First, ‘DNS is just plumbing’ badly undersells it: because almost everything starts with a DNS lookup, DNS is one of the richest vantage points for spotting risk. Second, ‘we have logs’ isn’t enough; logs only create visibility when analysed; unread logs surface no signals and reduce no risk. You can’t see risk you don’t record, and you can’t act on records you never read. Collecting and retaining DNS logs, then analysing them, is the foundation of the whole discipline.