Endpoint configuration · GraphQL type

LogonSession type

A user logon session observed on an Endpoint, identified by the username and the time the session started. The agent enumerates sessions through LsaEnumerateLogonSessions on Windows, the utmpx database and systemd-logind on Linux, and the utmpx database on macOS. Platform-specific detail is in osSpecific (LogonSessionWindows, LogonSessionMacOS, or LogonSessionLinux), such as the Windows logon type and authentication package or the terminal and remote host. The session links to the EndpointUser it authenticated through user; the Endpoint's logonSessions field lists sessions over a time range and lastLogonSession returns the most recent one.

Fields

Field Name Description
id - ID! The LogonSession's unique identifier on the security graph.
orgId - OrganizationId! Unique identifier that corresponds to your deployment of this product or a specific customer account that this Endpoint belongs to.
seen - SeenOnline! Describes when this LogonSession was seen.
objectType - GraphObjectType! The type of this graph object.
objectTypeLabel - String! A localized label describing the object type.
displayName - String! A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object.
firstSeen - Time! Time this object was first seen.
lastSeen - Time! Time this object was last seen.
createdAt - Time! The time this object was created in the security graph.
updatedAt - Time! The time this object was last mutated in the security graph.
snapshotInfo - GraphObjectSnapshotInfo! Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed.
endpoint - Endpoint The Endpoint this LogonSession was logged on to if available.
username - String! The user name or fully qualified Domain\Username on Windows that was used to logon.
uid - Int The local operating system user identifier (UID) of the user.
logonTime - Time! Time the logon session was started.
osSpecific - LogonSessionOsSpecific Operating-system-specific attributes of this logon session: a LogonSessionWindows, LogonSessionMacOS, or LogonSessionLinux depending on the Endpoint's platform.
user - EndpointUser The EndpointUser authenticated by this LogonSession if available.
findings - FindingsPayload! Policy findings for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issues - IssuesPayload! Policy issues for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issuesSummary - IssuesSummary! Summary of the active policy issues currently open on this object, broken down by severity.

Returned by

  • logonSession query: Retrieves a LogonSession by its graph object id: a user logon session on an endpoint, with platform-specific detail such as the Windows logon type…

Used by

  • Endpoint type: A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
  • EndpointUser type: An operating system or domain user account observed on an Endpoint.
  • GraphObjectType enum: An enumeration of the different types of security graph objects.
  • GraphObjectTypeCategory enum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.
  • LogonSessionConnection type: Collection payload for LogonSession edges with total count.
  • LogonSessionEdge type: Edge payload for a LogonSession with optional seen data.
  • LogonSessionPayload type: Payload wrapper for a single LogonSession result.

Related types

  • Endpoint A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
  • EndpointUser An operating system or domain user account observed on an Endpoint.

Example

Example

{
  "id": "4",
  "orgId": "615f3b3b28284380e28a7342",
  "seen": SeenOnline,
  "objectType": "ACCOUNT_POLICY",
  "objectTypeLabel": "xyz789",
  "displayName": "abc123",
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z",
  "createdAt": "2021-10-07T18:23:25.829Z",
  "updatedAt": "2021-10-07T18:23:25.829Z",
  "snapshotInfo": GraphObjectSnapshotInfo,
  "endpoint": Endpoint,
  "username": "abc123",
  "uid": 987,
  "logonTime": "2021-10-07T18:23:25.829Z",
  "osSpecific": LogonSessionWindows,
  "user": EndpointUser,
  "findings": FindingsPayload,
  "issues": IssuesPayload,
  "issuesSummary": IssuesSummary
}