Location · GraphQL type

PositionSeen type

A geographic coordinate (latitude and longitude) where a managed Endpoint was observed, and the times it was seen there. Endpoints and Device objects link to the positions where they were seen, last seen, and primarily located, a Network links to its primary position, and a position can resolve to a Location with a street address.

Fields

Field Name Description
id - ID! The PositionSeen's unique identifier on the security graph.
orgId - OrganizationId! Unique identifier that corresponds to your deployment of this product or a specific customer account that this Endpoint belongs to.
seen - SeenOnline! Describes when this Endpoint was seen online.
objectType - GraphObjectType! The type of this graph object.
objectTypeLabel - String! A localized label describing the object type.
displayName - String! A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object.
firstSeen - Time! Time this object was first seen.
lastSeen - Time! Time this object was last seen.
createdAt - Time! The time this object was created in the security graph.
updatedAt - Time! The time this object was last mutated in the security graph.
snapshotInfo - GraphObjectSnapshotInfo! Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed.
position - Position! The coordinates of this position.
location - Location If this position is associated with a known Location.
networks - NetworkConnection! Networks located at this position.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

devices - DeviceConnection! Devices last located at this position.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

primaryLocationOfDevices - DeviceConnection! Device objects primarily located at this position (where they spend most of their time).

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

devicesSeenAt - DeviceConnection! Historical sightings of Device objects at this position. Each edge records when the device was observed here; pass timeRange to constrain the window. When timeRange is null the last 30 days will be returned.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

timeRange - DateTimeRangeInput

Restrict edges to a date/time range.

includeSeen - Boolean

Include the per-edge seen series in the response.

endpoints - EndpointConnection! Endpoints last seen at this position.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

primaryLocationOfEndpoints - EndpointConnection! Endpoint objects primarily located at this position (where they spend most of their time).

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

endpointsSeenAt - EndpointConnection! Historical sightings of Endpoint objects at this position. Each edge records when the endpoint was observed here; pass timeRange to constrain the window. When timeRange is null the last 30 days will be returned.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

timeRange - DateTimeRangeInput

Restrict edges to a date/time range.

includeSeen - Boolean

Include the per-edge seen series in the response.

findings - FindingsPayload! Policy findings for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issues - IssuesPayload! Policy issues for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issuesSummary - IssuesSummary! Summary of the active policy issues currently open on this object, broken down by severity.

Returned by

  • positionSeen query: Retrieves a PositionSeen by its graph object id: a geographic coordinate where endpoints, and the devices and networks they see, were observed, with…

Used by

  • Device type: A physical or virtual device that does not run the Wartiva endpoint application but is visible on the network to a managed Endpoint, such as…
  • Endpoint type: A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
  • Network type: An IP network (subnet) that a managed Endpoint has been attached to, identified by its address range in CIDR notation and, for networks outside a…
  • GraphObjectType enum: An enumeration of the different types of security graph objects.
  • GraphObjectTypeCategory enum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.
  • PositionSeenConnection type: Collection payload for PositionSeen edges with total count.
  • PositionSeenEdge type: Edge payload for a PositionSeen with optional seen data.
  • PositionSeenPayload type: Payload wrapper for a single PositionSeen result.
  • RuleApplyToOptionKey enum: Attribute keys that further scope which objects a rule applies to, in addition to its applyTo object type.

Related types

  • Device A physical or virtual device that does not run the Wartiva endpoint application but is visible on the network to a managed Endpoint, such as…
  • Endpoint A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
  • Location A physical place identified by its global plus code (Open Location Code), with a street address resolved by reverse geocoding.

Example

Example

{
  "id": "4",
  "orgId": "615f3b3b28284380e28a7342",
  "seen": SeenOnline,
  "objectType": "ACCOUNT_POLICY",
  "objectTypeLabel": "xyz789",
  "displayName": "abc123",
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z",
  "createdAt": "2021-10-07T18:23:25.829Z",
  "updatedAt": "2021-10-07T18:23:25.829Z",
  "snapshotInfo": GraphObjectSnapshotInfo,
  "position": Position,
  "location": Location,
  "networks": NetworkConnection,
  "devices": DeviceConnection,
  "primaryLocationOfDevices": DeviceConnection,
  "devicesSeenAt": DeviceConnection,
  "endpoints": EndpointConnection,
  "primaryLocationOfEndpoints": EndpointConnection,
  "endpointsSeenAt": EndpointConnection,
  "findings": FindingsPayload,
  "issues": IssuesPayload,
  "issuesSummary": IssuesSummary
}