# One Pattern, Many Data Sources ## Capture, enrich, route, retain is not specific to DNS DNS is the entry point because it is universal, high-volume and high-signal. The architecture underneath does not care what the events are. | Source | Stated stage | | --- | --- | | DNS telemetry | live today, the initial wedge | | Network flow logs (NetFlow, IPFIX) | next | | Authentication and identity events | next | | API gateway logs | roadmap | | Cloud and Kubernetes logs (VPC flow, K8s audit) | roadmap | | IoT and sensor telemetry | roadmap | Each addition is the same collectors, the same enrichment engine and the same policy router, with a new source adapter. Expansion revenue comes from selling more data domains into customers already served. > [!tip] Why this ordering is sensible > Each new source shares the buyer, the budget and the deployment already in place. ==The second sale has no new procurement cycle.== That is a much better expansion motion than selling a second product to a second buyer. ## Why it matters It changes what the company is being valued as. A DNS telemetry tool has a bounded market. A telemetry routing layer with DNS as its first adapter has a market the size of enterprise log volume, which is growing faster than the tools that consume it. The thing to hold lightly is the roadmap ordering. Source adapters look similar on a slide and differ substantially in engineering effort, and the team is deliberately lean on engineering. → [[TelemetriX - Questions to Follow Up]] ## Related - [[Red Onion MOC]] - [[What TelemetriX Does]] - [[Who Buys and Why]] - [[Land-and-Expand in Enterprise AI]] - [[knowledge graphs]]