---
title: Service type | Wartiva GraphQL API
description: A network service identified on a discovered Device: one protocol. Wartiva GraphQL API reference with arguments, fields, and examples.
url: https://wartiva.com/api-docs/types/service.html
updated: 2026-10-07
---

Networks, devices, and sensors · GraphQL type

# `Service` type

A network service identified on a discovered [Device](https://wartiva.com/api-docs/types/device.html): one protocol (such as HTTP, TLS, SSH, SMB, DNS, SNMP, IPP, mDNS, or UPnP) acting as a client or server at one IP address, transport protocol, and port. Services are identified by sensors that probe a device's [OpenPort](https://wartiva.com/api-docs/types/open-port.html) objects and listen to its discovery traffic, run from managed endpoints on the local network or from Wartiva's servers. Each service carries a protocol-specific [ServiceReport](https://wartiva.com/api-docs/types/service-report.html), its up-time history (including when it was reachable from the public Internet), and the CPE product identifiers and matching CVEs found for the software it runs.

## Fields

| Field Name | Description |
|---|---|
| `id` - [`ID!`](https://wartiva.com/api-docs/types/id.html) | Unique identifier for this graph object. |
| `orgId` - [`OrganizationId!`](https://wartiva.com/api-docs/types/organization-id.html) | Unique identifier for the owning organization. |
| `objectType` - [`GraphObjectType!`](https://wartiva.com/api-docs/types/graph-object-type.html) | The type of this graph object. |
| `objectTypeLabel` - [`String!`](https://wartiva.com/api-docs/types/string.html) | A localized label describing the object type. |
| `displayName` - [`String!`](https://wartiva.com/api-docs/types/string.html) | A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object. |
| `firstSeen` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | Time this object was first seen. |
| `lastSeen` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | Time this object was last seen. |
| `seen` - [`SeenOnline!`](https://wartiva.com/api-docs/types/seen-online.html) | When this graph object was seen. |
| `createdAt` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | The time this object was created in the security graph. |
| `updatedAt` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | The time this object was last mutated in the security graph. |
| `snapshotInfo` - [`GraphObjectSnapshotInfo!`](https://wartiva.com/api-docs/types/graph-object-snapshot-info.html) | Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed. |
| `device` - [`Device`](https://wartiva.com/api-docs/types/device.html) | The [Device](https://wartiva.com/api-docs/types/device.html) this network service is found on. |
| `network` - [`Network`](https://wartiva.com/api-docs/types/network.html) | The [Network](https://wartiva.com/api-docs/types/network.html) this network service is found on if known. |
| `networkPrefix` - [`NetworkPrefix`](https://wartiva.com/api-docs/types/network-prefix.html) | The [NetworkPrefix](https://wartiva.com/api-docs/types/network-prefix.html) containing the IP this network service is found on if known. |
| `openPort` - [`OpenPort`](https://wartiva.com/api-docs/types/open-port.html) | The [OpenPort](https://wartiva.com/api-docs/types/open-port.html) this network service is found on if available. |
| `public` - [`Boolean!`](https://wartiva.com/api-docs/types/boolean.html) | True if the service is found to be open to the public Internet. |
| `addressFamily` - [`AddressFamily!`](https://wartiva.com/api-docs/types/address-family.html) | Network type where the service was found. |
| `ip` - [`IpAddress`](https://wartiva.com/api-docs/types/ip-address.html) | IP address where the service was found online. |
| `port` - [`Int`](https://wartiva.com/api-docs/types/int.html) | IP port number where the service was found online, an unsigned 16-bit integer. |
| `protocol` - [`IpProtocol`](https://wartiva.com/api-docs/types/ip-protocol.html) | Transport protocol where the service was found online. |
| `serviceType` - [`ServiceType!`](https://wartiva.com/api-docs/types/service-type.html) | Identity of the service running if known e.g.: unknown, http, https, dns, etc. |
| `clientServer` - [`ClientServer!`](https://wartiva.com/api-docs/types/client-server.html) | Identifies the discovered service as either a network client or server. |
| `sensorId` - [`ID!`](https://wartiva.com/api-docs/types/id.html) | The unique identifier of the sensor that last discovered this network service. |
| `sensor` - [`Sensor!`](https://wartiva.com/api-docs/types/sensor.html) | The sensor that last discovered this network service. |
| `sensorVersion` - [`String!`](https://wartiva.com/api-docs/types/string.html) | The version of the sensor that last discovered this network service. |
| `seenUp` - [`SeenUp!`](https://wartiva.com/api-docs/types/seen-up.html) | Describes when this Service was seen up. |
| `seenUpPublic` - [`SeenUp!`](https://wartiva.com/api-docs/types/seen-up.html) | Describes when this Service was seen up to the public Internet. |
| `report` - [`ServiceReport`](https://wartiva.com/api-docs/types/service-report.html) | The service specific data structure describing details of the service. |
| `canResubmitSensorRequests` - [`Boolean!`](https://wartiva.com/api-docs/types/boolean.html) | True if calling mutation sensorRequestReSubmitForService would have re-submitted one or more sensor requests related to this service. |
| `sensorRequestIds` - [`[ID!]`](https://wartiva.com/api-docs/types/id.html) | The associated SensorRequest identifiers if any. If the sensor only runs in the LAN zone this list will be empty. |
| `sensorRequests` - [`[SensorRequest!]`](https://wartiva.com/api-docs/types/sensor-request.html) | The associated SensorRequests if any. If the sensor only runs in the LAN zone this list will be empty. |
| `vulnerabilities` - [`PlatformVulnerabilities`](https://wartiva.com/api-docs/types/platform-vulnerabilities.html) | CPE identifiers determined for the product this service is running and the CVEs they match in the vulnerability catalog. Null when the service's protocol revealed no product identity, or revealed too little of it to match vulnerabilities accurately. See [PlatformVulnerabilities](https://wartiva.com/api-docs/types/platform-vulnerabilities.html). |
| `findings` - [`FindingsPayload!`](https://wartiva.com/api-docs/types/findings-payload.html) | Policy findings for this object. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. |
| `issues` - [`IssuesPayload!`](https://wartiva.com/api-docs/types/issues-payload.html) | Policy issues for this object. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. |
| `issuesSummary` - [`IssuesSummary!`](https://wartiva.com/api-docs/types/issues-summary.html) | Summary of the active policy issues currently open on this object, broken down by severity. |

