Retrieves an EndpointGroup by its graph object id: an operating system or domain group on an endpoint, identified by its SID on Windows or GID on macOS and Linux, with its member users. An Endpoint lists its current groups through groups and their history through groupsSeen, and an EndpointUser lists the groups it belongs to the same way; find them across endpoints with graphSearch on the ENDPOINT_GROUP object type. Returns a not-found error when no object has the id, and an error when the id belongs to another object type.
Response
Returns an EndpointGroupPayload!
Arguments
| Name | Description |
|---|---|
id - ID!
|
The EndpointGroup identifier. |
mockOptions - MockDataInput
|
Options for mock data generation. Options supported: key: "PLATFORM", value: OsPlatform example: "mockOptions": { "options": [ { "key": "PLATFORM", "value": "WINDOWS" } ] } |
Example
Query
query endpointGroup(
$id: ID!,
$mockOptions: MockDataInput
) {
endpointGroup(
id: $id,
mockOptions: $mockOptions
) {
node {
id
orgId
seen {
...SeenOnlineFragment
}
objectType
objectTypeLabel
displayName
firstSeen
lastSeen
createdAt
updatedAt
snapshotInfo {
...GraphObjectSnapshotInfoFragment
}
endpoint {
...EndpointFragment
}
groupname
description
gid
sid
members {
...EndpointUserConnectionFragment
}
membersSeen {
...EndpointUserConnectionFragment
}
findings {
...FindingsPayloadFragment
}
issues {
...IssuesPayloadFragment
}
issuesSummary {
...IssuesSummaryFragment
}
}
}
}
Variables
{
"id": "4",
"mockOptions": MockDataInput
}
Response
{"data": {"endpointGroup": {"node": EndpointGroup}}}