File path sensors · GraphQL query

endpointPathEntryStats query

Retrieves the stat record (mode, ownership, sizes, timestamps, and OS-specific attributes) of one file path discovered by an EndpointPath — list discovered paths with its entries field. Returns null when the sensor has never reported that path. See endpointPathEntryContents for the file's collected bytes.

Response

Returns an EndpointPathEntryStatsPayload

Arguments

Name Description
id - ID! The EndpointPath identifier.
path - String! The absolute file path exactly as reported by the endpoint.
mockOptions - MockDataInput

Options for mock data generation. Options supported: key: "PLATFORM", value: OsPlatform

example: "mockOptions": { "options": [ { "key": "PLATFORM", "value": "WINDOWS" } ] }

Example

Query

query endpointPathEntryStats(
  $id: ID!,
  $path: String!,
  $mockOptions: MockDataInput
) {
  endpointPathEntryStats(
    id: $id,
    path: $path,
    mockOptions: $mockOptions
  ) {
    node {
      path
      mode {
        ...PosixFileModeFragment
      }
      isDirectory
      isSymlink
      symlinkTarget
      isHardLink
      hardLinkCount
      inode
      deviceId
      ownerUid
      ownerGid
      owner {
        ...EndpointUserFragment
      }
      group {
        ...EndpointGroupFragment
      }
      size
      modifiedAt
      checksum
      hasContents
      deleted
      deletedAt
      renamedTo
      executedAt
      contentTruncated
      collectedAt
      osSpecific {
        ... on EndpointPathWindows {
          ...EndpointPathWindowsFragment
        }
        ... on EndpointPathMacOS {
          ...EndpointPathMacOSFragment
        }
        ... on EndpointPathLinux {
          ...EndpointPathLinuxFragment
        }
      }
      creationTime
      lastWriteTime
      lastAccessTime
      lastChangeTime
      lastStatusChangeTime
    }
  }
}

Variables

{
  "id": "4",
  "path": "abc123",
  "mockOptions": MockDataInput
}

Response

{
  "data": {
    "endpointPathEntryStats": {
      "node": EndpointPathEntryStats
    }
  }
}