Networks, devices, and sensors · GraphQL type

Interface type

A network interface (physical, virtual, loopback, or tunnel) on an Endpoint, collected from Windows, macOS, and Linux endpoints as part of the periodic network inventory. It records the interface's identity and type, administrative and operational status, MAC address, configured IP prefixes, and traffic and error counters. Each interface links to the Network objects it is connected to and the NetworkPrefix objects configured on it; a wireless interface also has a WlanInterface carrying its Wi-Fi state.

Fields

Field Name Description
id - ID! The Interface's unique identifier on the security graph.
orgId - OrganizationId! Unique identifier that corresponds to your deployment of this product or a specific customer account that this Endpoint belongs to.
seen - SeenOnline! Describes when this Interface was seen.
objectType - GraphObjectType! The type of this graph object.
objectTypeLabel - String! A localized label describing the object type.
displayName - String! A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object.
firstSeen - Time! Time this object was first seen.
lastSeen - Time! Time this object was last seen.
createdAt - Time! The time this object was created in the security graph.
updatedAt - Time! The time this object was last mutated in the security graph.
snapshotInfo - GraphObjectSnapshotInfo! Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed.
endpoint - Endpoint The Endpoint this Interface belongs to if available.
interfaceId - String! The unique identifier for a network interface in the context of an Endpoint. On macOS and Linux this is the interface name and on MS Windows is the GUID. See GUID structure (Microsoft) for the Windows GUID format.
index - Int! The index number of the interface on the local system. A positive integer that starts at one, zero is never used.
mtu - Int! The maximum transmission unit (MTU) of the interface in bytes.
name - String! The name or alias of the interface. E.g. "en0" on Apple macOS or "Ethernet" on MS Windows.
description - String! The description of the interface, only available on MS Windows e.g. "Realtek 8812BU Wireless LAN 802.11ac USB NIC".
type - InterfaceType! Enum representation of the network interface type code found in typeSnmpCode.
typeSnmpCode - Int! Network interface type code. This list is derived from the SNMP SMI network management codes, currently documented in RFC1573. The current list of assignments is maintained at: IANA SMI Numbers
adminStatus - InterfaceStatus! Is the interface administratively up or down.
operationalStatus - InterfaceStatus! Is the interface operationally up or down.
isUp - Boolean! True when the interface is fully usable for traffic: adminStatus is UP, operationalStatus is UP, and at least one network is attached.
mediaConnectedState - InterfaceMediaState The state of the physical connection, only available on MS Windows.
isLoopback - Boolean! True if the interface is a loopback type device.
isPointToPoint - Boolean! True if the interface represents a point-to-point network connection.
supportsBroadcast - Boolean! True if the interface supports broadcasts.
supportsMulticast - Boolean! True if the interface supports multicast.
mac - Mac! The hardware address of the interface.
networks - [IpPrefix!] List of IP prefixes configured on the interface, each with its IP network address and associated network ID if known.
ipNetwork - IpNetwork Primary IP network configured on this interface, carrying both the network prefix and its IP address. Selected from networks by preferring, in order: public IPv4, private IPv4, public IPv6, private IPv6, link-local unicast IPv4, link-local unicast IPv6, multicast IPv4, multicast IPv6. Within the highest-priority category that has a match, the numerically lowest network (by IP address) is chosen. Null when this interface has no networks.
lastStateChange - Time Time of the last up/down state change of the interface. Not available on MS Windows.
inPackets - Uint64! The number of packets received without errors through this interface.
outPackets - Uint64! The number of packets transmitted without errors through this interface.
packets - Uint64! The total number of packets transferred through this interface, the sum of inPackets and outPackets.
inBytes - Uint64! The number of octets of data received without errors through this interface. This value includes octets in unicast, broadcast, and multicast packets.
outBytes - Uint64! The number of octets of data transmitted without errors through this interface. This value includes octets in unicast, broadcast, and multicast packets.
bytes - Uint64! The total number of octets of data transferred through this interface, the sum of inBytes and outBytes.
inErrors - Uint64! The number of incoming packets that were discarded because of errors.
outErrors - Uint64! The number of outgoing packets that were discarded because of errors.
errors - Uint64! The total number of packet errors on this interface, the sum of inErrors and outErrors.
inDiscards - Uint64! The number of inbound packets which were chosen to be discarded even though no errors were detected to prevent the packets from being deliverable to a higher-layer protocol.
outDiscards - Uint64! The number of outgoing packets that were discarded even though they did not have errors.
collisions - Uint64 The total number of collisions on this Ethernet segment if available. Not available on MS Windows.
rxRate - Uint64! Receive rate in bits per second.
txRate - Uint64! Transmit rate in bits per second.
connectedNetworks - NetworkConnection! Networks this Interface is connected to.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

seenConnectedNetworks - NetworkConnection! Networks this Interface has been seen connected to. When timeRange is null the last 30 days will be returned. When timeRange is specified all entries seen in the time range are returned.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

timeRange - DateTimeRangeInput

Optional time range filter.

