A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization. The Endpoint is the root of everything the agent collects from that computer: operating system and hardware details (OsInfo, SystemInfo), installed software (ApplicationInstall), user accounts and groups (EndpointUser, EndpointGroup), storage (Disk, DiskMount), running programs (Executable), logons (LogonSession), and security configuration such as AccountPolicy and Security. The collected graph objects link back to this Endpoint through their own endpoint field.
Fields
| Field Name | Description |
|---|---|
id - ID!
|
The Endpoint's unique identifier on the security graph. |
orgId - OrganizationId!
|
Unique identifier that corresponds to your deployment of this product or a specific customer account that this Endpoint belongs to. |
seen - SeenOnline!
|
Describes when this Endpoint was seen online. |
objectType - GraphObjectType!
|
The type of this graph object. |
objectTypeLabel - String!
|
A localized label describing the object type. |
displayName - String!
|
A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object. |
firstSeen - Time!
|
Time this object was first seen. |
lastSeen - Time!
|
Time this object was last seen. |
createdAt - Time!
|
The time this object was created in the security graph. |
updatedAt - Time!
|
The time this object was last mutated in the security graph. |
snapshotInfo - GraphObjectSnapshotInfo!
|
Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed. |
enrollment - EndpointEnrollment!
|
Information about the status of the Endpoint's enrollment with the service. |
issuesSummary - IssuesSummary!
|
Summary of the active policy issues currently open on this Endpoint, broken down by severity. |
lastClientIp - IpAddress
|
Last public IP address used by Endpoint when connecting to the service. |
lastHeartBeat - Time
|
Last time Endpoint was seen by the service. |
lastConnectedAt - Time
|
Last time the Endpoint connected to the service. |
online - OnlineStatus!
|
True if the Endpoint is currently connected to the service.graph types |
osInfo - OsInfo
|
Basic information about the Endpoint's operating system. |
permissions - EndpointPermissions
|
Operating-system permissions granted to the endpoint agent. |
systemInfo - SystemInfo
|
Basic system identification information for this Endpoint. |
tray - EndpointTray
|
System-tray companion app status for this Endpoint. Null when the tray was never seen connected or the platform has no tray app. |
version - EndpointVersion
|
Version information about this product installed. |
accountPolicy - AccountPolicy
|
Returns the Endpoint AccountPolicy if available. |
activeDirectory - ActiveDirectory
|
Returns the Endpoint ActiveDirectory if available. |
administrativeTemplatesWindows - AdministrativeTemplatesWindows
|
Returns the Endpoint AdministrativeTemplatesWindows if available. |
applicationInstalls - ApplicationInstallConnection!
|
Applications installed on this Endpoint. |
applicationInstallsSeenOn - ApplicationInstallConnection!
|
Historical sightings of ApplicationInstall on this Endpoint. Each edge records when an install was observed; pass timeRange to constrain the window. When timeRange is null the last 30 days will be returned. |
|
Arguments
Maximum number of results to return.
Number of results to skip.
Restrict edges to a date/time range.
Include the per-edge seen series in the response. |
|
arpTableEntries - ArpTableEntryConnection!
|
Layer-2 Address Resolution Protocol (ARP) table entries seen on this Endpoint. |
arpTableEntriesSeen - ArpTableEntryConnection!
|
Historical sightings of ArpTableEntry on this Endpoint. Each edge records when the entry was observed; pass timeRange to constrain the window. When timeRange is null the last 30 days will be returned. |
|
Arguments
Maximum number of results to return.
Number of results to skip.
Restrict edges to a date/time range.
Include the per-edge seen series in the response. |
|
auditPolicy - AuditPolicy
|
Returns the Endpoint AuditPolicy if available. |
devicesSeen - DeviceConnection!
|
Device objects this Endpoint has had verifiable connectivity to. When timeRange is null the last 30 days will be returned. When timeRange is specified all entries seen in the time range are returned. |
|
Arguments
Maximum number of results to return.
Number of results to skip.
Optional time range filter.
