Public DNS query logs can be a useful tool to troubleshoot issues with your application. They can also be an essential part of security audits by enabling you to understand what domain names your end users are querying for, which can also be a useful business metric. Once you have enabled DNS Query logs for Route 53, the Cloudwatch Log records can be exported to S3 or streamed to Kinesis Firehose and Amazon Elasticsearch.