File path sensors · GraphQL type

EndpointPath type

The single graph object a PathSensor produces on an Endpoint, so an Endpoint has one EndpointPath per sensor that has reported data from it; list them with the Endpoint's paths field. Path sensors run on Windows, macOS, and Linux endpoints. Its path is the sensor's configured absolute path. The files the sensor discovered are not graph objects: each file's stat record and collected bytes are stored as this object's alternate data, listed through entries and fetched through entry. A file's stat record (EndpointPathEntryStats) carries its size, timestamps, owner, mode, and checksum, with platform-specific detail such as ACLs and extended attributes in EndpointPathWindows, EndpointPathMacOS, or EndpointPathLinux.

Fields

Field Name Description
id - ID! The EndpointPath's unique identifier on the security graph.
orgId - OrganizationId! Unique identifier that corresponds to your deployment of this product or a specific customer account that this EndpointPath belongs to.
objectType - GraphObjectType! The type of this graph object.
objectTypeLabel - String! A localized label describing the object type.
displayName - String! A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object.
firstSeen - Time! Time this object was first seen.
lastSeen - Time! Time this object was last seen.
seen - SeenOnline! Describes when this EndpointPath was seen.
createdAt - Time! The time this object was created in the security graph.
updatedAt - Time! The time this object was last mutated in the security graph.
snapshotInfo - GraphObjectSnapshotInfo! Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed.
endpoint - Endpoint The Endpoint this EndpointPath was observed on if available.
pathSensor - PathSensor The PathSensor configuration that produced this result if still available.
path - String! The sensor's configured absolute path — the root the sensor scans, not an individual discovered file. Discovered file paths are listed by entries.
entriesUpdatedAt - Time The last time this sensor's collected entries changed — stamped when a file report (a new or changed stat record, streamed contents, or a deletion) finishes committing. Null until the first report completes.
entries - EndpointPathEntriesPayload! The paths this sensor has discovered on the endpoint, in ascending path order, without reading any file data. Each entry only names one discovered file; retrieve its stat record with the separate endpointPathEntryStats query (a deleted file stays listed — its stat record's deleted is true) and its collected bytes with endpointPathEntryContents.

Arguments

limit - Int

Maximum number of entries to return.

skip - Int

Number of entries to skip.

entry - EndpointPathEntry The discovered entry for one exact file path, or null when the sensor has never reported that path. A cheap existence probe — no file data is read; see endpointPathEntryStats and endpointPathEntryContents for the file's stat record and bytes.

Arguments

path - String!

The absolute file path exactly as reported by the endpoint.

findings - FindingsPayload! Policy findings for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issues - IssuesPayload! Policy issues for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issuesSummary - IssuesSummary! Summary of the active policy issues currently open on this object, broken down by severity.

Returned by

  • endpointPath query: Retrieves an EndpointPath by its graph object id: the files a configured PathSensor found under its path on one endpoint, with each file's stat…

Used by

  • Endpoint type: A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
  • EndpointPathConnection type: Collection payload for EndpointPath edges with total count.
  • EndpointPathEdge type: Edge payload for an EndpointPath with optional seen data.
  • EndpointPathEntrySearchMatch type: One path search match: a discovered file entry together with the EndpointPath whose sensor collected it.
  • EndpointPathPayload type: Payload wrapper for a single EndpointPath.
  • GraphObjectType enum: An enumeration of the different types of security graph objects.
  • GraphObjectTypeCategory enum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.
  • RuleType enum: Describes how a rule gathers the input its function evaluates.

Related types

  • Endpoint A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
  • PathSensor An organization-wide instruction telling endpoints to collect file metadata under one filesystem path.

Example

Example

{
  "id": "4",
  "orgId": "615f3b3b28284380e28a7342",
  "objectType": "ACCOUNT_POLICY",
  "objectTypeLabel": "xyz789",
  "displayName": "abc123",
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z",
  "seen": SeenOnline,
  "createdAt": "2021-10-07T18:23:25.829Z",
  "updatedAt": "2021-10-07T18:23:25.829Z",
  "snapshotInfo": GraphObjectSnapshotInfo,
  "endpoint": Endpoint,
  "pathSensor": PathSensor,
  "path": "abc123",
  "entriesUpdatedAt": "2021-10-07T18:23:25.829Z",
  "entries": EndpointPathEntriesPayload,
  "entry": EndpointPathEntry,
  "findings": FindingsPayload,
  "issues": IssuesPayload,
  "issuesSummary": IssuesSummary
}