map from the project's Maps folder that contains the hot spot of interest.
  3. Create a calendar heat chart (hour by weekday): Select the incident layer and create a Calendar Heat Chart configured to aggregate incident counts by hour of day and day of week.
  4. Select incidents within the hot spot using the Lasso: Filter the chart by selection, and then use the Select By Lasso tool to trace and select only the incidents within the hot spot.
  5. Export the chart: Export the filtered chart as a graphic, table, or copy it to the clipboard for use in bulletins, briefings, or reports.

What you get

The workflow produces a calendar heat chart showing incident counts by hour of day and day of week for the incidents within a specific hot spot, which can be exported as an image, table, or pasted directly into briefing documents. Police agencies use this temporal profile to schedule directed patrols, saturation patrols, or other interventions to coincide with the specific hours and days the hot spot is most active, improving the efficiency and effectiveness of place-based crime-reduction strategies.

Workflow notes

  • The Select By Lasso tool allows an analyst to trace an irregular hot spot boundary directly on the map, rather than being limited to the exact boundary of a polygon output, which can be useful when working with raster-based hot spot outputs.