Retrieves an ArpTableEntry by its graph object id: one entry in an endpoint's neighbor cache (ARP for IPv4, NDP for IPv6 where the operating system reports it) mapping an IP address to a MAC address, with detection of conflicting mappings that can indicate ARP spoofing. An Endpoint lists its current entries through arpTableEntries and their history through arpTableEntriesSeen, and each entry links to the Device it resolves to; find them across endpoints with graphSearch on the ARP_TABLE_ENTRY object type. Returns a not-found error when no object has the id, and an error when the id belongs to another object type.
Response
Returns an ArpTableEntryPayload!
Arguments
| Name | Description |
|---|---|
id - ID!
|
The ArpTableEntry identifier. |
mockOptions - MockDataInput
|
Options for mock data generation. Options supported: key: "PLATFORM", value: OsPlatform example: "mockOptions": { "options": [ { "key": "PLATFORM", "value": "WINDOWS" } ] } |
Example
Query
query arpTableEntry(
$id: ID!,
$mockOptions: MockDataInput
) {
arpTableEntry(
id: $id,
mockOptions: $mockOptions
) {
node {
id
orgId
seen {
...SeenOnlineFragment
}
objectType
objectTypeLabel
displayName
firstSeen
lastSeen
createdAt
updatedAt
snapshotInfo {
...GraphObjectSnapshotInfoFragment
}
endpoint {
...EndpointFragment
}
device {
...DeviceFragment
}
networkPrefix {
...NetworkPrefixFragment
}
ip {
...IpAddressFragment
}
mac
static
ifaceIndex
duplicates {
...ArpTableEntryDuplicateFragment
}
activeDuplicateCount
findings {
...FindingsPayloadFragment
}
issues {
...IssuesPayloadFragment
}
issuesSummary {
...IssuesSummaryFragment
}
}
}
}
Variables
{"id": 4, "mockOptions": MockDataInput}
Response
{"data": {"arpTableEntry": {"node": ArpTableEntry}}}