Networks, devices, and sensors · GraphQL type

Device type

A physical or virtual device that does not run the Wartiva endpoint application but is visible on the network to a managed Endpoint, such as gateways, printers, cameras, telephones, IoT and home-automation equipment, virtual machines, and unmanaged computers. Endpoints discover devices passively and actively on their local networks, from their ARP/NDP neighbor tables, mDNS (DNS-SD), SSDP/UPnP, and DHCP traffic, and from TCP and UDP port scans. A fingerprinting pipeline classifies each device by type and resolves its DeviceManufacturer, usually from the MAC address OUI, and, less often, its DeviceModel. A Device links to the Network objects it was seen on, the OpenPort and Service objects found on it, and the endpoints that had connectivity to it.

Fields

Field Name Description
id - ID! Unique identifier for this graph object.
orgId - OrganizationId! Unique identifier for the owning organization.
objectType - GraphObjectType! The type of this graph object.
objectTypeLabel - String! A localized label describing the object type.
displayName - String! A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object.
firstSeen - Time! Time this object was first seen.
lastSeen - Time! Time this object was last seen.
seen - SeenOnline! When this graph object was seen.
createdAt - Time! The time this object was created in the security graph.
updatedAt - Time! The time this object was last mutated in the security graph.
snapshotInfo - GraphObjectSnapshotInfo! Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed.
mac - Mac Hardware or mac address of this device.
ipNetworks - [DeviceIpNetwork!] IP addresses and networks this device was found using.
natIps - [DeviceNatIp!] Describes IP addresses on this Device that were detected as a Network Address Translation (NAT) address used by a managed Endpoint to connect to this hosted service.
ip - IpAddress Primary IP address for this Device. Selected from the ipNetworks of the Device by preferring, in order: public IPv4, private IPv4, public IPv6, private IPv6, link-local unicast IPv4, link-local unicast IPv6, multicast IPv4, multicast IPv6. Within the highest-priority category that has a match, the numerically lowest IP address is chosen. Null when this Device has no ipNetworks.
ips - [IpAddress!] Every IP address known for this device, combining the addresses in ipNetworks and natIps, in sorted order.
hostname - String! Primary hostname of the device if known.
allHostnames - [DeviceHostname!] All hostnames discovered for this Device.
isGateway - Boolean! True if this device is a gateway for the endpoint.
type - DeviceTypeCategory! The DeviceTypeCategory resolved for this Device by the fingerprint pipeline, taken from the result fingerprint. Defaults to UNKNOWN when the fingerprint pipeline has not resolved a category.
fingerprints - DeviceFingerprint! Result and Resolved fingerprints that were used to identify this Device.
portsSummary - DeviceOpenPorts! Summary of open network port numbers.
arpTableEntries - ArpTableEntryConnection! ARP table entries that map to this Device.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

endpoints - EndpointConnection! Endpoints that have had connectivity to this Device. When timeRange is null the last 30 days will be returned. When timeRange is specified all entries seen in the time range are returned.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

timeRange - DateTimeRangeInput

Optional time range filter.

includeSeen - Boolean

When true, the payload will include information about when the edge was seen in the relationship. The data set will be limited to the time range specified in the timeRange field. If includeSeen is true and timeRange is null then seen data for the default 7 day time range will be returned.

gatewayForNetworks - NetworkConnection! Networks this Device was seen acting as a gateway for. When timeRange is null the last 30 days will be returned. When timeRange is specified all entries seen in the time range are returned.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

timeRange - DateTimeRangeInput

Optional time range filter.

includeSeen - Boolean

When true, the payload will include information about when the edge was seen in the relationship. The data set will be limited to the time range specified in the timeRange field. If includeSeen is true and timeRange is null then seen data for the default 7 day time range will be returned.

lastPosition - PositionSeen The last PositionSeen where this Device was observed.
manufacturer - DeviceManufacturer The DeviceManufacturer of this Device if known.
model - DeviceModel The DeviceModel this Device is an instance of if known.
networks - NetworkConnection! Networks this Device was seen connected to. When timeRange is null the last 30 days will be returned. When timeRange is specified all entries seen in the time range are returned.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

timeRange - DateTimeRangeInput

Optional time range filter.

includeSeen - Boolean

When true, the payload will include information about when the edge was seen in the relationship. The data set will be limited to the time range specified in the timeRange field. If includeSeen is true and timeRange is null then seen data for the default 7 day time range will be returned.

ports - OpenPortConnection! Open ports found on this Device.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

positions - PositionSeenConnection! PositionSeen observations for this Device in the specified time range. When timeRange is null the last 30 days will be returned.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

timeRange - DateTimeRangeInput

Optional time range filter.

includeSeen - Boolean

When true, the payload will include information about when the edge was seen in the relationship. The data set will be limited to the time range specified in the timeRange field. If includeSeen is true and timeRange is null then seen data for the default 7 day time range will be returned.

primaryPosition - PositionSeen The PositionSeen this Device spent the most time at.
seenNetworkPrefixes - NetworkPrefixConnection! NetworkPrefixes seen configured on this Device. When timeRange is null the last 30 days will be returned. When timeRange is specified all entries seen in the time range are returned.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

timeRange - DateTimeRangeInput

Optional time range filter.

includeSeen - Boolean

When true, the payload will include information about when the edge was seen in the relationship. The data set will be limited to the time range specified in the timeRange field. If includeSeen is true and timeRange is null then seen data for the default 7 day time range will be returned.

services - ServiceConnection! Network services found on this Device.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

sensorRequestIds - [ID!] List of unique identifiers belonging to the sensors requested on this Device.

