---
title: LogonHostOrigin enum | Wartiva GraphQL API
description: Where a Linux logon session's host places it relative to your networks, classified from the session's recorded host.
url: https://wartiva.com/api-docs/types/logon-host-origin.html
updated: 2026-10-07
---

Endpoint configuration · GraphQL enum

# `LogonHostOrigin` enum

Where a Linux logon session's host places it relative to your networks, classified from the session's recorded host. A remote root logon from a public address or a hostname is a strong sign of an exposed service or stolen credentials.

## Values

| Enum Value | Description |
|---|---|
| `LOCAL` | No remote host, a local X display, or a loopback address. |
| `PRIVATE_ADDRESS` | A private (RFC 1918 or IPv6 unique local) or link-local address. |
| `PUBLIC_ADDRESS` | Any other IP address, including carrier-grade NAT (100.64.0.0/10) and IPv4-mapped public addresses. |
| `HOSTNAME` | A hostname rather than an address, including a bare "localhost". It's never trusted as the address it may resolve to, since reverse DNS is controlled by whoever owns the connecting address. |

## Used by

- [`LogonSessionLinux`](https://wartiva.com/api-docs/types/logon-session-linux.html) type: Linux O/S specific logon session information.

## Example

### Example

```json
"LOCAL"

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