When true, the payload will include information about when the edge was seen in the relationship. The data set will be limited to the time range specified in the timeRange field. If includeSeen is true and timeRange is null then seen data for the default 7 day time range will be returned. |
|
diskMounts - DiskMountConnection!
|
Disk mount points on this Endpoint. |
diskMountsSeen - DiskMountConnection!
|
Historical sightings of DiskMount configured on this Endpoint. Each edge records when the mount was observed; pass timeRange to constrain the window. When timeRange is null the last 30 days will be returned. |
|
Arguments
Maximum number of results to return.
Number of results to skip.
Restrict edges to a date/time range.
Include the per-edge seen series in the response. |
|
disks - DiskConnection!
|
Hard disks and other storage devices on this Endpoint. |
disksSeen - DiskConnection!
|
Historical sightings of Disk attached to this Endpoint. Each edge records when the disk was observed; pass timeRange to constrain the window. When timeRange is null the last 30 days will be returned. |
|
Arguments
Maximum number of results to return.
Number of results to skip.
Restrict edges to a date/time range.
Include the per-edge seen series in the response. |
|
executables - ExecutableConnection!
|
Executable files observed running on this Endpoint. |
executablesSeen - ExecutableConnection!
|
Historical sightings of Executable on this Endpoint. Each edge records when the executable was observed; pass timeRange to constrain the window. When timeRange is null the last 30 days will be returned. |
|
Arguments
Maximum number of results to return.
Number of results to skip.
Restrict edges to a date/time range.
Include the per-edge seen series in the response. |
|
groups - EndpointGroupConnection!
|
Groups found on this Endpoint. |
groupsSeen - EndpointGroupConnection!
|
Historical sightings of EndpointGroup configured on this Endpoint. Each edge records when the group was observed; pass timeRange to constrain the window. When timeRange is null the last 30 days will be returned. |
|
Arguments
Maximum number of results to return.
Number of results to skip.
Restrict edges to a date/time range.
Include the per-edge seen series in the response. |
|
interfaces - InterfaceConnection!
|
Network interfaces on this Endpoint. |
interfacesSeen - InterfaceConnection!
|
Historical sightings of Interface on this Endpoint. Each edge records when the interface was observed; pass timeRange to constrain the window. When timeRange is null the last 30 days will be returned. |
|
Arguments
Maximum number of results to return.
Number of results to skip.
Restrict edges to a date/time range.
Include the per-edge seen series in the response. |
|
lastPosition - PositionSeen
|
The last position seen for this Endpoint. |
lastLogonSession - LogonSession
|
The most recent user to logon to this Endpoint. |
localPolicies - LocalPolicies
|
Returns the Endpoint LocalPolicies if available. |
logonSessions - LogonSessionConnection!
|
Logon sessions seen on this Endpoint in the specified time range. When timeRange is null the last 30 days of logon sessions will be returned. |
|
Arguments
Maximum number of results to return.
Number of results to skip.
Optional time range filter.
When true, the payload will include information about when the edge was seen in the relationship. The data set will be limited to the time range specified in the timeRange field. If includeSeen is true and timeRange is null then seen data for the default 7 day time range will be returned. |
|
networks - NetworkConnection!
|
Networks seen connected to this Endpoint. When timeRange is null the last 30 days will be returned. When timeRange is specified all entries seen in the time range are returned. |
|
Arguments
Maximum number of results to return.
Number of results to skip.
Optional time range filter.
When true, the payload will include information about when the edge was seen in the relationship. The data set will be limited to the time range specified in the timeRange field. If includeSeen is true and timeRange is null then seen data for the default 7 day time range will be returned. |
|
paths - EndpointPathConnection!
|
The EndpointPath objects on this Endpoint — one per PathSensor that has reported data here. Each carries its sensor's configured path; the files a sensor discovered are listed by the object's entries field. |
portsSeen - OpenPortConnection!
|
OpenPort objects this Endpoint has seen. When timeRange is null the last 30 days will be returned. When timeRange is specified all entries seen in the time range are returned. |
|
Arguments
Maximum number of results to return.
Number of results to skip.
Optional time range filter.
