Available feeds

Subscriptions select logical feed names from this catalog. CNX publishes the corresponding customer topic names and consumer group in your connection.yml. Feed availability depends on your account's enabled services and entitlements.

DNS

FeedContentsAnalysis use
dns.logs.opsApproval, validation, deployment, ownership, and alias eventsTrace accepted configuration revisions and change outcomes
dns.logs.platformSelected DNSSEC signing and zone-distribution eventsCorrelate signing and propagation by zone and serial
dns.queries.detailClassified DNS response detail; default customer sample up to 100 records per second across the fleetInspect responses and analyze sampled traffic; request full producer-selected fleet delivery up to 10,000 records per second
dns.queries.summaryUnsampled classified counts by server, zone, response code, and windowAggregate query counts independently of detail sampling

See DNS feed schemas for fields, actions, JSON examples, sampling, and delivery behavior. Ingesting DNS telemetry provides SIEM mappings for logs, individual responses, and summaries.

Customer delivery sampling applies only to query detail. The other DNS feeds have no customer sampling filter; their source selection and transport behavior are defined in the schemas.

Additional service families

TSA and IX feeds will extend this catalog. IX scope includes NetFlow, routing, and RPKI. Their logical feed names and schemas will be listed here as they become available.

Use Subscription configuration to request feeds and Connecting a Kafka consumer to configure delivery. The shared SIEM ingestion guide describes parser selection and event-time handling across feed families.