---
title: ArpTableEntry type | Wartiva GraphQL API
description: One entry in an Endpoint's neighbor cache: the IPv4 Address Resolution Protocol (ARP) table and, where the operating system reports it.
url: https://wartiva.com/api-docs/types/arp-table-entry.html
updated: 2026-10-07
---

Networks, devices, and sensors · GraphQL type

# `ArpTableEntry` type

One entry in an [Endpoint](https://wartiva.com/api-docs/types/endpoint.html)'s neighbor cache: the IPv4 Address Resolution Protocol (ARP) table and, where the operating system reports it, the IPv6 Neighbor Discovery (NDP) table. Each entry maps an IP address to the MAC address the endpoint resolved it to on one network interface, and is collected from Windows, macOS, and Linux endpoints as part of the periodic network inventory.

Entries link to the [Device](https://wartiva.com/api-docs/types/device.html) the MAC address identifies and to the [NetworkPrefix](https://wartiva.com/api-docs/types/network-prefix.html) containing the IP address. When another entry on the same endpoint and interface claims the same IP address with a different MAC address, the conflict is recorded in `duplicates` — the signature of ARP spoofing, cache poisoning, or an address conflict.

## Fields

| Field Name | Description |
|---|---|
| `id` - [`ID!`](https://wartiva.com/api-docs/types/id.html) | The ArpTableEntry's unique identifier on the security graph. |
| `orgId` - [`OrganizationId!`](https://wartiva.com/api-docs/types/organization-id.html) | Unique identifier that corresponds to your deployment of this product or a specific customer account that this Endpoint belongs to. |
| `seen` - [`SeenOnline!`](https://wartiva.com/api-docs/types/seen-online.html) | Describes when this ArpTableEntry was seen. |
| `objectType` - [`GraphObjectType!`](https://wartiva.com/api-docs/types/graph-object-type.html) | The type of this graph object. |
| `objectTypeLabel` - [`String!`](https://wartiva.com/api-docs/types/string.html) | A localized label describing the object type. |
| `displayName` - [`String!`](https://wartiva.com/api-docs/types/string.html) | A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object. |
| `firstSeen` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | Time this object was first seen. |
| `lastSeen` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | Time this object was last seen. |
| `createdAt` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | The time this object was created in the security graph. |
| `updatedAt` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | The time this object was last mutated in the security graph. |
| `snapshotInfo` - [`GraphObjectSnapshotInfo!`](https://wartiva.com/api-docs/types/graph-object-snapshot-info.html) | Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed. |
| `endpoint` - [`Endpoint`](https://wartiva.com/api-docs/types/endpoint.html) | The Endpoint this ArpTableEntry belongs to if available. |
| `device` - [`Device`](https://wartiva.com/api-docs/types/device.html) | The Device this ArpTableEntry maps to if available. |
| `networkPrefix` - [`NetworkPrefix`](https://wartiva.com/api-docs/types/network-prefix.html) | The NetworkPrefix this ArpTableEntry maps to if available. |
| `ip` - [`IpAddress!`](https://wartiva.com/api-docs/types/ip-address.html) | The neighbor's IP address (IPv4 or IPv6) that this entry resolves. |
| `mac` - [`Mac!`](https://wartiva.com/api-docs/types/mac.html) | The hardware (MAC) address the endpoint resolved `ip` to. |
| `static` - [`Boolean!`](https://wartiva.com/api-docs/types/boolean.html) | True if this entry is static and manually entered by an administrator. |
| `ifaceIndex` - [`Int!`](https://wartiva.com/api-docs/types/int.html) | O/S level index number of the interface number this entry was found for if available. |
| `duplicates` - [`[ArpTableEntryDuplicate!]!`](https://wartiva.com/api-docs/types/arp-table-entry-duplicate.html) | The other ARP table entries on this endpoint and interface that claim this entry's IP address with a different MAC address. Two hosts answering for one address is what ARP spoofing and cache poisoning look like on the wire, and it is also what an address conflict looks like. A conflict that has since resolved is kept here with `isActive` false, so the record shows that an address was contested and when. Ordered by the conflicting entry's identifier. |
| `activeDuplicateCount` - [`Int!`](https://wartiva.com/api-docs/types/int.html) | How many entries in `duplicates` were present in the most recent observation of this endpoint's ARP table. Non-zero means this entry's address is contested right now. |
| `findings` - [`FindingsPayload!`](https://wartiva.com/api-docs/types/findings-payload.html) | Policy findings for this object. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. |
| `issues` - [`IssuesPayload!`](https://wartiva.com/api-docs/types/issues-payload.html) | Policy issues for this object. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. |
| `issuesSummary` - [`IssuesSummary!`](https://wartiva.com/api-docs/types/issues-summary.html) | Summary of the active policy issues currently open on this object, broken down by severity. |

## Returned by

- [`arpTableEntry`](https://wartiva.com/api-docs/queries/arp-table-entry.html) query: Retrieves an ArpTableEntry by its graph object id: one entry in an endpoint's neighbor cache (ARP for IPv4, NDP for IPv6 where the operating system…

## Used by

- [`Endpoint`](https://wartiva.com/api-docs/types/endpoint.html) type: A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
- [`ArpTableEntryConnection`](https://wartiva.com/api-docs/types/arp-table-entry-connection.html) type: Collection payload for ArpTableEntry edges with total count.
- [`ArpTableEntryDuplicate`](https://wartiva.com/api-docs/types/arp-table-entry-duplicate.html) type: Another ARP table entry claiming the same IP address as the entry that records it, with a different MAC address — an address conflict, and the shape…
- [`ArpTableEntryEdge`](https://wartiva.com/api-docs/types/arp-table-entry-edge.html) type: Edge payload for an ArpTableEntry with optional seen data.
- [`ArpTableEntryPayload`](https://wartiva.com/api-docs/types/arp-table-entry-payload.html) type: Payload wrapper for a single ArpTableEntry result.
- [`GraphObjectType`](https://wartiva.com/api-docs/types/graph-object-type.html) enum: An enumeration of the different types of security graph objects.
- [`GraphObjectTypeCategory`](https://wartiva.com/api-docs/types/graph-object-type-category.html) enum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.

## Related types

- [`Device`](https://wartiva.com/api-docs/types/device.html) A physical or virtual device that does not run the Wartiva endpoint application but is visible on the network to a managed Endpoint, such as…
- [`Endpoint`](https://wartiva.com/api-docs/types/endpoint.html) A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
- [`NetworkPrefix`](https://wartiva.com/api-docs/types/network-prefix.html) A specific IP address together with its subnet prefix length (e.g.

## Example

### Example

```json
{
  "id": 4,
  "orgId": "615f3b3b28284380e28a7342",
  "seen": SeenOnline,
  "objectType": "ACCOUNT_POLICY",
  "objectTypeLabel": "xyz789",
  "displayName": "abc123",
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z",
  "createdAt": "2021-10-07T18:23:25.829Z",
  "updatedAt": "2021-10-07T18:23:25.829Z",
  "snapshotInfo": GraphObjectSnapshotInfo,
  "endpoint": Endpoint,
  "device": Device,
  "networkPrefix": NetworkPrefix,
  "ip": IpAddress,
  "mac": "f0:18:98:14:8e:80",
  "static": true,
  "ifaceIndex": 123,
  "duplicates": [ArpTableEntryDuplicate],
  "activeDuplicateCount": 987,
  "findings": FindingsPayload,
  "issues": IssuesPayload,
  "issuesSummary": IssuesSummary
}

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