When true, the payload will include information about when the edge was seen in the relationship. The data set will be limited to the time range specified in the timeRange field. If includeSeen is true and timeRange is null then seen data for the default 7 day time range will be returned. |
|
primaryPosition - PositionSeen
|
The position this endpoint spent the most time at. |
processes - ProcessesPayload!
|
List of running processes last seen on the Endpoint. |
positions - PositionSeenConnection!
|
Positions seen by this Endpoint in the specified time range. When timeRange is null the last 30 days will be returned. |
|
Arguments
Maximum number of results to return.
Number of results to skip.
Optional time range filter.
When true, the payload will include information about when the edge was seen in the relationship. The data set will be limited to the time range specified in the timeRange field. If includeSeen is true and timeRange is null then seen data for the default 7 day time range will be returned. |
|
routes - RouteConnection!
|
Network routes on this Endpoint. |
routesSeen - RouteConnection!
|
Historical sightings of Route on this Endpoint. Each edge records when the route was observed; pass timeRange to constrain the window. When timeRange is null the last 30 days will be returned. |
|
Arguments
Maximum number of results to return.
Number of results to skip.
Restrict edges to a date/time range.
Include the per-edge seen series in the response. |
|
security - Security
|
Returns the Endpoint Security if available. |
softwareUpdatePreferences - SoftwareUpdatePreferences
|
Returns the Endpoint SoftwareUpdatePreferences if available. |
systemServices - SystemServiceConnection!
|
System services found on this Endpoint. |
systemServicesSeen - SystemServiceConnection!
|
Historical sightings of SystemService on this Endpoint. Each edge records when the service was observed; pass timeRange to constrain the window. When timeRange is null the last 30 days will be returned. |
|
Arguments
Maximum number of results to return.
Number of results to skip.
Restrict edges to a date/time range.
Include the per-edge seen series in the response. |
|
systemSettings - SystemSettings
|
Returns the Endpoint SystemSettings if available. |
users - EndpointUserConnection!
|
Users found on this Endpoint. |
usersSeen - EndpointUserConnection!
|
Historical sightings of EndpointUser configured on this Endpoint. Each edge records when the user was observed; pass timeRange to constrain the window. When timeRange is null the last 30 days will be returned. |
|
Arguments
Maximum number of results to return.
Number of results to skip.
Restrict edges to a date/time range.
Include the per-edge seen series in the response. |
|
vulnerabilities - PlatformVulnerabilities
|
CPE identifiers determined for this endpoint's operating system and hardware and the CVEs they match in the vulnerability catalog. Null when the endpoint could not be identified precisely enough to match vulnerabilities accurately. See PlatformVulnerabilities. |
wlanInterfaces - WlanInterfaceList!
|
Wireless LAN interfaces on this Endpoint. |
wlanInterfacesSeen - WlanInterfaceList!
|
Historical sightings of WlanInterface on this Endpoint. Each edge records when the interface was observed; pass timeRange to constrain the window. When timeRange is null the last 30 days will be returned. |
|
Arguments
Maximum number of results to return.
Number of results to skip.
Restrict edges to a date/time range.
Include the per-edge seen series in the response. |
|
findings - FindingsPayload!
|
Policy findings for this object. |
issues - IssuesPayload!
|
Policy issues for this object. |
Returned by
endpointquery: Retrieves an Endpoint by its graph object id: a Windows, macOS, or Linux computer running the Wartiva agent.
