Getting Data In

Eventhubs - Splunk Add-ON for ms cloud services partitions

zippo706
Explorer

I was using the MS Azure add-on for splunk.  Trying to switch to Splunk Add-on for MS cloud services.   One thing i noticed is that the event hub i was using is appending event hub events into the same splunk event. 

 Ie, instead of 8 events in Event Hub, and 8 events in splunk (which i saw in ms azure add-on for splunk),

I get 2 events of 4 body.records[].service_principal_name.    The # of appended events is related to the # of partitiions, however, this thing doesn't seem to work w/ 1 partition.  Keep getting can not find partition 0 of 0 when the eventhub is 1 partition.  Formatting is TERRIBLE and it takes 30 seconds to render the 1st record in a search since raw so large.

Any ideas what's going on here?   This supposed to be by design?

Labels (1)
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...