Time provenance

CNX telemetry retains the timestamp captured by the system that produced the event. DNS log records preserve the source journal timestamp; query-detail records preserve the DNS response timestamp; query summaries identify the start of their counting window. Kafka delivery and SIEM ingestion preserve that event-time field, allowing you to correlate records even when they arrive in a different order.

Atomic-clock reference

CNX's DNS producer clocks share a UTC-traceable reference from on-premises, GNSS-disciplined atomic-clock grandmasters. Hardware-timestamped PTP carries that reference to the hypervisors. Virtual machines receive the hypervisor's precision hardware clock through ptp_kvm, and chrony disciplines their system clocks against it.

The reference chain is:

GNSS -> atomic-clock grandmasters -> hardware-timestamped PTP
     -> hypervisor clock -> VM precision hardware clock -> source event time

Monitoring covers grandmaster reachability, PTP synchronization state, offset and jitter, hypervisor and VM clock synchronization, and chrony's reported clock-error components. This shared reference gives DNS records from KPH, BDC, and SCT a common time basis for investigations across data centres.

DNS alignment assurance

Under normal network load, CNX ensures cross-datacentre DNS log timestamps are aligned within 10 microseconds at p99 while the timing chain is synchronized. This is a cross-host clock-alignment assurance. It describes the timing basis for event correlation; it does not bound Kafka delivery latency or SIEM ingestion delay.

During a detected synchronization or timing-transport incident, records remain attributable to their source, but the same cross-host ordering accuracy is not asserted for that interval. Events closer together than the applicable timing uncertainty should be treated as simultaneous unless causal identifiers establish their sequence. A percentile assurance also allows observations outside the stated bound.

Using source time in your SIEM

Map the JSON timestamp to event time and retain its original string. The nine fractional digits preserve source timestamp resolution; they do not imply nanosecond clock accuracy. Record SIEM ingestion time separately to measure delivery delay.

For DNS changes, combine time with zone, production_sha, and serial. These fields connect approval, deployment, signing, and propagation even when transport reorders events. Kafka offsets sequence records within a partition; they do not establish event order across hosts or topics.

Telemetry records carry source time and attribution. Individual JSON records do not contain an RFC 3161 timestamp token or a per-event clock-health proof. The DNS evidence package includes a separate RFC 3161 token over its daily report manifest. TSA token accuracy is governed by the TSA time policy.