---
title: systemService query | Wartiva GraphQL API
description: Retrieves a SystemService by its graph object id: a background service or daemon configured on an endpoint. Wartiva GraphQL API reference with examples.
url: https://wartiva.com/api-docs/queries/system-service.html
updated: 2026-10-07
---

Endpoint configuration · GraphQL query

# `systemService` query

Retrieves a [SystemService](https://wartiva.com/api-docs/types/system-service.html) by its graph object id: a background service or daemon configured on an endpoint (a Windows service, macOS launchd job, or Linux systemd service), with its executable path, start type, restart behavior, and current state. An [Endpoint](https://wartiva.com/api-docs/types/endpoint.html) lists its current services through `systemServices` and their history through `systemServicesSeen`; find them across endpoints with [graphSearch](https://wartiva.com/api-docs/queries/graph-search.html) on the SYSTEM_SERVICE object type. Returns a not-found error when no object has the id, and an error when the id belongs to another object type.

## Response

Returns a [`SystemServicePayload!`](https://wartiva.com/api-docs/types/system-service-payload.html)

## Arguments

| Name | Description |
|---|---|
| `id` - [`ID!`](https://wartiva.com/api-docs/types/id.html) | The SystemService identifier. |
| `mockOptions` - [`MockDataInput`](https://wartiva.com/api-docs/types/mock-data-input.html) | Options for mock data generation. Options supported: key: "PLATFORM", value: OsPlatform example: "mockOptions": { "options": [ { "key": "PLATFORM", "value": "WINDOWS" } ] } |

## Example

### Query

```graphql
query systemService(
  $id: ID!,
  $mockOptions: MockDataInput
) {
  systemService(
    id: $id,
    mockOptions: $mockOptions
  ) {
    node {
      id
      orgId
      seen {
        ...SeenOnlineFragment
      }
      objectType
      objectTypeLabel
      displayName
      firstSeen
      lastSeen
      createdAt
      updatedAt
      snapshotInfo {
        ...GraphObjectSnapshotInfoFragment
      }
      endpoint {
        ...EndpointFragment
      }
      executablePath
      userName
      startType
      description
      restartType
      state
      osSpecific {
        ... on SystemServiceMacOS {
          ...SystemServiceMacOSFragment
        }
        ... on SystemServiceWindows {
          ...SystemServiceWindowsFragment
        }
        ... on SystemServiceLinux {
          ...SystemServiceLinuxFragment
        }
      }
      findings {
        ...FindingsPayloadFragment
      }
      issues {
        ...IssuesPayloadFragment
      }
      issuesSummary {
        ...IssuesSummaryFragment
      }
    }
  }
}

```

### Variables

```json
{
  "id": "4",
  "mockOptions": MockDataInput
}

```

### Response

```json
{"data": {"systemService": {"node": SystemService}}}

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
