A physical disk drive attached to an Endpoint, identified on that Endpoint by its operating-system drive ID (for example \\.\PhysicalDrive0 on Windows). Collected on Windows, macOS, and Linux; on Linux, drives the system reports as removable are skipped. Each Disk carries its size, its Partition and Volume layout, and I/O statistics (DiskIoStat); vendor, model, serial number, and BusType are reported where the platform exposes them. Mounted file systems are modeled separately as DiskMount.
Fields
| Field Name | Description |
|---|---|
id - ID!
|
The Disk's unique identifier on the security graph. |
orgId - OrganizationId!
|
Unique identifier that corresponds to your deployment of this product or a specific customer account that this Endpoint belongs to. |
seen - SeenOnline!
|
Describes when this Disk was seen. |
objectType - GraphObjectType!
|
The type of this graph object. |
objectTypeLabel - String!
|
A localized label describing the object type. |
displayName - String!
|
A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object. |
firstSeen - Time!
|
Time this object was first seen. |
lastSeen - Time!
|
Time this object was last seen. |
createdAt - Time!
|
The time this object was created in the security graph. |
updatedAt - Time!
|
The time this object was last mutated in the security graph. |
snapshotInfo - GraphObjectSnapshotInfo!
|
Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed. |
endpoint - Endpoint
|
The Endpoint this Disk belongs to if available. |
driveId - String!
|
The unique identifier of the disk as reported by the operating system or hardware. |
serial - String
|
The hardware serial number of the disk. |
size - Uint64!
|
The total disk size in bytes. |
vendor - String
|
The vendor name of the disk. |
model - String
|
The model number or name of the disk. |
manufacturer - String
|
The manufacturer of the disk as reported by the operating system or hardware. |
description - String
|
A descriptive label or additional details about the disk. |
busType - BusType
|
The interface or bus type used by the disk. |
partitions - [Partition!]
|
The list of partitions defined on the disk. |
volumes - [Volume!]
|
The list of logical volumes created on the disk. |
stats - DiskIoStat!
|
Input/output performance statistics for the disk, including read/write data. |
findings - FindingsPayload!
|
Policy findings for this object. |
issues - IssuesPayload!
|
Policy issues for this object. |
issuesSummary - IssuesSummary!
|
Summary of the active policy issues currently open on this object, broken down by severity. |
Returned by
diskquery: Retrieves a Disk by its graph object id: a physical disk drive attached to an endpoint, with its partitions, volumes, and I/O statistics, on…
Used by
Endpointtype: A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.DiskConnectiontype: Collection payload for Disk edges with total count.DiskEdgetype: Edge payload for a Disk with optional seen data.DiskPayloadtype: Payload wrapper for a single Disk result.GraphObjectTypeenum: An enumeration of the different types of security graph objects.GraphObjectTypeCategoryenum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.RuleApplyToOptionKeyenum: Attribute keys that further scope which objects a rule applies to, in addition to its applyTo object type.
Related types
EndpointA Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
Example
Example
{
"id": 4,
"orgId": "615f3b3b28284380e28a7342",
"seen": SeenOnline,
"objectType": "ACCOUNT_POLICY",
"objectTypeLabel": "abc123",
"displayName": "abc123",
"firstSeen": "2021-10-07T18:23:25.829Z",
"lastSeen": "2021-10-07T18:23:25.829Z",
"createdAt": "2021-10-07T18:23:25.829Z",
"updatedAt": "2021-10-07T18:23:25.829Z",
"snapshotInfo": GraphObjectSnapshotInfo,
"endpoint": Endpoint,
"driveId": "xyz789",
"serial": "abc123",
"size": "8589934592",
"vendor": "abc123",
"model": "abc123",
"manufacturer": "abc123",
"description": "xyz789",
"busType": "UNKNOWN",
"partitions": [Partition],
"volumes": [Volume],
"stats": DiskIoStat,
"findings": FindingsPayload,
"issues": IssuesPayload,
"issuesSummary": IssuesSummary
}