AnswerX (rDNS) logs

Create a stream to capture data from Akamai’s recursive DNS (rDNS) AnswerX service for traffic monitoring, security analytics, and DNS performance reporting.

DataStream provides improved visibility into DNS transaction data, including query types, response codes, transport protocols, and metadata. Each stream delivers bundled log data to one of the supported third-party destinations for storage and analytics.

Additional DataStream features include delivery retry in case of data upload failure, uploading logs to third-party destinations with custom headers and dynamic variables in filenames, mTLS authentication, and log data localization for data stored and processed within the European Union (EU). See the list of Supported features in DataStream.

📘

Supported solutions

DataStream supports logging recursive DNS (rDNS) query data for the following solutions:

  • AnswerX Managed
  • AnswerX Cloud
  • AnswerX Cloud Lite
  • SPS Shield
  • Shield NS53
  • SIA Essentials 1.0 and 2.0
  • AnswerX - Disaster Avoidance
  • Enterprise Threat Protector

Get started

If DataStream is not enabled on your contract, contact your Akamai account team to get started with logging SIEM events using streams.

API workflow

  1. Run List groups to determine the group that you want to create a stream for.

  2. Run List AnswerX service instances by contract to get the security service ID, name, and AnswerX product value you can use in other operations.

  3. Run List data set fields to get the list of parameters and metrics you can collect in your AnswerX stream.

    For details, see AnswerX log format.

  4. Run Create an AnswerX stream to configure and activate a stream configuration or save it for later:

  • Set activate to true to activate the stream on request and start streaming logs within 60 minutes or false to save the configuration as inactive. Only active streams send logs to your destination.
  1. If required, run Activate a stream at a later time to start streaming logs within 60 minutes from activation.
  2. If you want to make changes to the stream involving the list of AnswerX service instances, Edit an AnswerX stream.