When checking for the number of logs related to DNSKEY key maintenance events, don't include CDNSKEY is published lines. Also consider RSASHA1: If not supported, the key maintenance for the nsec-only zone are not logged.