A file system mounted on an Endpoint, identified by its device and mount point (for example C: on Windows or / on Linux and macOS). Collected on Windows, macOS, and Linux. Each DiskMount carries the file system type, the mount options in effect (DiskMountOption, such as read-only or noexec), and capacity and inode usage (DiskUsage). The physical drives behind mounts are modeled separately as Disk.
Fields
| Field Name | Description |
|---|---|
id - ID!
|
The DiskMount's unique identifier on the security graph. |
orgId - OrganizationId!
|
Unique identifier that corresponds to your deployment of this product or a specific customer account that this Endpoint belongs to. |
seen - SeenOnline!
|
Describes when this DiskMount was seen. |
objectType - GraphObjectType!
|
The type of this graph object. |
objectTypeLabel - String!
|
A localized label describing the object type. |
displayName - String!
|
A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object. |
firstSeen - Time!
|
Time this object was first seen. |
lastSeen - Time!
|
Time this object was last seen. |
createdAt - Time!
|
The time this object was created in the security graph. |
updatedAt - Time!
|
The time this object was last mutated in the security graph. |
snapshotInfo - GraphObjectSnapshotInfo!
|
Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed. |
endpoint - Endpoint
|
The Endpoint this DiskMount belongs to if available. |
device - String!
|
The physical device e.g. C: or /dev/disk9s2. |
mountpoint - String!
|
The mount point e.g. C: or /. |
fstype - String!
|
The file system type e.g. NTFS, apfs, etc |
options - [DiskMountOption!]
|
The mount options in effect for this file system, such as read-only or noexec. |
usage - DiskUsage
|
Information about space available on this file system if available. |
findings - FindingsPayload!
|
Policy findings for this object. |
issues - IssuesPayload!
|
Policy issues for this object. |
issuesSummary - IssuesSummary!
|
Summary of the active policy issues currently open on this object, broken down by severity. |
Returned by
diskMountquery: Retrieves a DiskMount by its graph object id: a mounted file system on an endpoint, with its file system type, mount options, and capacity and inode…
Used by
Endpointtype: A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.DiskMountConnectiontype: Collection payload for DiskMount edges with total count.DiskMountEdgetype: Edge payload for a DiskMount with optional seen data.DiskMountPayloadtype: Payload wrapper for a single DiskMount result.GraphObjectTypeenum: An enumeration of the different types of security graph objects.GraphObjectTypeCategoryenum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.RuleApplyToOptionKeyenum: Attribute keys that further scope which objects a rule applies to, in addition to its applyTo object type.
Related types
EndpointA Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
Example
Example
{
"id": 4,
"orgId": "615f3b3b28284380e28a7342",
"seen": SeenOnline,
"objectType": "ACCOUNT_POLICY",
"objectTypeLabel": "xyz789",
"displayName": "xyz789",
"firstSeen": "2021-10-07T18:23:25.829Z",
"lastSeen": "2021-10-07T18:23:25.829Z",
"createdAt": "2021-10-07T18:23:25.829Z",
"updatedAt": "2021-10-07T18:23:25.829Z",
"snapshotInfo": GraphObjectSnapshotInfo,
"endpoint": Endpoint,
"device": "xyz789",
"mountpoint": "xyz789",
"fstype": "xyz789",
"options": ["READ_WRITE"],
"usage": DiskUsage,
"findings": FindingsPayload,
"issues": IssuesPayload,
"issuesSummary": IssuesSummary
}