Feeds and service evidence

CNX Telemetry Feeds deliver service events continuously over Kafka. A subscription selects logical feeds, such as dns.logs.ops, and receives the corresponding customer topics and a dedicated consumer group. Your consumer reads those topics and stores or indexes the records in your SIEM or analytics platform.

CNX manages feed definitions, customer routing, certificates, and Kafka access. You retain your private key, operate the consumer, and control the retention of your imported records. Independent destinations use separate subscriptions so each receives the selected stream in full.

For DNS, operations records connect approved Git revisions to validation and deployment results; platform records expose signing and zone distribution; query feeds provide sampled response detail and unsampled counts. Correlating their source timestamps and identifiers lets an analyst trace a change from approval through deployment and serving activity.

The daily DNS evidence package provides retained reports and a timestamped integrity manifest. Telemetry provides continuous delivery with feed-specific schemas and a two-hour Kafka retention window. CNX's central logging platform remains the durable source for DNS operational logs. Configure your own retention for SIEM investigations and audits that extend beyond the Kafka window.

See Delivery and compatibility for replay, duplicates, sampling, and transport behavior, and Time provenance for cross-system event correlation.