Retrieves an endpoint's AuditPolicy by its graph object id: the security event auditing configuration, either the Windows Advanced Audit Policy subcategory settings or the macOS audit configuration from /etc/security/audit_control. Each Endpoint has at most one, also reachable through its auditPolicy field; find them across endpoints with graphSearch on the AUDIT_POLICY object type. Returns a not-found error when no object has the id, and an error when the id belongs to another object type.
Response
Returns an AuditPolicyPayload!
Arguments
| Name | Description |
|---|---|
id - ID!
|
The AuditPolicy identifier. |
mockOptions - MockDataInput
|
Options for mock data generation. Options supported: key: "PLATFORM", value: OsPlatform example: "mockOptions": { "options": [ { "key": "PLATFORM", "value": "WINDOWS" } ] } |
Example
Query
query auditPolicy(
$id: ID!,
$mockOptions: MockDataInput
) {
auditPolicy(
id: $id,
mockOptions: $mockOptions
) {
node {
id
orgId
seen {
...SeenOnlineFragment
}
objectType
objectTypeLabel
displayName
firstSeen
lastSeen
createdAt
updatedAt
snapshotInfo {
...GraphObjectSnapshotInfoFragment
}
endpoint {
...EndpointFragment
}
osSpecific {
... on AuditPolicyWindows {
...AuditPolicyWindowsFragment
}
... on AuditPolicyMacOS {
...AuditPolicyMacOSFragment
}
}
findings {
...FindingsPayloadFragment
}
issues {
...IssuesPayloadFragment
}
issuesSummary {
...IssuesSummaryFragment
}
}
}
}
Variables
{
"id": "4",
"mockOptions": MockDataInput
}
Response
{"data": {"auditPolicy": {"node": AuditPolicy}}}