includeSeen - Boolean

When true, the payload will include information about when the edge was seen in the relationship. The data set will be limited to the time range specified in the timeRange field. If includeSeen is true and timeRange is null then seen data for the default 7 day time range will be returned.

networkPrefixes - NetworkPrefixConnection! NetworkPrefixes configured on this Interface.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

seenNetworkPrefixes - NetworkPrefixConnection! NetworkPrefixes seen as configured on this Interface. When timeRange is null the last 30 days will be returned. When timeRange is specified all entries seen in the time range are returned.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

timeRange - DateTimeRangeInput

Optional time range filter.

includeSeen - Boolean

When true, the payload will include information about when the edge was seen in the relationship. The data set will be limited to the time range specified in the timeRange field. If includeSeen is true and timeRange is null then seen data for the default 7 day time range will be returned.

wlanInterfaces - WlanInterfaceList! Wireless LAN interfaces that map to this network interface.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

findings - FindingsPayload! Policy findings for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issues - IssuesPayload! Policy issues for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issuesSummary - IssuesSummary! Summary of the active policy issues currently open on this object, broken down by severity.

Returned by

  • interface query: Retrieves an Interface by its graph object id: a network interface on a Windows, macOS, or Linux endpoint, with its status, IP addresses, and…

Used by

  • Endpoint type: A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
  • WlanInterface type: A wireless LAN (Wi-Fi) adapter on an Endpoint, collected from Windows, macOS, and Linux endpoints by the periodic Wi-Fi inventory.
  • GraphObjectType enum: An enumeration of the different types of security graph objects.
  • GraphObjectTypeCategory enum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.
  • InterfaceConnection type: Collection payload for Interface edges with total count.
  • InterfaceEdge type: Edge payload for an Interface with optional seen data.
  • InterfacePayload type: Payload wrapper for a single Interface result.
  • RuleApplyToOptionKey enum: Attribute keys that further scope which objects a rule applies to, in addition to its applyTo object type.

Related types

  • Endpoint A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.

Example

Example

{
  "id": 4,
  "orgId": "615f3b3b28284380e28a7342",
  "seen": SeenOnline,
  "objectType": "ACCOUNT_POLICY",
  "objectTypeLabel": "xyz789",
  "displayName": "abc123",
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z",
  "createdAt": "2021-10-07T18:23:25.829Z",
  "updatedAt": "2021-10-07T18:23:25.829Z",
  "snapshotInfo": GraphObjectSnapshotInfo,
  "endpoint": Endpoint,
  "interfaceId": "abc123",
  "index": 987,
  "mtu": 987,
  "name": "xyz789",
  "description": "abc123",
  "type": "OTHER",
  "typeSnmpCode": 987,
  "adminStatus": "UP",
  "operationalStatus": "UP",
  "isUp": false,
  "mediaConnectedState": "CONNECTED",
  "isLoopback": true,
  "isPointToPoint": false,
  "supportsBroadcast": true,
  "supportsMulticast": false,
  "mac": "f0:18:98:14:8e:80",
  "networks": [IpPrefix],
  "ipNetwork": IpNetwork,
  "lastStateChange": "2021-10-07T18:23:25.829Z",
  "inPackets": "8589934592",
  "outPackets": "8589934592",
  "packets": "8589934592",
  "inBytes": "8589934592",
  "outBytes": "8589934592",
  "bytes": "8589934592",
  "inErrors": "8589934592",
  "outErrors": "8589934592",
  "errors": "8589934592",
  "inDiscards": "8589934592",
  "outDiscards": "8589934592",
  "collisions": "8589934592",
  "rxRate": "8589934592",
  "txRate": "8589934592",
  "connectedNetworks": NetworkConnection,
  "seenConnectedNetworks": NetworkConnection,
  "networkPrefixes": NetworkPrefixConnection,
  "seenNetworkPrefixes": NetworkPrefixConnection,
  "wlanInterfaces": WlanInterfaceList,
  "findings": FindingsPayload,
  "issues": IssuesPayload,
  "issuesSummary": IssuesSummary
}