Arguments

count - Int

Maximum number of sensor request IDs to return.

sensorRequests - [SensorRequest!] List of sensors requested on this Device.

Arguments

count - Int

Maximum number of sensor requests to return.

sensorRequestRunIds - [ID!] History of unique identifiers for the runs of sensors on this Device ordered by most recent first.

Arguments

count - Int

Maximum number of sensor request run IDs to return.

sensorRequestRuns - [SensorRequestRun!] History of runs of sensors on this Device ordered by most recent first.

Arguments

count - Int

Maximum number of sensor request runs to return.

findings - FindingsPayload! Policy findings for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issues - IssuesPayload! Policy issues for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issuesSummary - IssuesSummary! Summary of the active policy issues currently open on this object, broken down by severity.

Returned by

  • device query: Retrieves a Device by its graph object id: an unmanaged device, such as a printer, camera, phone, or IoT appliance, that managed endpoints see on…

Used by

  • ArpTableEntry type: One entry in an Endpoint's neighbor cache: the IPv4 Address Resolution Protocol (ARP) table and, where the operating system reports it, the IPv6…
  • DeviceManufacturer type: A hardware vendor that made one or more discovered Device objects in an organization.
  • DeviceModel type: A specific product model, made by a DeviceManufacturer, that one or more discovered Device objects in an organization are instances of.
  • Endpoint type: A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
  • NetworkPrefix type: A specific IP address together with its subnet prefix length (e.g.
  • OpenPort type: One TCP or UDP port at one IP address on a discovered Device, found by managed endpoints port-scanning the devices on their local networks and by…
  • PositionSeen type: A geographic coordinate (latitude and longitude) where a managed Endpoint was observed, and the times it was seen there.
  • SensorRequest type: A standing request to run one Sensor against one Device IP address, optionally on a specific protocol and port, in the SAE or PUBLIC zone.
  • SensorRequestRun type: The record of one attempt to run a SensorRequest: when it ran, which sensor version ran it, which Endpoint ran it (none for PUBLIC-zone runs, which…
  • Service type: A network service identified on a discovered Device: one protocol (such as HTTP, TLS, SSH, SMB, DNS, SNMP, IPP, mDNS, or UPnP) acting as a client or…
  • DeviceConnection type: Connection for Device edges with total count.
  • DeviceEdge type: Edge payload for a Device with optional seen data.
  • DevicePayload type: Payload wrapper for a single Device result.
  • GraphObjectType enum: An enumeration of the different types of security graph objects.
  • GraphObjectTypeCategory enum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.
  • RuleApplyToOptionKey enum: Attribute keys that further scope which objects a rule applies to, in addition to its applyTo object type.

Related types

  • DeviceManufacturer A hardware vendor that made one or more discovered Device objects in an organization.
  • DeviceModel A specific product model, made by a DeviceManufacturer, that one or more discovered Device objects in an organization are instances of.
  • NetworkPrefix A specific IP address together with its subnet prefix length (e.g.
  • PositionSeen A geographic coordinate (latitude and longitude) where a managed Endpoint was observed, and the times it was seen there.
  • SensorRequest A standing request to run one Sensor against one Device IP address, optionally on a specific protocol and port, in the SAE or PUBLIC zone.
  • SensorRequestRun The record of one attempt to run a SensorRequest: when it ran, which sensor version ran it, which Endpoint ran it (none for PUBLIC-zone runs, which…

Example

Example

{
  "id": "4",
  "orgId": "615f3b3b28284380e28a7342",
  "objectType": "ACCOUNT_POLICY",
  "objectTypeLabel": "abc123",
  "displayName": "xyz789",
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z",
  "seen": SeenOnline,
  "createdAt": "2021-10-07T18:23:25.829Z",
  "updatedAt": "2021-10-07T18:23:25.829Z",
  "snapshotInfo": GraphObjectSnapshotInfo,
  "mac": "f0:18:98:14:8e:80",
  "ipNetworks": [DeviceIpNetwork],
  "natIps": [DeviceNatIp],
  "ip": IpAddress,
  "ips": [IpAddress],
  "hostname": "xyz789",
  "allHostnames": [DeviceHostname],
  "isGateway": true,
  "type": "UNKNOWN",
  "fingerprints": DeviceFingerprint,
  "portsSummary": DeviceOpenPorts,
  "arpTableEntries": ArpTableEntryConnection,
  "endpoints": EndpointConnection,
  "gatewayForNetworks": NetworkConnection,
  "lastPosition": PositionSeen,
  "manufacturer": DeviceManufacturer,
  "model": DeviceModel,
  "networks": NetworkConnection,
  "ports": OpenPortConnection,
  "positions": PositionSeenConnection,
  "primaryPosition": PositionSeen,
  "seenNetworkPrefixes": NetworkPrefixConnection,
  "services": ServiceConnection,
  "sensorRequestIds": ["4"],
  "sensorRequests": [SensorRequest],
  "sensorRequestRunIds": [4],
  "sensorRequestRuns": [SensorRequestRun],
  "findings": FindingsPayload,
  "issues": IssuesPayload,
  "issuesSummary": IssuesSummary
}