<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Tuning Configuration Event Hub in Microsoft Cloud Services App in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Tuning-Configuration-Event-Hub-in-Microsoft-Cloud-Services-App/m-p/688477#M114663</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I am having some trouble understanding the right configuration for collecting the Logs from the Event Hub of the App "Microsoft Cloud Services".&amp;nbsp;&lt;BR /&gt;From the documentation: &lt;A href="https://splunk.github.io/splunk-add-on-for-microsoft-cloud-services/Configureeventhubs/" target="_self"&gt;Configure Event Hubs&lt;/A&gt;&amp;nbsp; it is not clear how to set these three parameters for a Log Source that collect A LOT of logs every minute.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;interval --&amp;gt;&amp;nbsp; The number of seconds to wait before the Splunk platform runs the command again. The default is 3600 seconds.&lt;/STRONG&gt;&lt;BR /&gt;There is a way in the _internal logs to check when the command is executed?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;max_batch_size --&amp;gt; The maximum number of events to retrieve in one batch. The default is 300.&lt;/STRONG&gt;&lt;BR /&gt;This is pretty clear, but can we increase this value as much as we want? I believe we encounter some performance issue on that.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;max_wait_time --&amp;gt;&amp;nbsp; The maximum interval in seconds that the event processor will wait before processing. The default is 300 seconds.&lt;/STRONG&gt;&lt;BR /&gt;Processing what? Waiting for what?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Anyone know a configuration of values between these three fields that could optimize an Event Hub with thousands and thousands of Logs ??&lt;/P&gt;</description>
    <pubDate>Thu, 23 May 2024 14:34:01 GMT</pubDate>
    <dc:creator>dc17</dc:creator>
    <dc:date>2024-05-23T14:34:01Z</dc:date>
    <item>
      <title>Tuning Configuration Event Hub in Microsoft Cloud Services App</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Tuning-Configuration-Event-Hub-in-Microsoft-Cloud-Services-App/m-p/688477#M114663</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I am having some trouble understanding the right configuration for collecting the Logs from the Event Hub of the App "Microsoft Cloud Services".&amp;nbsp;&lt;BR /&gt;From the documentation: &lt;A href="https://splunk.github.io/splunk-add-on-for-microsoft-cloud-services/Configureeventhubs/" target="_self"&gt;Configure Event Hubs&lt;/A&gt;&amp;nbsp; it is not clear how to set these three parameters for a Log Source that collect A LOT of logs every minute.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;interval --&amp;gt;&amp;nbsp; The number of seconds to wait before the Splunk platform runs the command again. The default is 3600 seconds.&lt;/STRONG&gt;&lt;BR /&gt;There is a way in the _internal logs to check when the command is executed?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;max_batch_size --&amp;gt; The maximum number of events to retrieve in one batch. The default is 300.&lt;/STRONG&gt;&lt;BR /&gt;This is pretty clear, but can we increase this value as much as we want? I believe we encounter some performance issue on that.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;max_wait_time --&amp;gt;&amp;nbsp; The maximum interval in seconds that the event processor will wait before processing. The default is 300 seconds.&lt;/STRONG&gt;&lt;BR /&gt;Processing what? Waiting for what?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Anyone know a configuration of values between these three fields that could optimize an Event Hub with thousands and thousands of Logs ??&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 14:34:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Tuning-Configuration-Event-Hub-in-Microsoft-Cloud-Services-App/m-p/688477#M114663</guid>
      <dc:creator>dc17</dc:creator>
      <dc:date>2024-05-23T14:34:01Z</dc:date>
    </item>
  </channel>
</rss>

