Performance reference for the Azure Event Hub input in the Splunk Add-on for Microsoft Cloud Services¶
The following tables contain reference information about performance testing of the Azure Event Hub input in the Splunk Add-on for Microsoft Cloud Services. Use this information to enhance the performance of your own Azure Event Hub data collection tasks.
Many factors impact performance results, including file size, file compression, event size, deployment architecture, batch size for Event Hub file size, and hardware. Results represent reference information and do not represent performance in all environments.
Version 5.0.0 Event Hub performance characteristics¶
Common architecture setup |
Scenario |
Event type |
Event Size |
Ingest Rate |
IDM CPU |
---|---|---|---|---|---|
Splunk platform environment - Victoria Search Head Cluster
|
1 input 16 partition eventhub |
Non-JSON |
1 KB |
2124 kb/s |
N/A |
16 inputs 16 partition eventhub |
Non-JSON |
1 KB |
7018 kb/s |
N/A |
|
1 input 32 partition eventhub |
Non-JSON |
1 KB |
2124 kb/s |
N/A |
|
32 inputs 32 partition eventhub |
Non-JSON |
1 KB |
4093 kb/s |
N/A |
|
Splunk platform environment - Classic Cluster (1 IDM)
|
1 input 16 partition eventhub |
Non-JSON |
1 KB |
1947 kb/s |
30.60% |
16 inputs 16 partition eventhub |
Non-JSON |
1 KB |
1949 kb/s |
13% |
|
1 input 32 partition eventhub |
Non-JSON |
1 KB |
1845 kb/s |
30% |
|
32 inputs 32 partition eventhub |
Non-JSON |
1 KB |
1380 kb/s |
20% |
Version 4.1.5 Event Eub performance characteristics¶
See the following performance testing data for the previous version 4.1.5.
Event Hub input performance characteristics¶
Common Setup |
Event type |
Event size |
Scenario |
Ingest rate |
Data lag |
IDM CPU |
Index CPU |
Bottleneck |
---|---|---|---|---|---|---|---|---|
|
||||||||
JSON |
1 KB |
Sweet Spot |
187 GB/Day (2200 eps) |
4 seconds |
50-89% |
86-92% |
IDX CPU utilized |
|
Non-JSON (mcas-cef) |
994 bytes |
Sweet Spot |
133 GB/day (2000 eps) |
8 seconds |
65-94% |
99% |
IDX CPU utilized |
Event Hub Scale Up performance characteristics¶
Environment setup¶
Cluster setup |
Event Hub namespace |
Event Hub |
Add-on inputs |
Splunk software configurations |
---|---|---|---|---|
Scaled up Splunk Cloud platform environment
|
|
|
|
Inputs Data Manager and indexer configuration |
Scale up result summary¶
Event type | Number of inputs | Event size | Scenario | Ingest rate | Ingest Events per second | Max index rate | Data lag in seconds | Inputs Data Manager (IDM) CPU % | IDM CPU Cores % (Percentage of total IDM cores) | Indexer CPU % |
---|---|---|---|---|---|---|---|---|---|---|
JSON | 80 | 1 Kb | Sweet Spot | 6.106 TB/day | 78K | 7.55 TB/day | 4s | 51% | 36% | 30.5% |
JSON | 10 | 1 Kb | Sweet Spot | 1.764 TB/day | 20.8K | 2.19 TB/day | 9s | 24% | 8.6% | 10% |
Non JSON | 80 | 0.998 Kb | Sweet Spot | 5.555 TB/day | 83.2K | 7.22 TB/day | 4s | 67% | 48% | 47% |
Non JSON | 10 | 0.998 Kb | Sweet Spot | 1.595 TB/day | 24K | 2.07 TB/day | 3s | 29% | 10.4% | 11% |