Skip to main content
idle · azure

Event Hubs namespaces with no incoming or outgoing messages for 30 days

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

ZopNight flags an Azure Event Hubs namespace when both `IncomingMessages` and `OutgoingMessages` stay below 1, on average and at peak, across at least 30 days of data, and the namespace has a known cost. Throughput, processing and capacity units are billed by the hour whether or not events flow, so an unused namespace is pure overhead.

Signal and threshold

How ZopNight evaluates Event Hubs namespaces with no incoming or outgoing messages for 30 days.
Field Value
Rule IDsRC-1376
Categoryidle
Severitymedium
MetricIncomingMessages, OutgoingMessages
Thresholdboth < 1 (average and peak)
Evaluation window30d
SourceZopNight
Permissions usedMicrosoft.EventHub/namespaces/read · Microsoft.Insights/Metrics/Read

Event Hubs capacity is reserved by the hour

Event Hubs pricing charges the Basic and Standard tiers per throughput unit per hour, Premium per processing unit per hour, and Dedicated per capacity unit. Throughput units are chosen by you, apply to every event hub in the namespace, and are billed hourly on the highest number selected during that hour. Each one covers up to 1 MB per second of ingress and 2 MB per second of egress.

None of that depends on traffic. A namespace left behind after a pipeline was rebuilt elsewhere keeps paying for the units it was given.

Checking message flow on a namespace

Terminal window
az eventhubs namespace list \
--query "[].{name:name, rg:resourceGroup, sku:sku.name, units:sku.capacity}" -o table
az monitor metrics list --resource <namespace-resource-id> \
--metric IncomingMessages OutgoingMessages --offset 30d --interval PT24H --aggregation Total Maximum

Daily totals and maximums of zero in both directions mean nothing was produced or consumed.

The two-direction idle test

  1. Both the incoming and outgoing message series are present.
  2. Each covers at least 30 days.
  3. On both series, the average and the peak are below 1 message.
  4. The namespace has a known monthly cost above zero.

The peak matters as much as the average. A namespace that receives one large batch a night can average near zero over a month, but its peak shows it is in use, so it is not flagged.

Namespaces that keep their units

Traffic in either direction clears the namespace. Missing metrics, or fewer than 30 days of data, also mean no finding. An older behaviour that trusted a hand-set tag was removed, so the decision now rests only on Azure Monitor data.

Recovering the namespace charge

Terminal window
saving = current monthly cost of the namespace (its tier and unit count)
cost after fix = 0

If you keep the namespace but it is oversized, lowering the throughput unit count is a partial saving instead.

Removing an idle namespace

  1. List its event hubs and consumer groups, and check producers and consumers (Functions, Stream Analytics, Kafka clients) for its connection string or name.
  2. Check whether it is part of a geo-disaster-recovery alias before touching it.
  3. Delete it: az eventhubs namespace delete --resource-group my-rg --name my-namespace.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·