---
title: NetworkPrefix type | Wartiva GraphQL API
description: A specific IP address together with its subnet prefix length (e.g. 192.168.1.23/24) on one Network. Wartiva GraphQL API reference with examples.
url: https://wartiva.com/api-docs/types/network-prefix.html
updated: 2026-10-07
---

Networks, devices, and sensors · GraphQL type

# `NetworkPrefix` type

A specific IP address together with its subnet prefix length (e.g. 192.168.1.23/24) on one [Network](https://wartiva.com/api-docs/types/network.html). Prefixes are recorded from the addresses configured on endpoint [Interface](https://wartiva.com/api-docs/types/interface.html) objects and link to the [ArpTableEntry](https://wartiva.com/api-docs/types/arp-table-entry.html), [Device](https://wartiva.com/api-docs/types/device.html), [OpenPort](https://wartiva.com/api-docs/types/open-port.html), and [Service](https://wartiva.com/api-docs/types/service.html) objects that use the address. Because a prefix is scoped to its Network, the same address on two different networks is two distinct prefixes, so each observation traces to the exact network and host address where it was made.

## Fields

| Field Name | Description |
|---|---|
| `id` - [`ID!`](https://wartiva.com/api-docs/types/id.html) | The NetworkPrefix's unique identifier on the security graph. |
| `orgId` - [`OrganizationId!`](https://wartiva.com/api-docs/types/organization-id.html) | Unique identifier that corresponds to your deployment of this product or a specific customer account. |
| `seen` - [`SeenOnline!`](https://wartiva.com/api-docs/types/seen-online.html) | Describes when this NetworkPrefix was seen online. |
| `objectType` - [`GraphObjectType!`](https://wartiva.com/api-docs/types/graph-object-type.html) | The type of this graph object. |
| `objectTypeLabel` - [`String!`](https://wartiva.com/api-docs/types/string.html) | A localized label describing the object type. |
| `displayName` - [`String!`](https://wartiva.com/api-docs/types/string.html) | A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object. |
| `firstSeen` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | Time this object was first seen. |
| `lastSeen` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | Time this object was last seen. |
| `createdAt` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | The time this object was created in the security graph. |
| `updatedAt` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | The time this object was last mutated in the security graph. |
| `snapshotInfo` - [`GraphObjectSnapshotInfo!`](https://wartiva.com/api-docs/types/graph-object-snapshot-info.html) | Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed. |
| `prefix` - [`IpNetwork!`](https://wartiva.com/api-docs/types/ip-network.html) | The IP network address and prefix length in CIDR notation. |
| `isNetworkAddress` - [`Boolean!`](https://wartiva.com/api-docs/types/boolean.html) | Whether this prefix is the network address (all host bits are zero). |
| `isHostAddress` - [`Boolean!`](https://wartiva.com/api-docs/types/boolean.html) | Whether the address has host bits set, identifying a specific host within its subnet (e.g. 192.168.1.5/24) rather than the subnet itself. |
| `network` - [`Network`](https://wartiva.com/api-docs/types/network.html) | The Network this NetworkPrefix is found on. |
| `arpTableEntries` - [`ArpTableEntryConnection!`](https://wartiva.com/api-docs/types/arp-table-entry-connection.html) | ARP table entries that map to this NetworkPrefix. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. |
| `interfaces` - [`InterfaceConnection!`](https://wartiva.com/api-docs/types/interface-connection.html) | Interfaces this NetworkPrefix is configured on. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. |
| `ports` - [`OpenPortConnection!`](https://wartiva.com/api-docs/types/open-port-connection.html) | [OpenPorts](https://wartiva.com/api-docs/types/open-port.html) found on IPs within this NetworkPrefix. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. |
| `seenOnDevices` - [`DeviceConnection!`](https://wartiva.com/api-docs/types/device-connection.html) | [Devices](https://wartiva.com/api-docs/types/device.html) this NetworkPrefix has been seen as configured on. When timeRange is null the last 30 days will be returned. When timeRange is specified all entries seen in the time range are returned. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. `timeRange` - [`DateTimeRangeInput`](https://wartiva.com/api-docs/types/date-time-range-input.html) Optional time range filter. `includeSeen` - [`Boolean`](https://wartiva.com/api-docs/types/boolean.html) When true, the payload will include information about when the edge was seen in the relationship. The data set will be limited to the time range specified in the timeRange field. If includeSeen is true and timeRange is null then seen data for the default 7 day time range will be returned. |
| `seenOnInterfaces` - [`InterfaceConnection!`](https://wartiva.com/api-docs/types/interface-connection.html) | Interfaces this NetworkPrefix has been seen as configured on. When timeRange is null the last 30 days will be returned. When timeRange is specified all entries seen in the time range are returned. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. `timeRange` - [`DateTimeRangeInput`](https://wartiva.com/api-docs/types/date-time-range-input.html) Optional time range filter. `includeSeen` - [`Boolean`](https://wartiva.com/api-docs/types/boolean.html) When true, the payload will include information about when the edge was seen in the relationship. The data set will be limited to the time range specified in the timeRange field. If includeSeen is true and timeRange is null then seen data for the default 7 day time range will be returned. |
| `services` - [`ServiceConnection!`](https://wartiva.com/api-docs/types/service-connection.html) | [Services](https://wartiva.com/api-docs/types/service.html) found on IPs within this NetworkPrefix. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. |
| `findings` - [`FindingsPayload!`](https://wartiva.com/api-docs/types/findings-payload.html) | Policy findings for this object. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. |
| `issues` - [`IssuesPayload!`](https://wartiva.com/api-docs/types/issues-payload.html) | Policy issues for this object. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. |
| `issuesSummary` - [`IssuesSummary!`](https://wartiva.com/api-docs/types/issues-summary.html) | Summary of the active policy issues currently open on this object, broken down by severity. |

