Available feeds
Subscriptions select logical feed names from this catalog. CNX publishes the
corresponding customer topic names and consumer group in your connection.yml.
Feed availability depends on your account's enabled services and entitlements.
DNS
| Feed | Contents | Analysis use |
|---|---|---|
dns.logs.ops | Approval, validation, deployment, ownership, and alias events | Trace accepted configuration revisions and change outcomes |
dns.logs.platform | Selected DNSSEC signing and zone-distribution events | Correlate signing and propagation by zone and serial |
dns.queries.detail | Classified DNS response detail; default customer sample up to 100 records per second across the fleet | Inspect responses and analyze sampled traffic; request full producer-selected fleet delivery up to 10,000 records per second |
dns.queries.summary | Unsampled classified counts by server, zone, response code, and window | Aggregate query counts independently of detail sampling |
See DNS feed schemas for fields, actions, JSON examples, sampling, and delivery behavior. Ingesting DNS telemetry provides SIEM mappings for logs, individual responses, and summaries.
Customer delivery sampling applies only to query detail. The other DNS feeds have no customer sampling filter; their source selection and transport behavior are defined in the schemas.
Additional service families
TSA and IX feeds will extend this catalog. IX scope includes NetFlow, routing, and RPKI. Their logical feed names and schemas will be listed here as they become available.
Use Subscription configuration to request feeds and Connecting a Kafka consumer to configure delivery. The shared SIEM ingestion guide describes parser selection and event-time handling across feed families.