Query Commands
Query Commands
Query commands load and browse the graph in bulk. The typical usage is piping query results from firewall, NAC, or scanner logs into the graph.
shows the planned action, and _error explains any problem. Add the run=t option to
actually apply changes.
Generic Batch Commands
Work with every registered node/edge type. Input fields whose names match schema-defined attributes are stored along with the node or edge.
| Command | Input fields | Purpose |
|---|---|---|
sonar-set-node-batch | type, value, display_name, source + per-type attributes | Upsert nodes |
sonar-set-edge-batch | src_type, src_value, dst_type, dst_value, rel_type, source + edge attributes | Upsert edges (missing nodes are created) |
sonar-set-graph-batch | same as sonar-set-edge-batch | Alias with identical behavior |
sonar-remove-node-batch | type, value | Delete nodes (attributes and connected edges cascade) |
sonar-remove-edge-batch | src_type, src_value, dst_type, dst_value, rel_type | Delete edges |
json "[{\"type\":\"malware\", \"value\":\"Emotet\", \"malware_types\":[\"trojan\",\"bot\"], \"is_family\":\"true\"}]"
| sonar-set-node-batch run=t
json "[{\"src_type\":\"campaign\", \"src_value\":\"Op-X\", \"dst_type\":\"threat-actor\", \"dst_value\":\"APT99\", \"rel_type\":\"attributed-to\", \"confidence\":80}]"
| sonar-set-edge-batch run=t
Validation Rules
Batch commands validate input against the schema; violating rows fail
(in dry-run they are reported with _status=error and _error).
- Unregistered type —
unknown node type,unknown src_type,unknown rel_type - Undefined connection combination — each relationship declares its allowed
source/target type pairs. For example, feeding
user → cveinto theservesrelationship fails withunsupported combination. - Value format mismatch — types with a declared format validate their values.
For example, a
network-servicevalue not inip:port/tcpform fails withinvalid value format.
Partial Updates
- Nodes are matched by
(type, value); existing ones are updated. Attributes you do not provide stay unchanged, so send only the fields you want to change. - Edges are matched by
(source, target, relationship); existing ones only refreshlast_seen.
Asset Graph Commands
Purpose-built commands for asset topology: one input row creates several nodes and edges at once.
| Command | Fields | Result |
|---|---|---|
sonar-set-ipv4-node-batch | ip (required), mac, hostname, user, zone | IP node + MAC/host/user/zone nodes with relationships |
sonar-set-zone-node-batch | name (required), display_name, cidr | Zone node |
sonar-set-domain-node-batch | domain (required), ip | Domain node (+ IP link) |
sonar-set-cve-node-batch | ip, cve_id (required), cvss3_score, description, published, status | CVE node + has-vulnerability edge |
sonar-set-cpe-node-batch | cve_id, cpe (required) | CPE node + affects edge |
Each has a matching sonar-remove-*-node-batch.
json "[{\"ip\":\"10.0.1.1\", \"mac\":\"AA:BB:CC:DD:EE:FF\", \"hostname\":\"web01\", \"zone\":\"dmz\"}]"
| sonar-set-ipv4-node-batch run=t
Read Commands
| Command | Purpose | Key options |
|---|---|---|
sonar-graph-nodes | List nodes | type, guid, value, min-risk, tag |
sonar-graph-edges | List edges | guid, type, value, rel |
sonar-graph-attrs | List node attributes | guid, type, value, attr |
sonar-graph-node-defs | Registered node type definitions (names, attributes, value format) | locale |
sonar-graph-edge-defs | Registered relationship definitions (names, attributes, allowed pairs) | locale |
sonar-graph-builders | Registered graph builders | |
sonar-graph-running-builders | Currently running builders |
Builders
The app ships built-in builders that sync the employee and department roster into the
graph every 30 minutes (employee nodes, department nodes, membership and lead edges).
Check builder status with sonar-graph-builders. Other apps can register their own
builders — see App Extension.