---
title: EndpointPathEntryStats type | Wartiva GraphQL API
description: The stat record of one file a PathSensor discovered, stored as alternate data on the owning EndpointPath object and retrieved with endpointPathEntryStats.
url: https://wartiva.com/api-docs/types/endpoint-path-entry-stats.html
updated: 2026-10-07
---

File path sensors · GraphQL type

# `EndpointPathEntryStats` type

The stat record of one file a PathSensor discovered, stored as alternate data on the owning [EndpointPath](https://wartiva.com/api-docs/types/endpoint-path.html) object and retrieved with [endpointPathEntryStats](https://wartiva.com/api-docs/queries/endpoint-path-entry-stats.html).

## Fields

| Field Name | Description |
|---|---|
| `path` - [`String!`](https://wartiva.com/api-docs/types/string.html) | The file's absolute path as reported by the endpoint. |
| `mode` - [`PosixFileMode!`](https://wartiva.com/api-docs/types/posix-file-mode.html) | The file's permission bits decoded into octal, symbolic, per-class, and special-bit forms. |
| `isDirectory` - [`Boolean!`](https://wartiva.com/api-docs/types/boolean.html) | True when this entry is a directory. Derived cross-platform from the file mode (and, on Windows, the DIRECTORY file attribute). |
| `isSymlink` - [`Boolean!`](https://wartiva.com/api-docs/types/boolean.html) | True when this entry is a symbolic link. Populated on Linux and macOS (endpoints that lstat the file). |
| `symlinkTarget` - [`String`](https://wartiva.com/api-docs/types/string.html) | The path a symbolic link points at, or null when this entry is not a symlink. Linux and macOS only. |
| `isHardLink` - [`Boolean!`](https://wartiva.com/api-docs/types/boolean.html) | True when this entry is a regular file with more than one hard link (link count > 1). Linux and macOS only. |
| `hardLinkCount` - [`Int`](https://wartiva.com/api-docs/types/int.html) | The file's POSIX hard-link count (st_nlink), or null on Windows where it is not collected. |
| `inode` - [`Int64`](https://wartiva.com/api-docs/types/int64.html) | The file's inode number (st_ino). Together with `deviceId` it identifies the underlying inode, so files that are hard links of one another can be correlated. Null on Windows. |
| `deviceId` - [`Int64`](https://wartiva.com/api-docs/types/int64.html) | The device id (st_dev) of the filesystem holding the file. Pairs with `inode`. Null on Windows. |
| `ownerUid` - [`Int`](https://wartiva.com/api-docs/types/int.html) | The file's POSIX owner UID, or null on Windows (which has no POSIX ownership). |
| `ownerGid` - [`Int`](https://wartiva.com/api-docs/types/int.html) | The file's POSIX owner GID, or null on Windows. |
| `owner` - [`EndpointUser`](https://wartiva.com/api-docs/types/endpoint-user.html) | The [EndpointUser](https://wartiva.com/api-docs/types/endpoint-user.html) that owns this file, resolved from ownerUid on the same endpoint. Null on Windows or when no matching user has been observed. |
| `group` - [`EndpointGroup`](https://wartiva.com/api-docs/types/endpoint-group.html) | The [EndpointGroup](https://wartiva.com/api-docs/types/endpoint-group.html) that owns this file, resolved from ownerGid on the same endpoint. Null on Windows or when no matching group has been observed. |
| `size` - [`Int64!`](https://wartiva.com/api-docs/types/int64.html) | File size in bytes. |
| `modifiedAt` - [`Time`](https://wartiva.com/api-docs/types/time.html) | File modification time reported by the endpoint. Null when the endpoint reported no modification time — e.g. a file reported deleted (its mtime is no longer observable) or a report where the file could not be stat'd. |
| `checksum` - [`String!`](https://wartiva.com/api-docs/types/string.html) | Checksum of the file on disk (xxh3-128, lowercase hex), or empty when none is available. It is populated when the sensor's `collectChecksum` is enabled (the endpoint hashes up to the sensor's `checksumMaxBytes` of the file, regardless of how much content was collected), or when contents were collected and covered the whole file (the server then hashes the stream with the same scheme). When contents were collected but truncated to `contentMaxBytes` and `collectChecksum` was not enabled, this is empty. See `contentTruncated` for whether the stored contents are a prefix. |
| `hasContents` - [`Boolean!`](https://wartiva.com/api-docs/types/boolean.html) | True if file contents are stored for this file. |
| `deleted` - [`Boolean!`](https://wartiva.com/api-docs/types/boolean.html) | True if this file was reported deleted on the endpoint. The stat record is retained and marked, not removed, so the deletion remains visible; the file's collected bytes are removed when the deletion is reported. A later sighting of the same path clears the marker. |
| `deletedAt` - [`Time`](https://wartiva.com/api-docs/types/time.html) | When the endpoint reported this file as deleted, if it has been. Null for files still present. |
| `renamedTo` - [`String`](https://wartiva.com/api-docs/types/string.html) | The path this file was renamed to, set only on deleted entries whose deletion was observed as a rename. The entry stays at the original path; the new path appears as its own entry when a sensor covers it. Null when the file was not renamed away. |
| `executedAt` - [`Time`](https://wartiva.com/api-docs/types/time.html) | Set when the report this entry came from observed an open-for-execution of the file (execve, not an interpreter read) since the path's previous report; the timestamp is the report's collection time, not the exact exec time. Null when the covering report saw no execution. |
| `contentTruncated` - [`Boolean!`](https://wartiva.com/api-docs/types/boolean.html) | True when the collected contents are only the first `contentMaxBytes` of a larger file (a prefix), rather than the whole file. Meaningful only when `hasContents` is true. When true, the blob behind the entry's `contentsUrl` and the bytes from its `contentsAsString` are a prefix, not the complete file. This is independent of `checksum`, which (when `collectChecksum` is enabled) reflects the file hashed up to the sensor's `checksumMaxBytes` regardless of how much content was stored — see `checksum`. |
| `collectedAt` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | When the endpoint collected this stat record. |
| `osSpecific` - [`EndpointPathOsSpecific`](https://wartiva.com/api-docs/types/endpoint-path-os-specific.html) | OS-specific fields for this file. The concrete type depends on the endpoint platform. |
| `creationTime` - [`Time`](https://wartiva.com/api-docs/types/time.html) | File creation time reported by the endpoint, when available. |
| `lastWriteTime` - [`Time`](https://wartiva.com/api-docs/types/time.html) | Last write time reported by the endpoint, when available. |
| `lastAccessTime` - [`Time`](https://wartiva.com/api-docs/types/time.html) | Last access time reported by the endpoint, when available. |
| `lastChangeTime` - [`Time`](https://wartiva.com/api-docs/types/time.html) | Last metadata change time (Unix ctime) reported by the endpoint, when available. |
| `lastStatusChangeTime` - [`Time`](https://wartiva.com/api-docs/types/time.html) | Last status change time reported by the endpoint, when available. |

