Endpoint configuration · GraphQL type

OpenSocket type

An open network socket on a process.

Fields

Field Name Description
family - AddressFamily! IP address family of the socket.
type - SocketType! Socket Protocol/Type.
status - OpenSocketStatus! State of the Socket.
namespace - Uint64 The namespace identifier for the socket if applicable, available only on Linux.
path - String! The filesystem path associated with the socket if applicable.
remoteAddr - IpAddress The remote IP address the socket is connected to.
remotePort - Int The remote IP port the socket is connected to, an unsigned 16-bit integer.
localAddr - IpAddress The local IP address of the socket.
localPort - Int The local IP port of the socket, an unsigned 16-bit integer.

Used by

  • Executable type: A unique executable file observed running on an Endpoint, aggregating data across all observed processes that share the same file system path.
  • Process type: An operating system process.
  • SeenOpenSocket type: An open socket snapshot and when it was last observed.

Example

Example

{
  "family": "AF_UNSPEC",
  "type": "GENERIC",
  "status": "CLOSED",
  "namespace": "8589934592",
  "path": "xyz789",
  "remoteAddr": IpAddress,
  "remotePort": 987,
  "localAddr": IpAddress,
  "localPort": 987
}