An IP network (subnet) that a managed Endpoint has been attached to, identified by its address range in CIDR notation and, for networks outside a known premise, by the MAC address of its gateway router, so two home networks that both use 192.168.1.0/24 remain distinct. The NetworkType records which rule identifies it. A Network ties together the endpoint Interface objects connected to it, the Device objects seen on it and acting as its gateway, the open ports and services found there, its NetworkPrefix addresses, and the PositionSeen where it is located.
Fields
| Field Name | Description |
|---|---|
id - ID!
|
The Network's unique identifier on the security graph. |
orgId - OrganizationId!
|
Unique identifier that corresponds to your deployment of this product or a specific customer account. |
seen - SeenOnline!
|
Describes when this Network was seen online. |
objectType - GraphObjectType!
|
The type of this graph object. |
objectTypeLabel - String!
|
A localized label describing the object type. |
displayName - String!
|
A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object. |
firstSeen - Time!
|
Time this object was first seen. |
lastSeen - Time!
|
Time this object was last seen. |
createdAt - Time!
|
The time this object was created in the security graph. |
updatedAt - Time!
|
The time this object was last mutated in the security graph. |
snapshotInfo - GraphObjectSnapshotInfo!
|
Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed. |
networkType - NetworkType!
|
How this network is uniquely identified: REMOTE and LINK_LOCAL networks by address range plus gateway MAC address, PREMISE networks by address range alone. |
addressFamily - AddressFamily!
|
Network address family type of this network. |
ipNet - IpNetwork!
|
The network's address range in CIDR notation, e.g. 192.168.1.0/24. Also used as the display name. |
position - PositionSeen
|
The PositionSeen this Network is located at if available. |
connectedInterfaces - InterfaceConnection!
|
Interfaces connected to this Network. |
devices - DeviceConnection!
|
Devices seen connected to this Network. When timeRange is null the last 30 days will be returned. When timeRange is specified all entries seen in the time range are returned. |
|
Arguments
Maximum number of results to return.
Number of results to skip.
Optional time range filter.
When true, the payload will include information about when the edge was seen in the relationship. The data set will be limited to the time range specified in the timeRange field. If includeSeen is true and timeRange is null then seen data for the default 7 day time range will be returned. |
|
endpoints - EndpointConnection!
|
Endpoints seen connected to this Network. When timeRange is null the last 30 days will be returned. When timeRange is specified all entries seen in the time range are returned. |
|
Arguments
Maximum number of results to return.
Number of results to skip.
Optional time range filter.
When true, the payload will include information about when the edge was seen in the relationship. The data set will be limited to the time range specified in the timeRange field. If includeSeen is true and timeRange is null then seen data for the default 7 day time range will be returned. |
|
gatewayDevices - DeviceConnection!
|
Devices seen acting as a gateway for this Network. When timeRange is null the last 30 days will be returned. When timeRange is specified all entries seen in the time range are returned. |
|
Arguments
Maximum number of results to return.
Number of results to skip.
Optional time range filter.
When true, the payload will include information about when the edge was seen in the relationship. The data set will be limited to the time range specified in the timeRange field. If includeSeen is true and timeRange is null then seen data for the default 7 day time range will be returned. |
|
ports - OpenPortConnection!
|
OpenPorts found on this Network. |
prefixes - NetworkPrefixConnection!
|
IP prefixes found on this Network. |
seenConnectedInterfaces - InterfaceConnection!
|
Interfaces seen connected to this Network. When timeRange is null the last 30 days will be returned. When timeRange is specified all entries seen in the time range are returned. |
|
Arguments
Maximum number of results to return.
Number of results to skip.
Optional time range filter.
When true, the payload will include information about when the edge was seen in the relationship. The data set will be limited to the time range specified in the timeRange field. If includeSeen is true and timeRange is null then seen data for the default 7 day time range will be returned. |
|
services - ServiceConnection!
|
Services found on this Network. |
wlanAccessPoints - WlanAccessPointConnection!
|
Wireless LAN access points associated with this network. When timeRange is null the default time range is used. When timeRange is specified all entries seen in the time range are returned. |
|
Arguments
Maximum number of results to return.
Number of results to skip.
