Graph search · GraphQL interface

GraphObject interface

GraphObject represents a primary entity in the security graph. Each object has a graph of data collected about the object and objects can be associated by relationship on the security graph.

Used by

  • Finding type: The record of a policy Rule evaluating FAIL against one graph object, such as an Endpoint, Device, or network service.
  • Issue type: The triage record for a policy violation: a security concern on one graph object that needs remediation or a decision.
  • FindingStatusChange type: A single status transition in the history of a Finding.
  • GraphObjectSnapshotInfo type: Reports whether a GraphObject is a stored point-in-time copy of an object's state rather than the object's live state.
  • Rule type: A policy rule evaluated against graph objects.

Example

Example

{
  "id": "4",
  "orgId": "615f3b3b28284380e28a7342",
  "objectType": "ACCOUNT_POLICY",
  "objectTypeLabel": "xyz789",
  "displayName": "abc123",
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z",
  "seen": SeenOnline,
  "createdAt": "2021-10-07T18:23:25.829Z",
  "updatedAt": "2021-10-07T18:23:25.829Z",
  "snapshotInfo": GraphObjectSnapshotInfo,
  "findings": FindingsPayload,
  "issues": IssuesPayload,
  "issuesSummary": IssuesSummary
}