The single graph object a PathSensor produces on an Endpoint, so an Endpoint has one EndpointPath per sensor that has reported data from it; list them with the Endpoint's paths field. Path sensors run on Windows, macOS, and Linux endpoints. Its path is the sensor's configured absolute path. The files the sensor discovered are not graph objects: each file's stat record and collected bytes are stored as this object's alternate data, listed through entries and fetched through entry. A file's stat record (EndpointPathEntryStats) carries its size, timestamps, owner, mode, and checksum, with platform-specific detail such as ACLs and extended attributes in EndpointPathWindows, EndpointPathMacOS, or EndpointPathLinux.
Fields
| Field Name | Description |
|---|---|
id - ID!
|
The EndpointPath's unique identifier on the security graph. |
orgId - OrganizationId!
|
Unique identifier that corresponds to your deployment of this product or a specific customer account that this EndpointPath belongs to. |
objectType - GraphObjectType!
|
The type of this graph object. |
objectTypeLabel - String!
|
A localized label describing the object type. |
displayName - String!
|
A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object. |
firstSeen - Time!
|
Time this object was first seen. |
lastSeen - Time!
|
Time this object was last seen. |
seen - SeenOnline!
|
Describes when this EndpointPath was seen. |
createdAt - Time!
|
The time this object was created in the security graph. |
updatedAt - Time!
|
The time this object was last mutated in the security graph. |
snapshotInfo - GraphObjectSnapshotInfo!
|
Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed. |
endpoint - Endpoint
|
The Endpoint this EndpointPath was observed on if available. |
pathSensor - PathSensor
|
The PathSensor configuration that produced this result if still available. |
path - String!
|
The sensor's configured absolute path — the root the sensor scans, not an individual discovered file. Discovered file paths are listed by entries. |
entriesUpdatedAt - Time
|
The last time this sensor's collected entries changed — stamped when a file report (a new or changed stat record, streamed contents, or a deletion) finishes committing. Null until the first report completes. |
entries - EndpointPathEntriesPayload!
|
The paths this sensor has discovered on the endpoint, in ascending path order, without reading any file data. Each entry only names one discovered file; retrieve its stat record with the separate endpointPathEntryStats query (a deleted file stays listed — its stat record's deleted is true) and its collected bytes with endpointPathEntryContents. |
entry - EndpointPathEntry
|
The discovered entry for one exact file path, or null when the sensor has never reported that path. A cheap existence probe — no file data is read; see endpointPathEntryStats and endpointPathEntryContents for the file's stat record and bytes. |
|
Arguments
The absolute file path exactly as reported by the endpoint. |
|
findings - FindingsPayload!
|
Policy findings for this object. |
issues - IssuesPayload!
|
Policy issues for this object. |
issuesSummary - IssuesSummary!
|
Summary of the active policy issues currently open on this object, broken down by severity. |
Returned by
endpointPathquery: Retrieves an EndpointPath by its graph object id: the files a configured PathSensor found under its path on one endpoint, with each file's stat…
Used by
Endpointtype: A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.EndpointPathConnectiontype: Collection payload for EndpointPath edges with total count.EndpointPathEdgetype: Edge payload for an EndpointPath with optional seen data.EndpointPathEntrySearchMatchtype: One path search match: a discovered file entry together with the EndpointPath whose sensor collected it.EndpointPathPayloadtype: Payload wrapper for a single EndpointPath.GraphObjectTypeenum: An enumeration of the different types of security graph objects.GraphObjectTypeCategoryenum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.RuleTypeenum: Describes how a rule gathers the input its function evaluates.
Related types
EndpointA Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.PathSensorAn organization-wide instruction telling endpoints to collect file metadata under one filesystem path.
Example
Example
{
"id": "4",
"orgId": "615f3b3b28284380e28a7342",
"objectType": "ACCOUNT_POLICY",
"objectTypeLabel": "xyz789",
"displayName": "abc123",
"firstSeen": "2021-10-07T18:23:25.829Z",
"lastSeen": "2021-10-07T18:23:25.829Z",
"seen": SeenOnline,
"createdAt": "2021-10-07T18:23:25.829Z",
"updatedAt": "2021-10-07T18:23:25.829Z",
"snapshotInfo": GraphObjectSnapshotInfo,
"endpoint": Endpoint,
"pathSensor": PathSensor,
"path": "abc123",
"entriesUpdatedAt": "2021-10-07T18:23:25.829Z",
"entries": EndpointPathEntriesPayload,
"entry": EndpointPathEntry,
"findings": FindingsPayload,
"issues": IssuesPayload,
"issuesSummary": IssuesSummary
}