Endpoint configuration · GraphQL type

EndpointGroup type

An operating system or domain group observed on an Endpoint. The agent reads local groups through the NetLocalGroupEnum API on Windows, /etc/group on Linux, and the system group database on macOS. A group is identified on its Endpoint by its SID on Windows and by its numeric GID on Linux and macOS, so the same group name on two computers yields two EndpointGroup objects. Membership is exposed as EndpointUser connections through members (current) and membersSeen (history).

Fields

Field Name Description
id - ID! The EndpointGroup's unique identifier on the security graph.
orgId - OrganizationId! Unique identifier that corresponds to your deployment of this product or a specific customer account that this Endpoint belongs to.
seen - SeenOnline! Describes when this EndpointGroup was seen.
objectType - GraphObjectType! The type of this graph object.
objectTypeLabel - String! A localized label describing the object type.
displayName - String! A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object.
firstSeen - Time! Time this object was first seen.
lastSeen - Time! Time this object was last seen.
createdAt - Time! The time this object was created in the security graph.
updatedAt - Time! The time this object was last mutated in the security graph.
snapshotInfo - GraphObjectSnapshotInfo! Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed.
endpoint - Endpoint The Endpoint this EndpointGroup belongs to if available.
groupname - String! The group's name as reported by the operating system, for example Administrators on Windows or wheel on macOS.
description - String! Description of the group if available.
gid - Int! The operating system group identifier (GID).
sid - String The security identifier (SID) of the group, a variable-length string that uniquely identifies users or groups in the MS Windows O/S. Available on Windows endpoints only.
members - EndpointUserConnection! Users that are members of this EndpointGroup.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

membersSeen - EndpointUserConnection! Historical sightings of EndpointUser observed as members of this group. Each edge records when the membership was observed; pass timeRange to constrain the window. When timeRange is null the last 30 days will be returned.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

timeRange - DateTimeRangeInput

Restrict edges to a date/time range.

includeSeen - Boolean

Include the per-edge seen series in the response.

findings - FindingsPayload! Policy findings for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issues - IssuesPayload! Policy issues for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issuesSummary - IssuesSummary! Summary of the active policy issues currently open on this object, broken down by severity.

Returned by

  • endpointGroup query: Retrieves an EndpointGroup by its graph object id: an operating system or domain group on an endpoint, identified by its SID on Windows or GID on…

Used by

  • Endpoint type: A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
  • EndpointPathEntryStats type: The stat record of one file a PathSensor discovered, stored as alternate data on the owning EndpointPath object and retrieved with…
  • EndpointUser type: An operating system or domain user account observed on an Endpoint.
  • EndpointGroupConnection type: Collection payload for EndpointGroup edges with total count.
  • EndpointGroupEdge type: Edge payload for an EndpointGroup with optional seen data.
  • EndpointGroupPayload type: Payload wrapper for a single EndpointGroup result.
  • GraphObjectType enum: An enumeration of the different types of security graph objects.
  • GraphObjectTypeCategory enum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.

Related types

  • Endpoint A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
  • EndpointUser An operating system or domain user account observed on an Endpoint.

Example

Example

{
  "id": "4",
  "orgId": "615f3b3b28284380e28a7342",
  "seen": SeenOnline,
  "objectType": "ACCOUNT_POLICY",
  "objectTypeLabel": "xyz789",
  "displayName": "xyz789",
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z",
  "createdAt": "2021-10-07T18:23:25.829Z",
  "updatedAt": "2021-10-07T18:23:25.829Z",
  "snapshotInfo": GraphObjectSnapshotInfo,
  "endpoint": Endpoint,
  "groupname": "abc123",
  "description": "xyz789",
  "gid": 987,
  "sid": "xyz789",
  "members": EndpointUserConnection,
  "membersSeen": EndpointUserConnection,
  "findings": FindingsPayload,
  "issues": IssuesPayload,
  "issuesSummary": IssuesSummary
}