Networks, devices, and sensors · GraphQL type

ArpTableEntry type

One entry in an Endpoint's neighbor cache: the IPv4 Address Resolution Protocol (ARP) table and, where the operating system reports it, the IPv6 Neighbor Discovery (NDP) table. Each entry maps an IP address to the MAC address the endpoint resolved it to on one network interface, and is collected from Windows, macOS, and Linux endpoints as part of the periodic network inventory.

Entries link to the Device the MAC address identifies and to the NetworkPrefix containing the IP address. When another entry on the same endpoint and interface claims the same IP address with a different MAC address, the conflict is recorded in duplicates — the signature of ARP spoofing, cache poisoning, or an address conflict.

Fields

Field Name Description
id - ID! The ArpTableEntry's unique identifier on the security graph.
orgId - OrganizationId! Unique identifier that corresponds to your deployment of this product or a specific customer account that this Endpoint belongs to.
seen - SeenOnline! Describes when this ArpTableEntry was seen.
objectType - GraphObjectType! The type of this graph object.
objectTypeLabel - String! A localized label describing the object type.
displayName - String! A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object.
firstSeen - Time! Time this object was first seen.
lastSeen - Time! Time this object was last seen.
createdAt - Time! The time this object was created in the security graph.
updatedAt - Time! The time this object was last mutated in the security graph.
snapshotInfo - GraphObjectSnapshotInfo! Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed.
endpoint - Endpoint The Endpoint this ArpTableEntry belongs to if available.
device - Device The Device this ArpTableEntry maps to if available.
networkPrefix - NetworkPrefix The NetworkPrefix this ArpTableEntry maps to if available.
ip - IpAddress! The neighbor's IP address (IPv4 or IPv6) that this entry resolves.
mac - Mac! The hardware (MAC) address the endpoint resolved ip to.
static - Boolean! True if this entry is static and manually entered by an administrator.
ifaceIndex - Int! O/S level index number of the interface number this entry was found for if available.
duplicates - [ArpTableEntryDuplicate!]!

The other ARP table entries on this endpoint and interface that claim this entry's IP address with a different MAC address. Two hosts answering for one address is what ARP spoofing and cache poisoning look like on the wire, and it is also what an address conflict looks like.

A conflict that has since resolved is kept here with isActive false, so the record shows that an address was contested and when. Ordered by the conflicting entry's identifier.

activeDuplicateCount - Int! How many entries in duplicates were present in the most recent observation of this endpoint's ARP table. Non-zero means this entry's address is contested right now.
findings - FindingsPayload! Policy findings for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issues - IssuesPayload! Policy issues for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issuesSummary - IssuesSummary! Summary of the active policy issues currently open on this object, broken down by severity.

Returned by

  • arpTableEntry query: Retrieves an ArpTableEntry by its graph object id: one entry in an endpoint's neighbor cache (ARP for IPv4, NDP for IPv6 where the operating system…

Used by

  • Endpoint type: A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
  • ArpTableEntryConnection type: Collection payload for ArpTableEntry edges with total count.
  • ArpTableEntryDuplicate type: Another ARP table entry claiming the same IP address as the entry that records it, with a different MAC address — an address conflict, and the shape…
  • ArpTableEntryEdge type: Edge payload for an ArpTableEntry with optional seen data.
  • ArpTableEntryPayload type: Payload wrapper for a single ArpTableEntry result.
  • GraphObjectType enum: An enumeration of the different types of security graph objects.
  • GraphObjectTypeCategory enum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.

Related types

  • Device A physical or virtual device that does not run the Wartiva endpoint application but is visible on the network to a managed Endpoint, such as…
  • Endpoint A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
  • NetworkPrefix A specific IP address together with its subnet prefix length (e.g.

Example

Example

{
  "id": 4,
  "orgId": "615f3b3b28284380e28a7342",
  "seen": SeenOnline,
  "objectType": "ACCOUNT_POLICY",
  "objectTypeLabel": "xyz789",
  "displayName": "abc123",
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z",
  "createdAt": "2021-10-07T18:23:25.829Z",
  "updatedAt": "2021-10-07T18:23:25.829Z",
  "snapshotInfo": GraphObjectSnapshotInfo,
  "endpoint": Endpoint,
  "device": Device,
  "networkPrefix": NetworkPrefix,
  "ip": IpAddress,
  "mac": "f0:18:98:14:8e:80",
  "static": true,
  "ifaceIndex": 123,
  "duplicates": [ArpTableEntryDuplicate],
  "activeDuplicateCount": 987,
  "findings": FindingsPayload,
  "issues": IssuesPayload,
  "issuesSummary": IssuesSummary
}