macOS-specific logon session information, read from the utmpx database.
Fields
| Field Name | Description |
|---|---|
tty - String!
|
The terminal device the session is attached to, such as console or ttys000. |
pid - Int!
|
The process identifier (PID) of the logon session. |
utmpType - PosixLogonType!
|
The value of utmp type (ut_type) field. |
remoteHost - String
|
The remote host connected to the terminal if available. |
Used by
LogonSessiontype: A user logon session observed on an Endpoint, identified by the username and the time the session started.LogonSessionOsSpecificunion: OS-specific logon session union type.
Example
Example
{
"tty": "abc123",
"pid": 987,
"utmpType": "EMPTY",
"remoteHost": "xyz789"
}