Retrieves a SystemService by its graph object id: a background service or daemon configured on an endpoint (a Windows service, macOS launchd job, or Linux systemd service), with its executable path, start type, restart behavior, and current state. An Endpoint lists its current services through systemServices and their history through systemServicesSeen; find them across endpoints with graphSearch on the SYSTEM_SERVICE object type. Returns a not-found error when no object has the id, and an error when the id belongs to another object type.
Response
Returns a SystemServicePayload!
Arguments
| Name | Description |
|---|---|
id - ID!
|
The SystemService identifier. |
mockOptions - MockDataInput
|
Options for mock data generation. Options supported: key: "PLATFORM", value: OsPlatform example: "mockOptions": { "options": [ { "key": "PLATFORM", "value": "WINDOWS" } ] } |
Example
Query
query systemService(
$id: ID!,
$mockOptions: MockDataInput
) {
systemService(
id: $id,
mockOptions: $mockOptions
) {
node {
id
orgId
seen {
...SeenOnlineFragment
}
objectType
objectTypeLabel
displayName
firstSeen
lastSeen
createdAt
updatedAt
snapshotInfo {
...GraphObjectSnapshotInfoFragment
}
endpoint {
...EndpointFragment
}
executablePath
userName
startType
description
restartType
state
osSpecific {
... on SystemServiceMacOS {
...SystemServiceMacOSFragment
}
... on SystemServiceWindows {
...SystemServiceWindowsFragment
}
... on SystemServiceLinux {
...SystemServiceLinuxFragment
}
}
findings {
...FindingsPayloadFragment
}
issues {
...IssuesPayloadFragment
}
issuesSummary {
...IssuesSummaryFragment
}
}
}
}
Variables
{
"id": "4",
"mockOptions": MockDataInput
}
Response
{"data": {"systemService": {"node": SystemService}}}