Networks, devices, and sensors · GraphQL type

Route type

One entry in an Endpoint's IP routing table, collected from Windows, macOS, and Linux endpoints as part of the periodic network inventory. Each route records a destination prefix, the next-hop gateway (absent for on-link and loopback routes), the outgoing interface, the metric, and the mechanism that installed it (RouteProtocol), such as a static entry, a directly connected interface, or a routing protocol. Together the routes show where the endpoint sends traffic for each destination, including its default route.

Fields

Field Name Description
id - ID! The Route's unique identifier on the security graph.
orgId - OrganizationId! Unique identifier that corresponds to your deployment of this product or a specific customer account that this Endpoint belongs to.
seen - SeenOnline! Describes when this Route was seen.
objectType - GraphObjectType! The type of this graph object.
objectTypeLabel - String! A localized label describing the object type.
displayName - String! A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object.
firstSeen - Time! Time this object was first seen.
lastSeen - Time! Time this object was last seen.
createdAt - Time! The time this object was created in the security graph.
updatedAt - Time! The time this object was last mutated in the security graph.
snapshotInfo - GraphObjectSnapshotInfo! Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed.
endpoint - Endpoint The Endpoint this Route belongs to if available.
destination - IpNetwork! The IP address prefix for the destination IP address for this route.
nextHop - IpAddress For a remote route, the IP address of the next system or gateway en route. If the route is to a local loopback address or an IP address on the local link, the next hop is unspecified.
protocol - RouteProtocol! The routing mechanism how this IP route was added.
metric - Int The cost of the route as reported by the operating system. When several routes match a destination equally, the one with the lowest metric is preferred.
interfaceId - String The unique identifier for a network interface in the context of an Endpoint. This is the name in macOS,Linux and the GUID in MS Windows. See GUID structure (Microsoft) for the Windows GUID format.
findings - FindingsPayload! Policy findings for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issues - IssuesPayload! Policy issues for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issuesSummary - IssuesSummary! Summary of the active policy issues currently open on this object, broken down by severity.

Returned by

  • route query: Retrieves a Route by its graph object id: one entry in a Windows, macOS, or Linux endpoint's IP routing table.

Used by

  • Endpoint type: A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
  • GraphObjectType enum: An enumeration of the different types of security graph objects.
  • GraphObjectTypeCategory enum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.
  • RouteConnection type: Collection payload for Route edges with total count.
  • RouteEdge type: Edge payload for a Route with optional seen data.
  • RoutePayload type: Payload wrapper for a single Route result.

Related types

  • Endpoint A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.

Example

Example

{
  "id": 4,
  "orgId": "615f3b3b28284380e28a7342",
  "seen": SeenOnline,
  "objectType": "ACCOUNT_POLICY",
  "objectTypeLabel": "abc123",
  "displayName": "xyz789",
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z",
  "createdAt": "2021-10-07T18:23:25.829Z",
  "updatedAt": "2021-10-07T18:23:25.829Z",
  "snapshotInfo": GraphObjectSnapshotInfo,
  "endpoint": Endpoint,
  "destination": IpNetwork,
  "nextHop": IpAddress,
  "protocol": "UNSPEC",
  "metric": 987,
  "interfaceId": "abc123",
  "findings": FindingsPayload,
  "issues": IssuesPayload,
  "issuesSummary": IssuesSummary
}