Retrieves a LogonSession by its graph object id: a user logon session on an endpoint, with platform-specific detail such as the Windows logon type or the POSIX terminal and remote host. An Endpoint lists its sessions through logonSessions and its most recent one through lastLogonSession, and an EndpointUser lists its own through logonSessions; find them across endpoints with graphSearch on the LOGON_SESSION object type. Returns a not-found error when no object has the id, and an error when the id belongs to another object type.
Response
Returns a LogonSessionPayload!
Arguments
| Name | Description |
|---|---|
id - ID!
|
The LogonSession identifier. |
mockOptions - MockDataInput
|
Options for mock data generation. Options supported: key: "PLATFORM", value: OsPlatform example: "mockOptions": { "options": [ { "key": "PLATFORM", "value": "WINDOWS" } ] } |
Example
Query
query logonSession(
$id: ID!,
$mockOptions: MockDataInput
) {
logonSession(
id: $id,
mockOptions: $mockOptions
) {
node {
id
orgId
seen {
...SeenOnlineFragment
}
objectType
objectTypeLabel
displayName
firstSeen
lastSeen
createdAt
updatedAt
snapshotInfo {
...GraphObjectSnapshotInfoFragment
}
endpoint {
...EndpointFragment
}
username
uid
logonTime
osSpecific {
... on LogonSessionWindows {
...LogonSessionWindowsFragment
}
... on LogonSessionMacOS {
...LogonSessionMacOSFragment
}
... on LogonSessionLinux {
...LogonSessionLinuxFragment
}
}
user {
...EndpointUserFragment
}
findings {
...FindingsPayloadFragment
}
issues {
...IssuesPayloadFragment
}
issuesSummary {
...IssuesSummaryFragment
}
}
}
}
Variables
{
"id": "4",
"mockOptions": MockDataInput
}
Response
{"data": {"logonSession": {"node": LogonSession}}}