## Returned by

- [`endpointPathEntryStats`](https://wartiva.com/api-docs/queries/endpoint-path-entry-stats.html) query: Retrieves the stat record (mode, ownership, sizes, timestamps, and OS-specific attributes) of one file path discovered by an EndpointPath — list…

## Used by

- [`EndpointPathEntrySearchMatch`](https://wartiva.com/api-docs/types/endpoint-path-entry-search-match.html) type: One path search match: a discovered file entry together with the EndpointPath whose sensor collected it.
- [`EndpointPathEntryStatsPayload`](https://wartiva.com/api-docs/types/endpoint-path-entry-stats-payload.html) type: Payload wrapper for a single EndpointPathEntryStats.

## Related types

- [`EndpointGroup`](https://wartiva.com/api-docs/types/endpoint-group.html) An operating system or domain group observed on an Endpoint.
- [`EndpointUser`](https://wartiva.com/api-docs/types/endpoint-user.html) An operating system or domain user account observed on an Endpoint.

## Example

### Example

```json
{
  "path": "xyz789",
  "mode": PosixFileMode,
  "isDirectory": true,
  "isSymlink": false,
  "symlinkTarget": "abc123",
  "isHardLink": true,
  "hardLinkCount": 123,
  "inode": "-8589934592",
  "deviceId": "-8589934592",
  "ownerUid": 987,
  "ownerGid": 123,
  "owner": EndpointUser,
  "group": EndpointGroup,
  "size": "-8589934592",
  "modifiedAt": "2021-10-07T18:23:25.829Z",
  "checksum": "xyz789",
  "hasContents": true,
  "deleted": true,
  "deletedAt": "2021-10-07T18:23:25.829Z",
  "renamedTo": "xyz789",
  "executedAt": "2021-10-07T18:23:25.829Z",
  "contentTruncated": true,
  "collectedAt": "2021-10-07T18:23:25.829Z",
  "osSpecific": EndpointPathWindows,
  "creationTime": "2021-10-07T18:23:25.829Z",
  "lastWriteTime": "2021-10-07T18:23:25.829Z",
  "lastAccessTime": "2021-10-07T18:23:25.829Z",
  "lastChangeTime": "2021-10-07T18:23:25.829Z",
  "lastStatusChangeTime": "2021-10-07T18:23:25.829Z"
}

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
