Endpoint configuration · GraphQL query

auditPolicy query

Retrieves an endpoint's AuditPolicy by its graph object id: the security event auditing configuration, either the Windows Advanced Audit Policy subcategory settings or the macOS audit configuration from /etc/security/audit_control. Each Endpoint has at most one, also reachable through its auditPolicy field; find them across endpoints with graphSearch on the AUDIT_POLICY object type. Returns a not-found error when no object has the id, and an error when the id belongs to another object type.

Response

Returns an AuditPolicyPayload!

Arguments

Name Description
id - ID! The AuditPolicy identifier.
mockOptions - MockDataInput

Options for mock data generation. Options supported: key: "PLATFORM", value: OsPlatform

example: "mockOptions": { "options": [ { "key": "PLATFORM", "value": "WINDOWS" } ] }

Example

Query

query auditPolicy(
  $id: ID!,
  $mockOptions: MockDataInput
) {
  auditPolicy(
    id: $id,
    mockOptions: $mockOptions
  ) {
    node {
      id
      orgId
      seen {
        ...SeenOnlineFragment
      }
      objectType
      objectTypeLabel
      displayName
      firstSeen
      lastSeen
      createdAt
      updatedAt
      snapshotInfo {
        ...GraphObjectSnapshotInfoFragment
      }
      endpoint {
        ...EndpointFragment
      }
      osSpecific {
        ... on AuditPolicyWindows {
          ...AuditPolicyWindowsFragment
        }
        ... on AuditPolicyMacOS {
          ...AuditPolicyMacOSFragment
        }
      }
      findings {
        ...FindingsPayloadFragment
      }
      issues {
        ...IssuesPayloadFragment
      }
      issuesSummary {
        ...IssuesSummaryFragment
      }
    }
  }
}

Variables

{
  "id": "4",
  "mockOptions": MockDataInput
}

Response

{"data": {"auditPolicy": {"node": AuditPolicy}}}