An open network socket on a process.
Fields
| Field Name | Description |
|---|---|
family - AddressFamily!
|
IP address family of the socket. |
type - SocketType!
|
Socket Protocol/Type. |
status - OpenSocketStatus!
|
State of the Socket. |
namespace - Uint64
|
The namespace identifier for the socket if applicable, available only on Linux. |
path - String!
|
The filesystem path associated with the socket if applicable. |
remoteAddr - IpAddress
|
The remote IP address the socket is connected to. |
remotePort - Int
|
The remote IP port the socket is connected to, an unsigned 16-bit integer. |
localAddr - IpAddress
|
The local IP address of the socket. |
localPort - Int
|
The local IP port of the socket, an unsigned 16-bit integer. |
Used by
Executabletype: A unique executable file observed running on an Endpoint, aggregating data across all observed processes that share the same file system path.Processtype: An operating system process.SeenOpenSockettype: An open socket snapshot and when it was last observed.
Example
Example
{
"family": "AF_UNSPEC",
"type": "GENERIC",
"status": "CLOSED",
"namespace": "8589934592",
"path": "xyz789",
"remoteAddr": IpAddress,
"remotePort": 987,
"localAddr": IpAddress,
"localPort": 987
}