Networks, devices, and sensors · GraphQL type

OpenPort type

One TCP or UDP port at one IP address on a discovered Device, found by managed endpoints port-scanning the devices on their local networks and by Wartiva's server-side sensors scanning public addresses. It keeps the port's open and closed history (when it was first and last seen open, and when last seen closed), the number of endpoints that currently observe it open, and whether it is exposed to the public Internet. Each open port links to the Network and NetworkPrefix where it was found and to the Service objects identified on it.

Fields

Field Name Description
id - ID! Unique identifier for this graph object.
orgId - OrganizationId! Unique identifier for the owning organization.
objectType - GraphObjectType! The type of this graph object.
objectTypeLabel - String! A localized label describing the object type.
displayName - String! A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object.
firstSeen - Time! Time this object was first seen.
lastSeen - Time! Time this object was last seen.
seen - SeenOnline! When this graph object was seen.
createdAt - Time! The time this object was created in the security graph.
updatedAt - Time! The time this object was last mutated in the security graph.
snapshotInfo - GraphObjectSnapshotInfo! Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed.
device - Device The Device this open port belongs to.
network - Network The Network this open port was found on if known.
networkPrefix - NetworkPrefix The NetworkPrefix containing the IP this open port was found on if known.
ip - IpAddress! IP address where the port was found open.
isOpen - Boolean! True if the last known state was open.
public - Boolean! True if the port is on a public IP address and has been observed open from the public Internet.
port - Int! The IP port number, an unsigned 16-bit integer.
protocol - IpProtocol! The transport protocol of the port, TCP or UDP.
state - PortState! Last known state e.g. open or closed.
services - ServiceConnection! Services found on this open port.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

endpoints - EndpointConnection! Endpoints that have seen this port open. When timeRange is null the last 30 days will be returned. When timeRange is specified all entries seen in the time range are returned.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

timeRange - DateTimeRangeInput

Optional time range filter.

includeSeen - Boolean

When true, the payload will include information about when the edge was seen in the relationship. The data set will be limited to the time range specified in the timeRange field. If includeSeen is true and timeRange is null then seen data for the default 7 day time range will be returned.

firstSeenOpen - Time The time when the port was first detected as open.
lastSeenOpen - Time The time the port was last seen open.
lastSeenClosed - Time The time the port was last seen closed. Will be null if always seen open.
seenOpen - SeenOnline! Describes when this port was seen open.
openToEndpointCount - Int! The number of Endpoints that currently observe this port as open.
findings - FindingsPayload! Policy findings for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issues - IssuesPayload! Policy issues for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issuesSummary - IssuesSummary! Summary of the active policy issues currently open on this object, broken down by severity.

Returned by

  • openPort query: Retrieves an OpenPort by its graph object id: a TCP or UDP port on a discovered device, found by endpoint port scans of local devices or by…

Used by

  • Endpoint type: A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
  • Network type: An IP network (subnet) that a managed Endpoint has been attached to, identified by its address range in CIDR notation and, for networks outside a…
  • NetworkPrefix type: A specific IP address together with its subnet prefix length (e.g.
  • Service type: A network service identified on a discovered Device: one protocol (such as HTTP, TLS, SSH, SMB, DNS, SNMP, IPP, mDNS, or UPnP) acting as a client or…
  • GraphObjectType enum: An enumeration of the different types of security graph objects.
  • GraphObjectTypeCategory enum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.
  • OpenPortConnection type: Connection for OpenPort edges with total count.
  • OpenPortEdge type: Edge payload for an OpenPort with optional seen data.
  • OpenPortPayload type: Payload wrapper for a single OpenPort result.
  • OpenPortSummary type: An abbreviated summary of an OpenPort.
  • RuleApplyToOptionKey enum: Attribute keys that further scope which objects a rule applies to, in addition to its applyTo object type.

Related types

  • Device A physical or virtual device that does not run the Wartiva endpoint application but is visible on the network to a managed Endpoint, such as…
  • Network An IP network (subnet) that a managed Endpoint has been attached to, identified by its address range in CIDR notation and, for networks outside a…
  • NetworkPrefix A specific IP address together with its subnet prefix length (e.g.

Example

Example

{
  "id": 4,
  "orgId": "615f3b3b28284380e28a7342",
  "objectType": "ACCOUNT_POLICY",
  "objectTypeLabel": "abc123",
  "displayName": "xyz789",
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z",
  "seen": SeenOnline,
  "createdAt": "2021-10-07T18:23:25.829Z",
  "updatedAt": "2021-10-07T18:23:25.829Z",
  "snapshotInfo": GraphObjectSnapshotInfo,
  "device": Device,
  "network": Network,
  "networkPrefix": NetworkPrefix,
  "ip": IpAddress,
  "isOpen": true,
  "public": false,
  "port": 987,
  "protocol": "TCP",
  "state": "OPEN",
  "services": ServiceConnection,
  "endpoints": EndpointConnection,
  "firstSeenOpen": "2021-10-07T18:23:25.829Z",
  "lastSeenOpen": "2021-10-07T18:23:25.829Z",
  "lastSeenClosed": "2021-10-07T18:23:25.829Z",
  "seenOpen": SeenOnline,
  "openToEndpointCount": 123,
  "findings": FindingsPayload,
  "issues": IssuesPayload,
  "issuesSummary": IssuesSummary
}