I have just found a solution for the eventhub offset issue within the MSCS app. Just deactivate the modular input, then go to Splunk\var\lib\splunk\modinputs\mscs_azure_event_hub and delete the according file [eventhubnamespace]-[eventhub]-$Default.v1.ckpt and reactivate the input. Splunk will recreate the file with a corrected timestamp and will reload the missing events from the eventhub.
... View more