Endpoint configuration · GraphQL query

logonSession query

Retrieves a LogonSession by its graph object id: a user logon session on an endpoint, with platform-specific detail such as the Windows logon type or the POSIX terminal and remote host. An Endpoint lists its sessions through logonSessions and its most recent one through lastLogonSession, and an EndpointUser lists its own through logonSessions; find them across endpoints with graphSearch on the LOGON_SESSION object type. Returns a not-found error when no object has the id, and an error when the id belongs to another object type.

Response

Returns a LogonSessionPayload!

Arguments

Name Description
id - ID! The LogonSession identifier.
mockOptions - MockDataInput

Options for mock data generation. Options supported: key: "PLATFORM", value: OsPlatform

example: "mockOptions": { "options": [ { "key": "PLATFORM", "value": "WINDOWS" } ] }

Example

Query

query logonSession(
  $id: ID!,
  $mockOptions: MockDataInput
) {
  logonSession(
    id: $id,
    mockOptions: $mockOptions
  ) {
    node {
      id
      orgId
      seen {
        ...SeenOnlineFragment
      }
      objectType
      objectTypeLabel
      displayName
      firstSeen
      lastSeen
      createdAt
      updatedAt
      snapshotInfo {
        ...GraphObjectSnapshotInfoFragment
      }
      endpoint {
        ...EndpointFragment
      }
      username
      uid
      logonTime
      osSpecific {
        ... on LogonSessionWindows {
          ...LogonSessionWindowsFragment
        }
        ... on LogonSessionMacOS {
          ...LogonSessionMacOSFragment
        }
        ... on LogonSessionLinux {
          ...LogonSessionLinuxFragment
        }
      }
      user {
        ...EndpointUserFragment
      }
      findings {
        ...FindingsPayloadFragment
      }
      issues {
        ...IssuesPayloadFragment
      }
      issuesSummary {
        ...IssuesSummaryFragment
      }
    }
  }
}

Variables

{
  "id": "4",
  "mockOptions": MockDataInput
}

Response

{"data": {"logonSession": {"node": LogonSession}}}