---
title: logonSession query | Wartiva GraphQL API
description: Retrieves a LogonSession by its graph object id: a user logon session on an endpoint. Wartiva GraphQL API reference with arguments, fields, and examples.
url: https://wartiva.com/api-docs/queries/logon-session.html
updated: 2026-10-07
---

Endpoint configuration · GraphQL query

# `logonSession` query

Retrieves a [LogonSession](https://wartiva.com/api-docs/types/logon-session.html) by its graph object id: a user logon session on an endpoint, with platform-specific detail such as the Windows logon type or the POSIX terminal and remote host. An [Endpoint](https://wartiva.com/api-docs/types/endpoint.html) lists its sessions through `logonSessions` and its most recent one through `lastLogonSession`, and an [EndpointUser](https://wartiva.com/api-docs/types/endpoint-user.html) lists its own through `logonSessions`; find them across endpoints with [graphSearch](https://wartiva.com/api-docs/queries/graph-search.html) on the LOGON_SESSION object type. Returns a not-found error when no object has the id, and an error when the id belongs to another object type.

## Response

Returns a [`LogonSessionPayload!`](https://wartiva.com/api-docs/types/logon-session-payload.html)

## Arguments

| Name | Description |
|---|---|
| `id` - [`ID!`](https://wartiva.com/api-docs/types/id.html) | The LogonSession identifier. |
| `mockOptions` - [`MockDataInput`](https://wartiva.com/api-docs/types/mock-data-input.html) | Options for mock data generation. Options supported: key: "PLATFORM", value: OsPlatform example: "mockOptions": { "options": [ { "key": "PLATFORM", "value": "WINDOWS" } ] } |

## Example

### Query

```graphql
query logonSession(
  $id: ID!,
  $mockOptions: MockDataInput
) {
  logonSession(
    id: $id,
    mockOptions: $mockOptions
  ) {
    node {
      id
      orgId
      seen {
        ...SeenOnlineFragment
      }
      objectType
      objectTypeLabel
      displayName
      firstSeen
      lastSeen
      createdAt
      updatedAt
      snapshotInfo {
        ...GraphObjectSnapshotInfoFragment
      }
      endpoint {
        ...EndpointFragment
      }
      username
      uid
      logonTime
      osSpecific {
        ... on LogonSessionWindows {
          ...LogonSessionWindowsFragment
        }
        ... on LogonSessionMacOS {
          ...LogonSessionMacOSFragment
        }
        ... on LogonSessionLinux {
          ...LogonSessionLinuxFragment
        }
      }
      user {
        ...EndpointUserFragment
      }
      findings {
        ...FindingsPayloadFragment
      }
      issues {
        ...IssuesPayloadFragment
      }
      issuesSummary {
        ...IssuesSummaryFragment
      }
    }
  }
}

```

### Variables

```json
{
  "id": "4",
  "mockOptions": MockDataInput
}

```

### Response

```json
{"data": {"logonSession": {"node": LogonSession}}}

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
