Endpoint configuration · GraphQL type

AuditPolicy type

The security event auditing configuration of an Endpoint. Collected on Windows and macOS: on Windows it is the Advanced Audit Policy Configuration, recording the success/failure setting of each audit subcategory (logon/logoff, object access, privilege use, process tracking, policy change, account management and others) in AuditPolicyWindows; on macOS it is the audit configuration read from /etc/security/audit_control, including audit flags, log directories and retention limits, in AuditPolicyMacOS. Each Endpoint has at most one AuditPolicy, reachable from the Endpoint's auditPolicy field.

Fields

Field Name Description
id - ID! The AuditPolicy's unique identifier on the security graph.
orgId - OrganizationId! Unique identifier that corresponds to your deployment of this product or a specific customer account that this Endpoint belongs to.
seen - SeenOnline! Describes when this AuditPolicy was seen.
objectType - GraphObjectType! The type of this graph object.
objectTypeLabel - String! A localized label describing the object type.
displayName - String! A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object.
firstSeen - Time! Time this object was first seen.
lastSeen - Time! Time this object was last seen.
createdAt - Time! The time this object was created in the security graph.
updatedAt - Time! The time this object was last mutated in the security graph.
snapshotInfo - GraphObjectSnapshotInfo! Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed.
endpoint - Endpoint The Endpoint this AuditPolicy belongs to if available.
osSpecific - AuditPolicyOsSpecific The platform-specific audit configuration: AuditPolicyWindows on Windows or AuditPolicyMacOS on macOS.
findings - FindingsPayload! Policy findings for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issues - IssuesPayload! Policy issues for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issuesSummary - IssuesSummary! Summary of the active policy issues currently open on this object, broken down by severity.

Returned by

  • auditPolicy query: Retrieves an endpoint's AuditPolicy by its graph object id: the security event auditing configuration, either the Windows Advanced Audit Policy…

Used by

  • Endpoint type: A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
  • AuditPolicyPayload type: Payload wrapper for a single AuditPolicy result.
  • GraphObjectType enum: An enumeration of the different types of security graph objects.
  • GraphObjectTypeCategory enum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.

Related types

  • Endpoint A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.

Example

Example

{
  "id": "4",
  "orgId": "615f3b3b28284380e28a7342",
  "seen": SeenOnline,
  "objectType": "ACCOUNT_POLICY",
  "objectTypeLabel": "xyz789",
  "displayName": "xyz789",
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z",
  "createdAt": "2021-10-07T18:23:25.829Z",
  "updatedAt": "2021-10-07T18:23:25.829Z",
  "snapshotInfo": GraphObjectSnapshotInfo,
  "endpoint": Endpoint,
  "osSpecific": AuditPolicyWindows,
  "findings": FindingsPayload,
  "issues": IssuesPayload,
  "issuesSummary": IssuesSummary
}