Retrieves a Finding by its graph object id: the record of a policy rule evaluating FAIL against one graph object, with its status history and the evidence collected, such as the current and expected configuration and remediation steps. A finding opens on FAIL, moves to RESOLVED when a later evaluation passes, and reopens on the next FAIL. Every graph object lists its findings through findings; find them across the organization with graphSearch on the FINDING object type. Returns a not-found error when no object has the id, and an error when the id belongs to another object type.
Response
Returns a FindingPayload!
Arguments
| Name | Description |
|---|---|
id - ID!
|
The Finding identifier. |
mockOptions - MockDataInput
|
Options for mock data generation. Options supported: none. |
Example
Query
query finding(
$id: ID!,
$mockOptions: MockDataInput
) {
finding(
id: $id,
mockOptions: $mockOptions
) {
node {
id
orgId
objectType
objectTypeLabel
displayName
firstSeen
lastSeen
seen {
...SeenOnlineFragment
}
createdAt
updatedAt
snapshotInfo {
...GraphObjectSnapshotInfoFragment
}
name
foundOnObject {
...GraphObjectFragment
}
foundOnSnapshot {
...GraphObjectFragment
}
severity
remediationInstructions {
...RemediationInstructionsFragment
}
currentConfiguration
expectedConfiguration
type
typeMetadata {
... on FindingTypeMetadataConfiguration {
...FindingTypeMetadataConfigurationFragment
}
... on FindingTypeMetadataFile {
...FindingTypeMetadataFileFragment
}
... on FindingTypeMetadataVulnerability {
...FindingTypeMetadataVulnerabilityFragment
}
}
status
statusChanges {
...FindingStatusChangesPayloadFragment
}
rule {
...RuleFragment
}
findings {
...FindingsPayloadFragment
}
issues {
...IssuesPayloadFragment
}
issuesSummary {
...IssuesSummaryFragment
}
}
}
}
Variables
{
"id": "4",
"mockOptions": MockDataInput
}
Response
{"data": {"finding": {"node": Finding}}}