Endpoint configuration · GraphQL type

LogonSessionLinux type

Linux O/S specific logon session information.

Fields

Field Name Description
utmpType - PosixLogonType! The value of utmp type (ut_type field).
ttyDeviceName - String! The TTY device name associated with the logon session (ut_line field).
host - String! Hostname for remote login, or kernel version for run-level messages
hostOrigin - LogonHostOrigin! Where the host puts this session relative to your networks: local, a private address, a public address, or a hostname. A hostname counts on its own, never as the address it may resolve to. See LogonHostOrigin.
pid - Int! Process identifier (PID) of the login process.
extended - LogonSessionLinuxExtended Extended Linux specific logon session information found via systemd/login1, available if the session is currently active.

Used by

  • LogonSession type: A user logon session observed on an Endpoint, identified by the username and the time the session started.
  • LogonSessionOsSpecific union: OS-specific logon session union type.

Example

Example

{
  "utmpType": "EMPTY",
  "ttyDeviceName": "xyz789",
  "host": "abc123",
  "hostOrigin": "LOCAL",
  "pid": 123,
  "extended": LogonSessionLinuxExtended
}