Endpoint configuration · GraphQL query

endpointGroup query

Retrieves an EndpointGroup by its graph object id: an operating system or domain group on an endpoint, identified by its SID on Windows or GID on macOS and Linux, with its member users. An Endpoint lists its current groups through groups and their history through groupsSeen, and an EndpointUser lists the groups it belongs to the same way; find them across endpoints with graphSearch on the ENDPOINT_GROUP object type. Returns a not-found error when no object has the id, and an error when the id belongs to another object type.

Response

Returns an EndpointGroupPayload!

Arguments

Name Description
id - ID! The EndpointGroup identifier.
mockOptions - MockDataInput

Options for mock data generation. Options supported: key: "PLATFORM", value: OsPlatform

example: "mockOptions": { "options": [ { "key": "PLATFORM", "value": "WINDOWS" } ] }

Example

Query

query endpointGroup(
  $id: ID!,
  $mockOptions: MockDataInput
) {
  endpointGroup(
    id: $id,
    mockOptions: $mockOptions
  ) {
    node {
      id
      orgId
      seen {
        ...SeenOnlineFragment
      }
      objectType
      objectTypeLabel
      displayName
      firstSeen
      lastSeen
      createdAt
      updatedAt
      snapshotInfo {
        ...GraphObjectSnapshotInfoFragment
      }
      endpoint {
        ...EndpointFragment
      }
      groupname
      description
      gid
      sid
      members {
        ...EndpointUserConnectionFragment
      }
      membersSeen {
        ...EndpointUserConnectionFragment
      }
      findings {
        ...FindingsPayloadFragment
      }
      issues {
        ...IssuesPayloadFragment
      }
      issuesSummary {
        ...IssuesSummaryFragment
      }
    }
  }
}

Variables

{
  "id": "4",
  "mockOptions": MockDataInput
}

Response

{"data": {"endpointGroup": {"node": EndpointGroup}}}