Optional time range filter.
When true, the payload will include information about when the edge was seen in the relationship. The data set will be limited to the time range specified in the timeRange field. If includeSeen is true and timeRange is null then seen data for the default 7 day time range will be returned. |
|
wlanInterfaceConnections - WlanInterfaceConnectionConnection!
|
Wireless LAN interface connections associated with this network. |
wlanInterfaceConnectionsSeen - WlanInterfaceConnectionConnection!
|
Historical sightings of WlanInterfaceConnection connected to this Network. Each edge records when the connection was observed on this network; pass timeRange to constrain the window. When timeRange is null the last 30 days will be returned. |
|
Arguments
Maximum number of results to return.
Number of results to skip.
Restrict edges to a date/time range.
Include the per-edge seen series in the response. |
|
findings - FindingsPayload!
|
Policy findings for this object. |
issues - IssuesPayload!
|
Policy issues for this object. |
issuesSummary - IssuesSummary!
|
Summary of the active policy issues currently open on this object, broken down by severity. |
Returned by
networkquery: Retrieves a Network by its graph object id: an IP subnet that managed endpoints have joined, classified as PREMISE, REMOTE, or LINK_LOCAL, with…
Used by
NetworkPrefixtype: A specific IP address together with its subnet prefix length (e.g.OpenPorttype: One TCP or UDP port at one IP address on a discovered Device, found by managed endpoints port-scanning the devices on their local networks and by…Servicetype: A network service identified on a discovered Device: one protocol (such as HTTP, TLS, SSH, SMB, DNS, SNMP, IPP, mDNS, or UPnP) acting as a client or…DeviceIpNetworktype: An IP prefix containing an IP address and CIDR mask that a Device was seen using.GraphObjectTypeenum: An enumeration of the different types of security graph objects.GraphObjectTypeCategoryenum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.NetworkConnectiontype: Collection payload for Network edges with total count.NetworkEdgetype: Edge payload for a Network with optional seen data.NetworkPayloadtype: Payload wrapper for a single Network result.RuleApplyToOptionKeyenum: Attribute keys that further scope which objects a rule applies to, in addition to its applyTo object type.SensorFilterNetworkstype: A filter applying this scope to defined Networks.WlanInterfaceConnectiontype: The association between an endpoint's WlanInterface and a Wi-Fi network, identified by the adapter, the network name (SSID), and the access point's…
Related types
OpenPortOne TCP or UDP port at one IP address on a discovered Device, found by managed endpoints port-scanning the devices on their local networks and by…PositionSeenA geographic coordinate (latitude and longitude) where a managed Endpoint was observed, and the times it was seen there.ServiceA network service identified on a discovered Device: one protocol (such as HTTP, TLS, SSH, SMB, DNS, SNMP, IPP, mDNS, or UPnP) acting as a client or…
Example
Example
{
"id": 4,
"orgId": "615f3b3b28284380e28a7342",
"seen": SeenOnline,
"objectType": "ACCOUNT_POLICY",
"objectTypeLabel": "abc123",
"displayName": "abc123",
"firstSeen": "2021-10-07T18:23:25.829Z",
"lastSeen": "2021-10-07T18:23:25.829Z",
"createdAt": "2021-10-07T18:23:25.829Z",
"updatedAt": "2021-10-07T18:23:25.829Z",
"snapshotInfo": GraphObjectSnapshotInfo,
"networkType": "REMOTE",
"addressFamily": "AF_UNSPEC",
"ipNet": IpNetwork,
"position": PositionSeen,
"connectedInterfaces": InterfaceConnection,
"devices": DeviceConnection,
"endpoints": EndpointConnection,
"gatewayDevices": DeviceConnection,
"ports": OpenPortConnection,
"prefixes": NetworkPrefixConnection,
"seenConnectedInterfaces": InterfaceConnection,
"services": ServiceConnection,
"wlanAccessPoints": WlanAccessPointConnection,
"wlanInterfaceConnections": WlanInterfaceConnectionConnection,
"wlanInterfaceConnectionsSeen": WlanInterfaceConnectionConnection,
"findings": FindingsPayload,
"issues": IssuesPayload,
"issuesSummary": IssuesSummary
}