Used by
AccountPolicytype: The local account password and lockout policy in effect on an Endpoint.ActiveDirectorytype: The Active Directory (AD) domain membership and directory-binding configuration of an Endpoint.AdministrativeTemplatesWindowstype: The Group Policy Administrative Templates (ADMX) settings applied to a Windows Endpoint, read from the policy registry values those templates write.ApplicationInstalltype: One installed copy of an application on one Endpoint.ArpTableEntrytype: One entry in an Endpoint's neighbor cache: the IPv4 Address Resolution Protocol (ARP) table and, where the operating system reports it, the IPv6…AuditPolicytype: The security event auditing configuration of an Endpoint.Disktype: A physical disk drive attached to an Endpoint, identified on that Endpoint by its operating-system drive ID (for example \\.\PhysicalDrive0 on…DiskMounttype: A file system mounted on an Endpoint, identified by its device and mount point (for example C: on Windows or / on Linux and macOS).EndpointGrouptype: An operating system or domain group observed on an Endpoint.EndpointPathtype: The single graph object a PathSensor produces on an Endpoint, so an Endpoint has one EndpointPath per sensor that has reported data from it; list…EndpointUsertype: An operating system or domain user account observed on an Endpoint.Executabletype: A unique executable file observed running on an Endpoint, aggregating data across all observed processes that share the same file system path.Interfacetype: A network interface (physical, virtual, loopback, or tunnel) on an Endpoint, collected from Windows, macOS, and Linux endpoints as part of the…LocalPoliciestype: The local security policy settings of an Endpoint.LogonSessiontype: A user logon session observed on an Endpoint, identified by the username and the time the session started.PositionSeentype: A geographic coordinate (latitude and longitude) where a managed Endpoint was observed, and the times it was seen there.Routetype: One entry in an Endpoint's IP routing table, collected from Windows, macOS, and Linux endpoints as part of the periodic network inventory.Securitytype: The security posture of an Endpoint: its firewall, anti-malware and disk encryption state, summarized as per-component health ratings in Health.SensorRequestRuntype: The record of one attempt to run a SensorRequest: when it ran, which sensor version ran it, which Endpoint ran it (none for PUBLIC-zone runs, which…SoftwareUpdatePreferencestype: The operating system update configuration of an Endpoint and the updates currently available to it.SystemServicetype: A background service or daemon configured on an Endpoint.SystemSettingstype: The machine-wide operating system configuration of an Endpoint.WlanInterfacetype: A wireless LAN (Wi-Fi) adapter on an Endpoint, collected from Windows, macOS, and Linux endpoints by the periodic Wi-Fi inventory.EndpointConnectiontype: Collection payload for Endpoint edges with total count.EndpointEdgetype: Edge payload for an Endpoint with optional seen data.EndpointPayloadtype: Payload wrapper for a single Endpoint result.GraphObjectTypeenum: An enumeration of the different types of security graph objects.GraphObjectTypeCategoryenum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.ProprietaryCheckIdenum: A check that ships with the platform, run by a PROPRIETARY rule on its Schedule.RuleTypeenum: Describes how a rule gathers the input its function evaluates.SensorRequestStatetype: Contains the current state of the SensorRequest.
Related types
AccountPolicyThe local account password and lockout policy in effect on an Endpoint.ActiveDirectoryThe Active Directory (AD) domain membership and directory-binding configuration of an Endpoint.AdministrativeTemplatesWindowsThe Group Policy Administrative Templates (ADMX) settings applied to a Windows Endpoint, read from the policy registry values those templates write.ApplicationInstallOne installed copy of an application on one Endpoint.ArpTableEntryOne entry in an Endpoint's neighbor cache: the IPv4 Address Resolution Protocol (ARP) table and, where the operating system reports it, the IPv6…AuditPolicyThe security event auditing configuration of an Endpoint.DeviceA physical or virtual device that does not run the Wartiva endpoint application but is visible on the network to a managed Endpoint, such as…DiskA physical disk drive attached to an Endpoint, identified on that Endpoint by its operating-system drive ID (for example \\.\PhysicalDrive0 on…DiskMountA file system mounted on an Endpoint, identified by its device and mount point (for example C: on Windows or / on Linux and macOS).EndpointGroupAn operating system or domain group observed on an Endpoint.EndpointPathThe single graph object a PathSensor produces on an Endpoint, so an Endpoint has one EndpointPath per sensor that has reported data from it; list…EndpointUserAn operating system or domain user account observed on an Endpoint.ExecutableA unique executable file observed running on an Endpoint, aggregating data across all observed processes that share the same file system path.InterfaceA network interface (physical, virtual, loopback, or tunnel) on an Endpoint, collected from Windows, macOS, and Linux endpoints as part of the…LocalPoliciesThe local security policy settings of an Endpoint.LogonSessionA user logon session observed on an Endpoint, identified by the username and the time the session started.OpenPortOne TCP or UDP port at one IP address on a discovered Device, found by managed endpoints port-scanning the devices on their local networks and by…PositionSeenA geographic coordinate (latitude and longitude) where a managed Endpoint was observed, and the times it was seen there.RouteOne entry in an Endpoint's IP routing table, collected from Windows, macOS, and Linux endpoints as part of the periodic network inventory.SecurityThe security posture of an Endpoint: its firewall, anti-malware and disk encryption state, summarized as per-component health ratings in Health.SoftwareUpdatePreferencesThe operating system update configuration of an Endpoint and the updates currently available to it.SystemServiceA background service or daemon configured on an Endpoint.SystemSettingsThe machine-wide operating system configuration of an Endpoint.WlanInterfaceA wireless LAN (Wi-Fi) adapter on an Endpoint, collected from Windows, macOS, and Linux endpoints by the periodic Wi-Fi inventory.
