One entry in an Endpoint's neighbor cache: the IPv4 Address Resolution Protocol (ARP) table and, where the operating system reports it, the IPv6 Neighbor Discovery (NDP) table. Each entry maps an IP address to the MAC address the endpoint resolved it to on one network interface, and is collected from Windows, macOS, and Linux endpoints as part of the periodic network inventory.
Entries link to the Device the MAC address identifies and to the NetworkPrefix containing the IP address. When another entry on the same endpoint and interface claims the same IP address with a different MAC address, the conflict is recorded in duplicates — the signature of ARP spoofing, cache poisoning, or an address conflict.
Fields
| Field Name | Description |
|---|---|
id - ID!
|
The ArpTableEntry's unique identifier on the security graph. |
orgId - OrganizationId!
|
Unique identifier that corresponds to your deployment of this product or a specific customer account that this Endpoint belongs to. |
seen - SeenOnline!
|
Describes when this ArpTableEntry was seen. |
objectType - GraphObjectType!
|
The type of this graph object. |
objectTypeLabel - String!
|
A localized label describing the object type. |
displayName - String!
|
A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object. |
firstSeen - Time!
|
Time this object was first seen. |
lastSeen - Time!
|
Time this object was last seen. |
createdAt - Time!
|
The time this object was created in the security graph. |
updatedAt - Time!
|
The time this object was last mutated in the security graph. |
snapshotInfo - GraphObjectSnapshotInfo!
|
Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed. |
endpoint - Endpoint
|
The Endpoint this ArpTableEntry belongs to if available. |
device - Device
|
The Device this ArpTableEntry maps to if available. |
networkPrefix - NetworkPrefix
|
The NetworkPrefix this ArpTableEntry maps to if available. |
ip - IpAddress!
|
The neighbor's IP address (IPv4 or IPv6) that this entry resolves. |
mac - Mac!
|
The hardware (MAC) address the endpoint resolved ip to. |
static - Boolean!
|
True if this entry is static and manually entered by an administrator. |
ifaceIndex - Int!
|
O/S level index number of the interface number this entry was found for if available. |
duplicates - [ArpTableEntryDuplicate!]!
|
The other ARP table entries on this endpoint and interface that claim this entry's IP address with a different MAC address. Two hosts answering for one address is what ARP spoofing and cache poisoning look like on the wire, and it is also what an address conflict looks like. A conflict that has since resolved is kept here with |
activeDuplicateCount - Int!
|
How many entries in duplicates were present in the most recent observation of this endpoint's ARP table. Non-zero means this entry's address is contested right now. |
findings - FindingsPayload!
|
Policy findings for this object. |
issues - IssuesPayload!
|
Policy issues for this object. |
issuesSummary - IssuesSummary!
|
Summary of the active policy issues currently open on this object, broken down by severity. |
Returned by
arpTableEntryquery: Retrieves an ArpTableEntry by its graph object id: one entry in an endpoint's neighbor cache (ARP for IPv4, NDP for IPv6 where the operating system…
Used by
Endpointtype: A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.ArpTableEntryConnectiontype: Collection payload for ArpTableEntry edges with total count.ArpTableEntryDuplicatetype: Another ARP table entry claiming the same IP address as the entry that records it, with a different MAC address — an address conflict, and the shape…ArpTableEntryEdgetype: Edge payload for an ArpTableEntry with optional seen data.ArpTableEntryPayloadtype: Payload wrapper for a single ArpTableEntry result.GraphObjectTypeenum: An enumeration of the different types of security graph objects.GraphObjectTypeCategoryenum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.
Related types
DeviceA physical or virtual device that does not run the Wartiva endpoint application but is visible on the network to a managed Endpoint, such as…EndpointA Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.NetworkPrefixA specific IP address together with its subnet prefix length (e.g.
Example
Example
{
"id": 4,
"orgId": "615f3b3b28284380e28a7342",
"seen": SeenOnline,
"objectType": "ACCOUNT_POLICY",
"objectTypeLabel": "xyz789",
"displayName": "abc123",
"firstSeen": "2021-10-07T18:23:25.829Z",
"lastSeen": "2021-10-07T18:23:25.829Z",
"createdAt": "2021-10-07T18:23:25.829Z",
"updatedAt": "2021-10-07T18:23:25.829Z",
"snapshotInfo": GraphObjectSnapshotInfo,
"endpoint": Endpoint,
"device": Device,
"networkPrefix": NetworkPrefix,
"ip": IpAddress,
"mac": "f0:18:98:14:8e:80",
"static": true,
"ifaceIndex": 123,
"duplicates": [ArpTableEntryDuplicate],
"activeDuplicateCount": 987,
"findings": FindingsPayload,
"issues": IssuesPayload,
"issuesSummary": IssuesSummary
}