Delivery and compatibility

Access and topics

Consumers authenticate over TLS with a CNX-issued client certificate. Each subscriber can read and describe its selected customer topics and use its assigned consumer group. Its permissions do not include publishing, topic administration, or access to another customer's feeds.

Topics follow cnx.customer.<customer_id>.<feed_suffix>. For example, dns.logs.ops maps to cnx.customer.123.dns.logs.ops for example customer 123. The authoritative physical names and group are in connection.yml. Independent subscriptions receive separate groups. Consumers within the same group share consumption across partitions.

Retention and replay

Customer topics retain two hours of data. Consumers should run continuously and monitor lag. Reconnecting resumes from committed offsets only while the corresponding records remain retained. Records that expire cannot be recovered from the customer topic; the client's offset-reset policy determines where consumption continues after an out-of-range offset.

Kafka retention is the delivery window. Retention of imported events is controlled by your SIEM or storage platform.

Feed-specific delivery

Replay identifiers, loss behavior, sampling, and aggregation are defined per feed. Topic retention specifies how long delivered records remain available; it does not establish completeness at the source or during transport. See the feed catalog and DNS delivery behavior.

Time and ordering

Each feed defines its event-time field and semantics. Kafka offsets describe partition position, and SIEM ingestion timestamps describe consumption. Events can arrive out of order across hosts, partitions, and topics.

Use the documented source time for event-time views and the feed's correlation identifiers for relationships. A deduplication identifier does not by itself establish causal order. The time provenance reference describes the source clock chain and DNS cross-host alignment assurance.

Payload compatibility

Each feed reference defines the payload format, field types, optional and null values, version identification, and compatibility rules. Select the parser using the logical feed mapped to the physical topic in connection.yml. Consumers must tolerate unrecognized additional fields according to the documented compatibility contract.