## Returned by

- [`networkPrefix`](https://wartiva.com/api-docs/queries/network-prefix.html) query: Retrieves a NetworkPrefix by its graph object id: a host IP address with its subnet length, such as 192.168.1.23/24, on a specific Network.

## Used by

- [`ArpTableEntry`](https://wartiva.com/api-docs/types/arp-table-entry.html) type: One entry in an Endpoint's neighbor cache: the IPv4 Address Resolution Protocol (ARP) table and, where the operating system reports it, the IPv6…
- [`Device`](https://wartiva.com/api-docs/types/device.html) type: A physical or virtual device that does not run the Wartiva endpoint application but is visible on the network to a managed Endpoint, such as…
- [`OpenPort`](https://wartiva.com/api-docs/types/open-port.html) type: One TCP or UDP port at one IP address on a discovered Device, found by managed endpoints port-scanning the devices on their local networks and by…
- [`Service`](https://wartiva.com/api-docs/types/service.html) type: A network service identified on a discovered Device: one protocol (such as HTTP, TLS, SSH, SMB, DNS, SNMP, IPP, mDNS, or UPnP) acting as a client or…
- [`DeviceIpNetwork`](https://wartiva.com/api-docs/types/device-ip-network.html) type: An IP prefix containing an IP address and CIDR mask that a Device was seen using.
- [`GraphObjectType`](https://wartiva.com/api-docs/types/graph-object-type.html) enum: An enumeration of the different types of security graph objects.
- [`GraphObjectTypeCategory`](https://wartiva.com/api-docs/types/graph-object-type-category.html) enum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.
- [`NetworkPrefixConnection`](https://wartiva.com/api-docs/types/network-prefix-connection.html) type: Collection payload for NetworkPrefix edges with total count.
- [`NetworkPrefixEdge`](https://wartiva.com/api-docs/types/network-prefix-edge.html) type: Edge payload for a NetworkPrefix.
- [`NetworkPrefixPayload`](https://wartiva.com/api-docs/types/network-prefix-payload.html) type: Payload wrapper for a single NetworkPrefix result.

## Related types

- [`Device`](https://wartiva.com/api-docs/types/device.html) A physical or virtual device that does not run the Wartiva endpoint application but is visible on the network to a managed Endpoint, such as…
- [`Network`](https://wartiva.com/api-docs/types/network.html) An IP network (subnet) that a managed Endpoint has been attached to, identified by its address range in CIDR notation and, for networks outside a…
- [`OpenPort`](https://wartiva.com/api-docs/types/open-port.html) One TCP or UDP port at one IP address on a discovered Device, found by managed endpoints port-scanning the devices on their local networks and by…
- [`Service`](https://wartiva.com/api-docs/types/service.html) A network service identified on a discovered Device: one protocol (such as HTTP, TLS, SSH, SMB, DNS, SNMP, IPP, mDNS, or UPnP) acting as a client or…

## Example

### Example

```json
{
  "id": "4",
  "orgId": "615f3b3b28284380e28a7342",
  "seen": SeenOnline,
  "objectType": "ACCOUNT_POLICY",
  "objectTypeLabel": "xyz789",
  "displayName": "xyz789",
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z",
  "createdAt": "2021-10-07T18:23:25.829Z",
  "updatedAt": "2021-10-07T18:23:25.829Z",
  "snapshotInfo": GraphObjectSnapshotInfo,
  "prefix": IpNetwork,
  "isNetworkAddress": false,
  "isHostAddress": true,
  "network": Network,
  "arpTableEntries": ArpTableEntryConnection,
  "interfaces": InterfaceConnection,
  "ports": OpenPortConnection,
  "seenOnDevices": DeviceConnection,
  "seenOnInterfaces": InterfaceConnection,
  "services": ServiceConnection,
  "findings": FindingsPayload,
  "issues": IssuesPayload,
  "issuesSummary": IssuesSummary
}

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
