Telemetry Feeds
CNX Telemetry Feeds deliver structured service events to your SIEM or analytics platform over Kafka. Each subscription selects feeds for your customer account and authenticates with a client certificate whose private key you retain.
Manage subscriptions through repositories on CNX's Git server, using your organisation's SSO integration. Coordinate repository access with your internal team responsible for SSO and CNX access.
Source timestamps travel with each record, preserving the event's time through delivery and ingestion. CNX's GNSS-disciplined atomic-clock reference provides a shared time basis for correlating events across CNX systems.
Start with the available feed catalog to choose what to subscribe to, then connect a Kafka consumer. The DNS feed schemas contain event fields, actions, and payload examples; DNS ingestion examples show how to use them in your SIEM. See Time provenance for the timing chain and the DNS cross-datacentre alignment assurance.
The current catalog contains DNS operations, platform, query-detail, and query-summary feeds. The service also accommodates future TSA and IX feed families, including NetFlow, routing, and RPKI events.
-
Connection and ingestion
Connect a Kafka consumer and ingest CNX events into your SIEM.
-
Feeds and configuration
Subscription configuration, Kafka delivery behavior, and service-specific event schemas.
-
Time and evidence
How subscriptions, source timestamps, and service evidence fit together.