Getting Data In

Eventhubs - Splunk Add-ON for ms cloud services partitions

zippo706
Explorer

I was using the MS Azure add-on for splunk.  Trying to switch to Splunk Add-on for MS cloud services.   One thing i noticed is that the event hub i was using is appending event hub events into the same splunk event. 

 Ie, instead of 8 events in Event Hub, and 8 events in splunk (which i saw in ms azure add-on for splunk),

I get 2 events of 4 body.records[].service_principal_name.    The # of appended events is related to the # of partitiions, however, this thing doesn't seem to work w/ 1 partition.  Keep getting can not find partition 0 of 0 when the eventhub is 1 partition.  Formatting is TERRIBLE and it takes 30 seconds to render the 1st record in a search since raw so large.

Any ideas what's going on here?   This supposed to be by design?

Labels (1)
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...