I was using the MS Azure add-on for splunk. Trying to switch to Splunk Add-on for MS cloud services. One thing i noticed is that the event hub i was using is appending event hub events into the same splunk event.
Ie, instead of 8 events in Event Hub, and 8 events in splunk (which i saw in ms azure add-on for splunk),
I get 2 events of 4 body.records[].service_principal_name. The # of appended events is related to the # of partitiions, however, this thing doesn't seem to work w/ 1 partition. Keep getting can not find partition 0 of 0 when the eventhub is 1 partition. Formatting is TERRIBLE and it takes 30 seconds to render the 1st record in a search since raw so large.
Any ideas what's going on here? This supposed to be by design?