Lists the processes that were running on an Endpoint in its most recent process report, with the time of that report. Processes are not graph objects; the executables behind them are tracked over time as Executable objects. Readable by users of the endpoint's organization.
Response
Returns a ProcessesPayload!
Arguments
| Name | Description |
|---|---|
id - ID!
|
The Endpoint's unique identifier on the security graph. |
limit - Int
|
Maximum number of processes to return. Defaults to 1000; values above 100000 are reduced to 100000, and zero or a negative value returns 100. Default = 1000 |
skip - Int
|
Number of processes to skip before returning results. Default = 0 |
mockOptions - MockDataInput
|
Options for mock data generation. Options supported: key: "PLATFORM", value: OsPlatform example: "mockOptions": { "options": [ { "key": "PLATFORM", "value": "WINDOWS" } ] } |
Example
Query
query processes(
$id: ID!,
$limit: Int,
$skip: Int,
$mockOptions: MockDataInput
) {
processes(
id: $id,
limit: $limit,
skip: $skip,
mockOptions: $mockOptions
) {
nodes {
pid
name
path
commandLineArgs
workingDir
executableOnDisk
memory {
...ProcessMemoryFragment
}
disk {
...ProcessDiskFragment
}
startTime
parent
processGroup
threads
elapsedTime
cpuPercent
openFiles {
...OpenFileFragment
}
openSockets {
...OpenSocketFragment
}
osSpecific {
... on ProcessWindows {
...ProcessWindowsFragment
}
... on ProcessMacOS {
...ProcessMacOSFragment
}
... on ProcessLinux {
...ProcessLinuxFragment
}
}
}
timestamp
updatedAt
}
}
Variables
{
"id": 4,
"limit": 1000,
"skip": 0,
"mockOptions": MockDataInput
}
Response
{
"data": {
"processes": {
"nodes": [Process],
"timestamp": "2021-10-07T18:23:25.829Z",
"updatedAt": "2021-10-07T18:23:25.829Z"
}
}
}