Policies and findings · GraphQL query

finding query

Retrieves a Finding by its graph object id: the record of a policy rule evaluating FAIL against one graph object, with its status history and the evidence collected, such as the current and expected configuration and remediation steps. A finding opens on FAIL, moves to RESOLVED when a later evaluation passes, and reopens on the next FAIL. Every graph object lists its findings through findings; find them across the organization with graphSearch on the FINDING object type. Returns a not-found error when no object has the id, and an error when the id belongs to another object type.

Response

Returns a FindingPayload!

Arguments

Name Description
id - ID! The Finding identifier.
mockOptions - MockDataInput Options for mock data generation. Options supported: none.

Example

Query

query finding(
  $id: ID!,
  $mockOptions: MockDataInput
) {
  finding(
    id: $id,
    mockOptions: $mockOptions
  ) {
    node {
      id
      orgId
      objectType
      objectTypeLabel
      displayName
      firstSeen
      lastSeen
      seen {
        ...SeenOnlineFragment
      }
      createdAt
      updatedAt
      snapshotInfo {
        ...GraphObjectSnapshotInfoFragment
      }
      name
      foundOnObject {
        ...GraphObjectFragment
      }
      foundOnSnapshot {
        ...GraphObjectFragment
      }
      severity
      remediationInstructions {
        ...RemediationInstructionsFragment
      }
      currentConfiguration
      expectedConfiguration
      type
      typeMetadata {
        ... on FindingTypeMetadataConfiguration {
          ...FindingTypeMetadataConfigurationFragment
        }
        ... on FindingTypeMetadataFile {
          ...FindingTypeMetadataFileFragment
        }
        ... on FindingTypeMetadataVulnerability {
          ...FindingTypeMetadataVulnerabilityFragment
        }
      }
      status
      statusChanges {
        ...FindingStatusChangesPayloadFragment
      }
      rule {
        ...RuleFragment
      }
      findings {
        ...FindingsPayloadFragment
      }
      issues {
        ...IssuesPayloadFragment
      }
      issuesSummary {
        ...IssuesSummaryFragment
      }
    }
  }
}

Variables

{
  "id": "4",
  "mockOptions": MockDataInput
}

Response

{"data": {"finding": {"node": Finding}}}