Endpoint configuration · GraphQL type

DiskMount type

A file system mounted on an Endpoint, identified by its device and mount point (for example C: on Windows or / on Linux and macOS). Collected on Windows, macOS, and Linux. Each DiskMount carries the file system type, the mount options in effect (DiskMountOption, such as read-only or noexec), and capacity and inode usage (DiskUsage). The physical drives behind mounts are modeled separately as Disk.

Fields

Field Name Description
id - ID! The DiskMount's unique identifier on the security graph.
orgId - OrganizationId! Unique identifier that corresponds to your deployment of this product or a specific customer account that this Endpoint belongs to.
seen - SeenOnline! Describes when this DiskMount was seen.
objectType - GraphObjectType! The type of this graph object.
objectTypeLabel - String! A localized label describing the object type.
displayName - String! A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object.
firstSeen - Time! Time this object was first seen.
lastSeen - Time! Time this object was last seen.
createdAt - Time! The time this object was created in the security graph.
updatedAt - Time! The time this object was last mutated in the security graph.
snapshotInfo - GraphObjectSnapshotInfo! Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed.
endpoint - Endpoint The Endpoint this DiskMount belongs to if available.
device - String! The physical device e.g. C: or /dev/disk9s2.
mountpoint - String! The mount point e.g. C: or /.
fstype - String! The file system type e.g. NTFS, apfs, etc
options - [DiskMountOption!] The mount options in effect for this file system, such as read-only or noexec.
usage - DiskUsage Information about space available on this file system if available.
findings - FindingsPayload! Policy findings for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issues - IssuesPayload! Policy issues for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issuesSummary - IssuesSummary! Summary of the active policy issues currently open on this object, broken down by severity.

Returned by

  • diskMount query: Retrieves a DiskMount by its graph object id: a mounted file system on an endpoint, with its file system type, mount options, and capacity and inode…

Used by

  • Endpoint type: A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
  • DiskMountConnection type: Collection payload for DiskMount edges with total count.
  • DiskMountEdge type: Edge payload for a DiskMount with optional seen data.
  • DiskMountPayload type: Payload wrapper for a single DiskMount result.
  • GraphObjectType enum: An enumeration of the different types of security graph objects.
  • GraphObjectTypeCategory enum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.
  • RuleApplyToOptionKey enum: Attribute keys that further scope which objects a rule applies to, in addition to its applyTo object type.

Related types

  • Endpoint A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.

Example

Example

{
  "id": 4,
  "orgId": "615f3b3b28284380e28a7342",
  "seen": SeenOnline,
  "objectType": "ACCOUNT_POLICY",
  "objectTypeLabel": "xyz789",
  "displayName": "xyz789",
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z",
  "createdAt": "2021-10-07T18:23:25.829Z",
  "updatedAt": "2021-10-07T18:23:25.829Z",
  "snapshotInfo": GraphObjectSnapshotInfo,
  "endpoint": Endpoint,
  "device": "xyz789",
  "mountpoint": "xyz789",
  "fstype": "xyz789",
  "options": ["READ_WRITE"],
  "usage": DiskUsage,
  "findings": FindingsPayload,
  "issues": IssuesPayload,
  "issuesSummary": IssuesSummary
}