Networks, devices, and sensors · GraphQL type

Service type

A network service identified on a discovered Device: one protocol (such as HTTP, TLS, SSH, SMB, DNS, SNMP, IPP, mDNS, or UPnP) acting as a client or server at one IP address, transport protocol, and port. Services are identified by sensors that probe a device's OpenPort objects and listen to its discovery traffic, run from managed endpoints on the local network or from Wartiva's servers. Each service carries a protocol-specific ServiceReport, its up-time history (including when it was reachable from the public Internet), and the CPE product identifiers and matching CVEs found for the software it runs.

Fields

Field Name Description
id - ID! Unique identifier for this graph object.
orgId - OrganizationId! Unique identifier for the owning organization.
objectType - GraphObjectType! The type of this graph object.
objectTypeLabel - String! A localized label describing the object type.
displayName - String! A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object.
firstSeen - Time! Time this object was first seen.
lastSeen - Time! Time this object was last seen.
seen - SeenOnline! When this graph object was seen.
createdAt - Time! The time this object was created in the security graph.
updatedAt - Time! The time this object was last mutated in the security graph.
snapshotInfo - GraphObjectSnapshotInfo! Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed.
device - Device The Device this network service is found on.
network - Network The Network this network service is found on if known.
networkPrefix - NetworkPrefix The NetworkPrefix containing the IP this network service is found on if known.
openPort - OpenPort The OpenPort this network service is found on if available.
public - Boolean! True if the service is found to be open to the public Internet.
addressFamily - AddressFamily! Network type where the service was found.
ip - IpAddress IP address where the service was found online.
port - Int IP port number where the service was found online, an unsigned 16-bit integer.
protocol - IpProtocol Transport protocol where the service was found online.
serviceType - ServiceType! Identity of the service running if known e.g.: unknown, http, https, dns, etc.
clientServer - ClientServer! Identifies the discovered service as either a network client or server.
sensorId - ID! The unique identifier of the sensor that last discovered this network service.
sensor - Sensor! The sensor that last discovered this network service.
sensorVersion - String! The version of the sensor that last discovered this network service.
seenUp - SeenUp! Describes when this Service was seen up.
seenUpPublic - SeenUp! Describes when this Service was seen up to the public Internet.
report - ServiceReport The service specific data structure describing details of the service.
canResubmitSensorRequests - Boolean! True if calling mutation sensorRequestReSubmitForService would have re-submitted one or more sensor requests related to this service.
sensorRequestIds - [ID!] The associated SensorRequest identifiers if any. If the sensor only runs in the LAN zone this list will be empty.
sensorRequests - [SensorRequest!] The associated SensorRequests if any. If the sensor only runs in the LAN zone this list will be empty.
vulnerabilities - PlatformVulnerabilities CPE identifiers determined for the product this service is running and the CVEs they match in the vulnerability catalog. Null when the service's protocol revealed no product identity, or revealed too little of it to match vulnerabilities accurately. See PlatformVulnerabilities.
findings - FindingsPayload! Policy findings for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issues - IssuesPayload! Policy issues for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issuesSummary - IssuesSummary! Summary of the active policy issues currently open on this object, broken down by severity.

Returned by

  • service query: Retrieves a Service by its graph object id: a network service identified on a discovered device, such as HTTP, TLS, SSH, SMB, SNMP, or DNS, in a…

Used by

  • Network type: An IP network (subnet) that a managed Endpoint has been attached to, identified by its address range in CIDR notation and, for networks outside a…
  • NetworkPrefix type: A specific IP address together with its subnet prefix length (e.g.
  • GraphObjectType enum: An enumeration of the different types of security graph objects.
  • GraphObjectTypeCategory enum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.
  • RuleApplyToOptionKey enum: Attribute keys that further scope which objects a rule applies to, in addition to its applyTo object type.
  • ServiceConnection type: Connection for Service edges with total count.
  • ServiceEdge type: Edge payload for a Service with optional seen data.
  • ServicePayload type: Payload wrapper for a single Service result.
  • ServiceSummary type: An abbreviated summary of a network Service.

Related types

  • Device A physical or virtual device that does not run the Wartiva endpoint application but is visible on the network to a managed Endpoint, such as…
  • Network An IP network (subnet) that a managed Endpoint has been attached to, identified by its address range in CIDR notation and, for networks outside a…
  • NetworkPrefix A specific IP address together with its subnet prefix length (e.g.
  • OpenPort One TCP or UDP port at one IP address on a discovered Device, found by managed endpoints port-scanning the devices on their local networks and by…
  • SensorRequest A standing request to run one Sensor against one Device IP address, optionally on a specific protocol and port, in the SAE or PUBLIC zone.

Example

Example

{
  "id": 4,
  "orgId": "615f3b3b28284380e28a7342",
  "objectType": "ACCOUNT_POLICY",
  "objectTypeLabel": "abc123",
  "displayName": "abc123",
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z",
  "seen": SeenOnline,
  "createdAt": "2021-10-07T18:23:25.829Z",
  "updatedAt": "2021-10-07T18:23:25.829Z",
  "snapshotInfo": GraphObjectSnapshotInfo,
  "device": Device,
  "network": Network,
  "networkPrefix": NetworkPrefix,
  "openPort": OpenPort,
  "public": true,
  "addressFamily": "AF_UNSPEC",
  "ip": IpAddress,
  "port": 123,
  "protocol": "TCP",
  "serviceType": "UNKNOWN",
  "clientServer": "CLIENT",
  "sensorId": "4",
  "sensor": Sensor,
  "sensorVersion": "abc123",
  "seenUp": SeenUp,
  "seenUpPublic": SeenUp,
  "report": AppSocket,
  "canResubmitSensorRequests": false,
  "sensorRequestIds": [4],
  "sensorRequests": [SensorRequest],
  "vulnerabilities": PlatformVulnerabilities,
  "findings": FindingsPayload,
  "issues": IssuesPayload,
  "issuesSummary": IssuesSummary
}