Event Hubs namespaces with no incoming or outgoing messages for 30 days
What does ZopNight detect here?
ZopNight flags an Azure Event Hubs namespace when both `IncomingMessages` and `OutgoingMessages` stay below 1, on average and at peak, across at least 30 days of data, and the namespace has a known cost. Throughput, processing and capacity units are billed by the hour whether or not events flow, so an unused namespace is pure overhead.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1376 |
| Category | idle |
| Severity | medium |
| Metric | IncomingMessages, OutgoingMessages |
| Threshold | both < 1 (average and peak) |
| Evaluation window | 30d |
| Source | ZopNight |
| Permissions used | Microsoft.EventHub/namespaces/read · Microsoft.Insights/Metrics/Read |
Where it applies
Event Hubs capacity is reserved by the hour
Event Hubs pricing charges the Basic and Standard tiers per throughput unit per hour, Premium per processing unit per hour, and Dedicated per capacity unit. Throughput units are chosen by you, apply to every event hub in the namespace, and are billed hourly on the highest number selected during that hour. Each one covers up to 1 MB per second of ingress and 2 MB per second of egress.
None of that depends on traffic. A namespace left behind after a pipeline was rebuilt elsewhere keeps paying for the units it was given.
Checking message flow on a namespace
az eventhubs namespace list \ --query "[].{name:name, rg:resourceGroup, sku:sku.name, units:sku.capacity}" -o table
az monitor metrics list --resource <namespace-resource-id> \ --metric IncomingMessages OutgoingMessages --offset 30d --interval PT24H --aggregation Total MaximumDaily totals and maximums of zero in both directions mean nothing was produced or consumed.
The two-direction idle test
- Both the incoming and outgoing message series are present.
- Each covers at least 30 days.
- On both series, the average and the peak are below 1 message.
- The namespace has a known monthly cost above zero.
The peak matters as much as the average. A namespace that receives one large batch a night can average near zero over a month, but its peak shows it is in use, so it is not flagged.
Namespaces that keep their units
Traffic in either direction clears the namespace. Missing metrics, or fewer than 30 days of data, also mean no finding. An older behaviour that trusted a hand-set tag was removed, so the decision now rests only on Azure Monitor data.
Recovering the namespace charge
saving = current monthly cost of the namespace (its tier and unit count)cost after fix = 0If you keep the namespace but it is oversized, lowering the throughput unit count is a partial saving instead.
Removing an idle namespace
- List its event hubs and consumer groups, and check producers and consumers (Functions, Stream Analytics, Kafka clients) for its connection string or name.
- Check whether it is part of a geo-disaster-recovery alias before touching it.
- Delete it:
az eventhubs namespace delete --resource-group my-rg --name my-namespace.