Networks, devices, and sensors · GraphQL type

Network type

An IP network (subnet) that a managed Endpoint has been attached to, identified by its address range in CIDR notation and, for networks outside a known premise, by the MAC address of its gateway router, so two home networks that both use 192.168.1.0/24 remain distinct. The NetworkType records which rule identifies it. A Network ties together the endpoint Interface objects connected to it, the Device objects seen on it and acting as its gateway, the open ports and services found there, its NetworkPrefix addresses, and the PositionSeen where it is located.

Fields

Field Name Description
id - ID! The Network's unique identifier on the security graph.
orgId - OrganizationId! Unique identifier that corresponds to your deployment of this product or a specific customer account.
seen - SeenOnline! Describes when this Network was seen online.
objectType - GraphObjectType! The type of this graph object.
objectTypeLabel - String! A localized label describing the object type.
displayName - String! A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object.
firstSeen - Time! Time this object was first seen.
lastSeen - Time! Time this object was last seen.
createdAt - Time! The time this object was created in the security graph.
updatedAt - Time! The time this object was last mutated in the security graph.
snapshotInfo - GraphObjectSnapshotInfo! Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed.
networkType - NetworkType! How this network is uniquely identified: REMOTE and LINK_LOCAL networks by address range plus gateway MAC address, PREMISE networks by address range alone.
addressFamily - AddressFamily! Network address family type of this network.
ipNet - IpNetwork! The network's address range in CIDR notation, e.g. 192.168.1.0/24. Also used as the display name.
position - PositionSeen The PositionSeen this Network is located at if available.
connectedInterfaces - InterfaceConnection! Interfaces connected to this Network.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

devices - DeviceConnection! Devices seen connected to this Network. When timeRange is null the last 30 days will be returned. When timeRange is specified all entries seen in the time range are returned.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

timeRange - DateTimeRangeInput

Optional time range filter.

includeSeen - Boolean

When true, the payload will include information about when the edge was seen in the relationship. The data set will be limited to the time range specified in the timeRange field. If includeSeen is true and timeRange is null then seen data for the default 7 day time range will be returned.

endpoints - EndpointConnection! Endpoints seen connected to this Network. When timeRange is null the last 30 days will be returned. When timeRange is specified all entries seen in the time range are returned.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

timeRange - DateTimeRangeInput

Optional time range filter.

includeSeen - Boolean

When true, the payload will include information about when the edge was seen in the relationship. The data set will be limited to the time range specified in the timeRange field. If includeSeen is true and timeRange is null then seen data for the default 7 day time range will be returned.

gatewayDevices - DeviceConnection! Devices seen acting as a gateway for this Network. When timeRange is null the last 30 days will be returned. When timeRange is specified all entries seen in the time range are returned.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

timeRange - DateTimeRangeInput

Optional time range filter.

includeSeen - Boolean

When true, the payload will include information about when the edge was seen in the relationship. The data set will be limited to the time range specified in the timeRange field. If includeSeen is true and timeRange is null then seen data for the default 7 day time range will be returned.

ports - OpenPortConnection! OpenPorts found on this Network.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

prefixes - NetworkPrefixConnection! IP prefixes found on this Network.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

seenConnectedInterfaces - InterfaceConnection! Interfaces seen connected to this Network. When timeRange is null the last 30 days will be returned. When timeRange is specified all entries seen in the time range are returned.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

timeRange - DateTimeRangeInput

Optional time range filter.

includeSeen - Boolean

When true, the payload will include information about when the edge was seen in the relationship. The data set will be limited to the time range specified in the timeRange field. If includeSeen is true and timeRange is null then seen data for the default 7 day time range will be returned.

services - ServiceConnection! Services found on this Network.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

wlanAccessPoints - WlanAccessPointConnection! Wireless LAN access points associated with this network. When timeRange is null the default time range is used. When timeRange is specified all entries seen in the time range are returned.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

timeRange - DateTimeRangeInput

Optional time range filter.