Example
Example
{
"id": 4,
"orgId": "615f3b3b28284380e28a7342",
"seen": SeenOnline,
"objectType": "ACCOUNT_POLICY",
"objectTypeLabel": "xyz789",
"displayName": "xyz789",
"firstSeen": "2021-10-07T18:23:25.829Z",
"lastSeen": "2021-10-07T18:23:25.829Z",
"createdAt": "2021-10-07T18:23:25.829Z",
"updatedAt": "2021-10-07T18:23:25.829Z",
"snapshotInfo": GraphObjectSnapshotInfo,
"enrollment": EndpointEnrollment,
"issuesSummary": IssuesSummary,
"lastClientIp": IpAddress,
"lastHeartBeat": "2021-10-07T18:23:25.829Z",
"lastConnectedAt": "2021-10-07T18:23:25.829Z",
"online": "ONLINE",
"osInfo": OsInfo,
"permissions": EndpointPermissions,
"systemInfo": SystemInfo,
"tray": EndpointTray,
"version": EndpointVersion,
"accountPolicy": AccountPolicy,
"activeDirectory": ActiveDirectory,
"administrativeTemplatesWindows": AdministrativeTemplatesWindows,
"applicationInstalls": ApplicationInstallConnection,
"applicationInstallsSeenOn": ApplicationInstallConnection,
"arpTableEntries": ArpTableEntryConnection,
"arpTableEntriesSeen": ArpTableEntryConnection,
"auditPolicy": AuditPolicy,
"devicesSeen": DeviceConnection,
"diskMounts": DiskMountConnection,
"diskMountsSeen": DiskMountConnection,
"disks": DiskConnection,
"disksSeen": DiskConnection,
"executables": ExecutableConnection,
"executablesSeen": ExecutableConnection,
"groups": EndpointGroupConnection,
"groupsSeen": EndpointGroupConnection,
"interfaces": InterfaceConnection,
"interfacesSeen": InterfaceConnection,
"lastPosition": PositionSeen,
"lastLogonSession": LogonSession,
"localPolicies": LocalPolicies,
"logonSessions": LogonSessionConnection,
"networks": NetworkConnection,
"paths": EndpointPathConnection,
"portsSeen": OpenPortConnection,
"primaryPosition": PositionSeen,
"processes": ProcessesPayload,
"positions": PositionSeenConnection,
"routes": RouteConnection,
"routesSeen": RouteConnection,
"security": Security,
"softwareUpdatePreferences": SoftwareUpdatePreferences,
"systemServices": SystemServiceConnection,
"systemServicesSeen": SystemServiceConnection,
"systemSettings": SystemSettings,
"users": EndpointUserConnection,
"usersSeen": EndpointUserConnection,
"vulnerabilities": PlatformVulnerabilities,
"wlanInterfaces": WlanInterfaceList,
"wlanInterfacesSeen": WlanInterfaceList,
"findings": FindingsPayload,
"issues": IssuesPayload
}