## Returned by

- [`service`](https://wartiva.com/api-docs/queries/service.html) query: Retrieves a Service by its graph object id: a network service identified on a discovered device, such as HTTP, TLS, SSH, SMB, SNMP, or DNS, in a…

## Used by

- [`Network`](https://wartiva.com/api-docs/types/network.html) type: An IP network (subnet) that a managed Endpoint has been attached to, identified by its address range in CIDR notation and, for networks outside a…
- [`NetworkPrefix`](https://wartiva.com/api-docs/types/network-prefix.html) type: A specific IP address together with its subnet prefix length (e.g.
- [`GraphObjectType`](https://wartiva.com/api-docs/types/graph-object-type.html) enum: An enumeration of the different types of security graph objects.
- [`GraphObjectTypeCategory`](https://wartiva.com/api-docs/types/graph-object-type-category.html) enum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.
- [`RuleApplyToOptionKey`](https://wartiva.com/api-docs/types/rule-apply-to-option-key.html) enum: Attribute keys that further scope which objects a rule applies to, in addition to its applyTo object type.
- [`ServiceConnection`](https://wartiva.com/api-docs/types/service-connection.html) type: Connection for Service edges with total count.
- [`ServiceEdge`](https://wartiva.com/api-docs/types/service-edge.html) type: Edge payload for a Service with optional seen data.
- [`ServicePayload`](https://wartiva.com/api-docs/types/service-payload.html) type: Payload wrapper for a single Service result.
- [`ServiceSummary`](https://wartiva.com/api-docs/types/service-summary.html) type: An abbreviated summary of a network Service.

## Related types

- [`Device`](https://wartiva.com/api-docs/types/device.html) A physical or virtual device that does not run the Wartiva endpoint application but is visible on the network to a managed Endpoint, such as…
- [`Network`](https://wartiva.com/api-docs/types/network.html) An IP network (subnet) that a managed Endpoint has been attached to, identified by its address range in CIDR notation and, for networks outside a…
- [`NetworkPrefix`](https://wartiva.com/api-docs/types/network-prefix.html) A specific IP address together with its subnet prefix length (e.g.
- [`OpenPort`](https://wartiva.com/api-docs/types/open-port.html) One TCP or UDP port at one IP address on a discovered Device, found by managed endpoints port-scanning the devices on their local networks and by…
- [`SensorRequest`](https://wartiva.com/api-docs/types/sensor-request.html) A standing request to run one Sensor against one Device IP address, optionally on a specific protocol and port, in the SAE or PUBLIC zone.

## Example

### Example

```json
{
  "id": 4,
  "orgId": "615f3b3b28284380e28a7342",
  "objectType": "ACCOUNT_POLICY",
  "objectTypeLabel": "abc123",
  "displayName": "abc123",
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z",
  "seen": SeenOnline,
  "createdAt": "2021-10-07T18:23:25.829Z",
  "updatedAt": "2021-10-07T18:23:25.829Z",
  "snapshotInfo": GraphObjectSnapshotInfo,
  "device": Device,
  "network": Network,
  "networkPrefix": NetworkPrefix,
  "openPort": OpenPort,
  "public": true,
  "addressFamily": "AF_UNSPEC",
  "ip": IpAddress,
  "port": 123,
  "protocol": "TCP",
  "serviceType": "UNKNOWN",
  "clientServer": "CLIENT",
  "sensorId": "4",
  "sensor": Sensor,
  "sensorVersion": "abc123",
  "seenUp": SeenUp,
  "seenUpPublic": SeenUp,
  "report": AppSocket,
  "canResubmitSensorRequests": false,
  "sensorRequestIds": [4],
  "sensorRequests": [SensorRequest],
  "vulnerabilities": PlatformVulnerabilities,
  "findings": FindingsPayload,
  "issues": IssuesPayload,
  "issuesSummary": IssuesSummary
}

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