includeSeen - Boolean

When true, the payload will include information about when the edge was seen in the relationship. The data set will be limited to the time range specified in the timeRange field. If includeSeen is true and timeRange is null then seen data for the default 7 day time range will be returned.

wlanInterfaceConnections - WlanInterfaceConnectionConnection! Wireless LAN interface connections associated with this network.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

wlanInterfaceConnectionsSeen - WlanInterfaceConnectionConnection! Historical sightings of WlanInterfaceConnection connected to this Network. Each edge records when the connection was observed on this network; pass timeRange to constrain the window. When timeRange is null the last 30 days will be returned.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

timeRange - DateTimeRangeInput

Restrict edges to a date/time range.

includeSeen - Boolean

Include the per-edge seen series in the response.

findings - FindingsPayload! Policy findings for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issues - IssuesPayload! Policy issues for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issuesSummary - IssuesSummary! Summary of the active policy issues currently open on this object, broken down by severity.

Returned by

  • network query: Retrieves a Network by its graph object id: an IP subnet that managed endpoints have joined, classified as PREMISE, REMOTE, or LINK_LOCAL, with…

Used by

  • NetworkPrefix type: A specific IP address together with its subnet prefix length (e.g.
  • OpenPort type: One TCP or UDP port at one IP address on a discovered Device, found by managed endpoints port-scanning the devices on their local networks and by…
  • Service type: A network service identified on a discovered Device: one protocol (such as HTTP, TLS, SSH, SMB, DNS, SNMP, IPP, mDNS, or UPnP) acting as a client or…
  • DeviceIpNetwork type: An IP prefix containing an IP address and CIDR mask that a Device was seen using.
  • GraphObjectType enum: An enumeration of the different types of security graph objects.
  • GraphObjectTypeCategory enum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.
  • NetworkConnection type: Collection payload for Network edges with total count.
  • NetworkEdge type: Edge payload for a Network with optional seen data.
  • NetworkPayload type: Payload wrapper for a single Network result.
  • RuleApplyToOptionKey enum: Attribute keys that further scope which objects a rule applies to, in addition to its applyTo object type.
  • SensorFilterNetworks type: A filter applying this scope to defined Networks.
  • WlanInterfaceConnection type: The association between an endpoint's WlanInterface and a Wi-Fi network, identified by the adapter, the network name (SSID), and the access point's…

Related types

  • OpenPort One TCP or UDP port at one IP address on a discovered Device, found by managed endpoints port-scanning the devices on their local networks and by…
  • PositionSeen A geographic coordinate (latitude and longitude) where a managed Endpoint was observed, and the times it was seen there.
  • Service A network service identified on a discovered Device: one protocol (such as HTTP, TLS, SSH, SMB, DNS, SNMP, IPP, mDNS, or UPnP) acting as a client or…

Example

Example

{
  "id": 4,
  "orgId": "615f3b3b28284380e28a7342",
  "seen": SeenOnline,
  "objectType": "ACCOUNT_POLICY",
  "objectTypeLabel": "abc123",
  "displayName": "abc123",
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z",
  "createdAt": "2021-10-07T18:23:25.829Z",
  "updatedAt": "2021-10-07T18:23:25.829Z",
  "snapshotInfo": GraphObjectSnapshotInfo,
  "networkType": "REMOTE",
  "addressFamily": "AF_UNSPEC",
  "ipNet": IpNetwork,
  "position": PositionSeen,
  "connectedInterfaces": InterfaceConnection,
  "devices": DeviceConnection,
  "endpoints": EndpointConnection,
  "gatewayDevices": DeviceConnection,
  "ports": OpenPortConnection,
  "prefixes": NetworkPrefixConnection,
  "seenConnectedInterfaces": InterfaceConnection,
  "services": ServiceConnection,
  "wlanAccessPoints": WlanAccessPointConnection,
  "wlanInterfaceConnections": WlanInterfaceConnectionConnection,
  "wlanInterfaceConnectionsSeen": WlanInterfaceConnectionConnection,
  "findings": FindingsPayload,
  "issues": IssuesPayload,
  "issuesSummary": IssuesSummary
}