A network service identified on a discovered Device: one protocol (such as HTTP, TLS, SSH, SMB, DNS, SNMP, IPP, mDNS, or UPnP) acting as a client or server at one IP address, transport protocol, and port. Services are identified by sensors that probe a device's OpenPort objects and listen to its discovery traffic, run from managed endpoints on the local network or from Wartiva's servers. Each service carries a protocol-specific ServiceReport, its up-time history (including when it was reachable from the public Internet), and the CPE product identifiers and matching CVEs found for the software it runs.
Fields
| Field Name | Description |
|---|---|
id - ID!
|
Unique identifier for this graph object. |
orgId - OrganizationId!
|
Unique identifier for the owning organization. |
objectType - GraphObjectType!
|
The type of this graph object. |
objectTypeLabel - String!
|
A localized label describing the object type. |
displayName - String!
|
A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object. |
firstSeen - Time!
|
Time this object was first seen. |
lastSeen - Time!
|
Time this object was last seen. |
seen - SeenOnline!
|
When this graph object was seen. |
createdAt - Time!
|
The time this object was created in the security graph. |
updatedAt - Time!
|
The time this object was last mutated in the security graph. |
snapshotInfo - GraphObjectSnapshotInfo!
|
Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed. |
device - Device
|
The Device this network service is found on. |
network - Network
|
The Network this network service is found on if known. |
networkPrefix - NetworkPrefix
|
The NetworkPrefix containing the IP this network service is found on if known. |
openPort - OpenPort
|
The OpenPort this network service is found on if available. |
public - Boolean!
|
True if the service is found to be open to the public Internet. |
addressFamily - AddressFamily!
|
Network type where the service was found. |
ip - IpAddress
|
IP address where the service was found online. |
port - Int
|
IP port number where the service was found online, an unsigned 16-bit integer. |
protocol - IpProtocol
|
Transport protocol where the service was found online. |
serviceType - ServiceType!
|
Identity of the service running if known e.g.: unknown, http, https, dns, etc. |
clientServer - ClientServer!
|
Identifies the discovered service as either a network client or server. |
sensorId - ID!
|
The unique identifier of the sensor that last discovered this network service. |
sensor - Sensor!
|
The sensor that last discovered this network service. |
sensorVersion - String!
|
The version of the sensor that last discovered this network service. |
seenUp - SeenUp!
|
Describes when this Service was seen up. |
seenUpPublic - SeenUp!
|
Describes when this Service was seen up to the public Internet. |
report - ServiceReport
|
The service specific data structure describing details of the service. |
canResubmitSensorRequests - Boolean!
|
True if calling mutation sensorRequestReSubmitForService would have re-submitted one or more sensor requests related to this service. |
sensorRequestIds - [ID!]
|
The associated SensorRequest identifiers if any. If the sensor only runs in the LAN zone this list will be empty. |
sensorRequests - [SensorRequest!]
|
The associated SensorRequests if any. If the sensor only runs in the LAN zone this list will be empty. |
vulnerabilities - PlatformVulnerabilities
|
CPE identifiers determined for the product this service is running and the CVEs they match in the vulnerability catalog. Null when the service's protocol revealed no product identity, or revealed too little of it to match vulnerabilities accurately. See PlatformVulnerabilities. |
findings - FindingsPayload!
|
Policy findings for this object. |
issues - IssuesPayload!
|
Policy issues for this object. |
issuesSummary - IssuesSummary!
|
Summary of the active policy issues currently open on this object, broken down by severity. |
Returned by
servicequery: Retrieves a Service by its graph object id: a network service identified on a discovered device, such as HTTP, TLS, SSH, SMB, SNMP, or DNS, in a…
Used by
Networktype: An IP network (subnet) that a managed Endpoint has been attached to, identified by its address range in CIDR notation and, for networks outside a…NetworkPrefixtype: A specific IP address together with its subnet prefix length (e.g.GraphObjectTypeenum: An enumeration of the different types of security graph objects.GraphObjectTypeCategoryenum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.RuleApplyToOptionKeyenum: Attribute keys that further scope which objects a rule applies to, in addition to its applyTo object type.ServiceConnectiontype: Connection for Service edges with total count.ServiceEdgetype: Edge payload for a Service with optional seen data.ServicePayloadtype: Payload wrapper for a single Service result.ServiceSummarytype: An abbreviated summary of a network Service.
Related types
DeviceA physical or virtual device that does not run the Wartiva endpoint application but is visible on the network to a managed Endpoint, such as…NetworkAn IP network (subnet) that a managed Endpoint has been attached to, identified by its address range in CIDR notation and, for networks outside a…NetworkPrefixA specific IP address together with its subnet prefix length (e.g.OpenPortOne TCP or UDP port at one IP address on a discovered Device, found by managed endpoints port-scanning the devices on their local networks and by…SensorRequestA standing request to run one Sensor against one Device IP address, optionally on a specific protocol and port, in the SAE or PUBLIC zone.
Example
Example
{
"id": 4,
"orgId": "615f3b3b28284380e28a7342",
"objectType": "ACCOUNT_POLICY",
"objectTypeLabel": "abc123",
"displayName": "abc123",
"firstSeen": "2021-10-07T18:23:25.829Z",
"lastSeen": "2021-10-07T18:23:25.829Z",
"seen": SeenOnline,
"createdAt": "2021-10-07T18:23:25.829Z",
"updatedAt": "2021-10-07T18:23:25.829Z",
"snapshotInfo": GraphObjectSnapshotInfo,
"device": Device,
"network": Network,
"networkPrefix": NetworkPrefix,
"openPort": OpenPort,
"public": true,
"addressFamily": "AF_UNSPEC",
"ip": IpAddress,
"port": 123,
"protocol": "TCP",
"serviceType": "UNKNOWN",
"clientServer": "CLIENT",
"sensorId": "4",
"sensor": Sensor,
"sensorVersion": "abc123",
"seenUp": SeenUp,
"seenUpPublic": SeenUp,
"report": AppSocket,
"canResubmitSensorRequests": false,
"sensorRequestIds": [4],
"sensorRequests": [SensorRequest],
"vulnerabilities": PlatformVulnerabilities,
"findings": FindingsPayload,
"issues": IssuesPayload,
"issuesSummary": IssuesSummary
}