Log Argument Key Glossary

This glossary defines canonical log argument keys for machine consumers. It complements docs/specifications/log-args-coherency.md.

Contract version:

  • v1.1 (documentation version, not emitted in runtime args)

Scope:

  • Normative for all tags following the coherency contract.
  • Migration is complete; all engine emitters use canonical keys.

Core Identity Keys

KeyTypeMeaningNotes
nsstringNameserver name (FQDN string).Name only. Never name/ip.
addressstringSingle nameserver IP address.Use together with ns when both are known.
domainstringDomain name in testcase-specific contexts.Keep testcase meaning explicit.
mnamestringSOA MNAME hostname.Hostname only.
signerstringSigner’s Name of an RRSIG record.Zone apex name. Never the owner name of the signed RRset.
zonestringZone apex name a finding is about.Never the zone under test. Use signer where the name comes from an RRSIG.
asnintAutonomous system number.Integer in 1 to 4294967295. Used where a finding names exactly one AS; asns carries a list.

Query Identity Keys

KeyTypeMeaningNotes
query_namestringDNS owner name queried.
query_typestringDNS RR type queried.Uppercase form (for example SOA).
query_classstringDNS class queried.Usually IN.

Message Size Keys

KeyTypeMeaningNotes
sizeintDNS message size in bytes.Wire length of the message observed.
payloadintAdvertised EDNS(0) requestor UDP payload size in bytes.The value carried on the query the observation describes.

Structured Collection Keys

KeyTypeMeaningNotes
serversarray<object>Endpoint list for machine use.Items use { "ns": "...", "address": "..." }.
addressesarray<string>IP address list.
asnsarray<int>ASN list.Integer ASN values.
prefixesarray<string>CIDR prefix list.
ptr_namesarray<string>PTR hostname list from reverse-DNS checks.Used for PTR mismatch detail payloads.
mail_targetsarray<string>MX target hostname list.Replaces mailtarget_list.
mx_rdataarray<string>MX RDATA list, each element a preference and exchange separated by a space.mail_targets carries the exchange names of the same RRset.

DNSSEC Algorithm Keys

KeyTypeMeaningNotes
ds_key_algo_numintAlgorithm field value from DS RDATA (the DNSKEY algorithm the DS references).Distinct from ds_algo_num (DS digest type) and algo_num (DNSKEY record algorithm).
ds_key_algo_descrstringText description of the DS algorithm field value.
ds_key_algo_mnemostringDNSSEC algorithm mnemonic for the DS algorithm field value (for example PRIVATEDNS).

Denial Of Existence Keys

KeyTypeMeaningNotes
ownerstringOwner name of the NSEC or NSEC3 record whose interval covers another record, lowercased.The full name as served, hashed label included for NSEC3.
coveredstringOwner name of the NSEC or NSEC3 record that lies inside the interval of owner, lowercased.
nextstringNext field of the record at owner.Next Hashed Owner Name in base32hex for NSEC3, Next Domain Name for NSEC.

Temporal Keys

KeyTypeMeaningNotes
datestringHuman-visible timestamp argument in tag-specific contexts.Use UTC RFC3339 (ISO 8601 profile).

Role-Specific Collection Variants

Use role-specific server collections where needed, with the same endpoint item shape as servers:

  • parent_servers
  • child_servers
  • failing_servers

Retired Legacy Keys

These keys are no longer emitted by the engine. If encountered in historical outputs or external adapters, they are non-canonical:

  • ip (replaced by address)
  • name, server (replaced by ns or context-specific keys)
  • nsname, ns_ip (replaced by ns + address)
  • ns_list, ns_ip_list, nsname_list (replaced by servers)
  • asn_list (replaced by asns)
  • query aliases type, class, rrtype (replaced by query_name, query_type, query_class)
  • delimiter-packed identity fields (; or ,) without typed counterparts

CI guardrails reject reintroduction of these patterns.