Feeds and service evidence
CNX Telemetry Feeds deliver service events continuously over Kafka. A
subscription selects logical feeds, such as dns.logs.ops, and receives
the corresponding customer topics and a dedicated consumer group. Your
consumer reads those topics and stores or indexes the records in your SIEM
or analytics platform.
CNX manages feed definitions, customer routing, certificates, and Kafka access. You retain your private key, operate the consumer, and control the retention of your imported records. Independent destinations use separate subscriptions so each receives the selected stream in full.
For DNS, operations records connect approved Git revisions to validation and deployment results; platform records expose signing and zone distribution; query feeds provide sampled response detail and unsampled counts. Correlating their source timestamps and identifiers lets an analyst trace a change from approval through deployment and serving activity.
The daily DNS evidence package provides retained reports and a timestamped integrity manifest. Telemetry provides continuous delivery with feed-specific schemas and a two-hour Kafka retention window. CNX's central logging platform remains the durable source for DNS operational logs. Configure your own retention for SIEM investigations and audits that extend beyond the Kafka window.
See Delivery and compatibility for replay, duplicates, sampling, and transport behavior, and Time provenance for cross-system event correlation.