---
title: LogonSession type | Wartiva GraphQL API
description: A user logon session observed on an Endpoint, identified by the username and the time the session started. Wartiva GraphQL API reference with examples.
url: https://wartiva.com/api-docs/types/logon-session.html
updated: 2026-10-07
---

Endpoint configuration · GraphQL type

# `LogonSession` type

A user logon session observed on an [Endpoint](https://wartiva.com/api-docs/types/endpoint.html), identified by the username and the time the session started. The agent enumerates sessions through LsaEnumerateLogonSessions on Windows, the utmpx database and systemd-logind on Linux, and the utmpx database on macOS. Platform-specific detail is in `osSpecific` ([LogonSessionWindows](https://wartiva.com/api-docs/types/logon-session-windows.html), [LogonSessionMacOS](https://wartiva.com/api-docs/types/logon-session-mac-os.html), or [LogonSessionLinux](https://wartiva.com/api-docs/types/logon-session-linux.html)), such as the Windows logon type and authentication package or the terminal and remote host. The session links to the [EndpointUser](https://wartiva.com/api-docs/types/endpoint-user.html) it authenticated through `user`; the Endpoint's `logonSessions` field lists sessions over a time range and `lastLogonSession` returns the most recent one.

## Fields

| Field Name | Description |
|---|---|
| `id` - [`ID!`](https://wartiva.com/api-docs/types/id.html) | The LogonSession's unique identifier on the security graph. |
| `orgId` - [`OrganizationId!`](https://wartiva.com/api-docs/types/organization-id.html) | Unique identifier that corresponds to your deployment of this product or a specific customer account that this Endpoint belongs to. |
| `seen` - [`SeenOnline!`](https://wartiva.com/api-docs/types/seen-online.html) | Describes when this LogonSession was seen. |
| `objectType` - [`GraphObjectType!`](https://wartiva.com/api-docs/types/graph-object-type.html) | The type of this graph object. |
| `objectTypeLabel` - [`String!`](https://wartiva.com/api-docs/types/string.html) | A localized label describing the object type. |
| `displayName` - [`String!`](https://wartiva.com/api-docs/types/string.html) | A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object. |
| `firstSeen` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | Time this object was first seen. |
| `lastSeen` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | Time this object was last seen. |
| `createdAt` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | The time this object was created in the security graph. |
| `updatedAt` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | The time this object was last mutated in the security graph. |
| `snapshotInfo` - [`GraphObjectSnapshotInfo!`](https://wartiva.com/api-docs/types/graph-object-snapshot-info.html) | Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed. |
| `endpoint` - [`Endpoint`](https://wartiva.com/api-docs/types/endpoint.html) | The Endpoint this LogonSession was logged on to if available. |
| `username` - [`String!`](https://wartiva.com/api-docs/types/string.html) | The user name or fully qualified Domain\Username on Windows that was used to logon. |
| `uid` - [`Int`](https://wartiva.com/api-docs/types/int.html) | The local operating system user identifier (UID) of the user. |
| `logonTime` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | Time the logon session was started. |
| `osSpecific` - [`LogonSessionOsSpecific`](https://wartiva.com/api-docs/types/logon-session-os-specific.html) | Operating-system-specific attributes of this logon session: a [LogonSessionWindows](https://wartiva.com/api-docs/types/logon-session-windows.html), [LogonSessionMacOS](https://wartiva.com/api-docs/types/logon-session-mac-os.html), or [LogonSessionLinux](https://wartiva.com/api-docs/types/logon-session-linux.html) depending on the Endpoint's platform. |
| `user` - [`EndpointUser`](https://wartiva.com/api-docs/types/endpoint-user.html) | The EndpointUser authenticated by this LogonSession if available. |
| `findings` - [`FindingsPayload!`](https://wartiva.com/api-docs/types/findings-payload.html) | Policy findings for this object. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. |
| `issues` - [`IssuesPayload!`](https://wartiva.com/api-docs/types/issues-payload.html) | Policy issues for this object. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. |
| `issuesSummary` - [`IssuesSummary!`](https://wartiva.com/api-docs/types/issues-summary.html) | Summary of the active policy issues currently open on this object, broken down by severity. |

## Returned by

- [`logonSession`](https://wartiva.com/api-docs/queries/logon-session.html) query: Retrieves a LogonSession by its graph object id: a user logon session on an endpoint, with platform-specific detail such as the Windows logon type…

## Used by

- [`Endpoint`](https://wartiva.com/api-docs/types/endpoint.html) type: A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
- [`EndpointUser`](https://wartiva.com/api-docs/types/endpoint-user.html) type: An operating system or domain user account observed on an Endpoint.
- [`GraphObjectType`](https://wartiva.com/api-docs/types/graph-object-type.html) enum: An enumeration of the different types of security graph objects.
- [`GraphObjectTypeCategory`](https://wartiva.com/api-docs/types/graph-object-type-category.html) enum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.
- [`LogonSessionConnection`](https://wartiva.com/api-docs/types/logon-session-connection.html) type: Collection payload for LogonSession edges with total count.
- [`LogonSessionEdge`](https://wartiva.com/api-docs/types/logon-session-edge.html) type: Edge payload for a LogonSession with optional seen data.
- [`LogonSessionPayload`](https://wartiva.com/api-docs/types/logon-session-payload.html) type: Payload wrapper for a single LogonSession result.

## Related types

- [`Endpoint`](https://wartiva.com/api-docs/types/endpoint.html) A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
- [`EndpointUser`](https://wartiva.com/api-docs/types/endpoint-user.html) An operating system or domain user account observed on an Endpoint.

## Example

### Example

```json
{
  "id": "4",
  "orgId": "615f3b3b28284380e28a7342",
  "seen": SeenOnline,
  "objectType": "ACCOUNT_POLICY",
  "objectTypeLabel": "xyz789",
  "displayName": "abc123",
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z",
  "createdAt": "2021-10-07T18:23:25.829Z",
  "updatedAt": "2021-10-07T18:23:25.829Z",
  "snapshotInfo": GraphObjectSnapshotInfo,
  "endpoint": Endpoint,
  "username": "abc123",
  "uid": 987,
  "logonTime": "2021-10-07T18:23:25.829Z",
  "osSpecific": LogonSessionWindows,
  "user": EndpointUser,
  "findings": FindingsPayload,
  "issues": IssuesPayload,
  "issuesSummary": IssuesSummary
}

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
