Endpoint configuration · GraphQL type

SystemService type

A background service or daemon configured on an Endpoint. Collected on Windows (Windows services), macOS (launchd jobs) and Linux (systemd services), each records the service's executable path, start type, restart behavior and current state, with platform-specific detail in SystemServiceWindows, SystemServiceMacOS or SystemServiceLinux. An Endpoint has many SystemService objects, one per service label; they are listed by the Endpoint's systemServices field, and systemServicesSeen returns the history of when each service was observed.

Fields

Field Name Description
id - ID! The SystemService's unique identifier on the security graph.
orgId - OrganizationId! Unique identifier that corresponds to your deployment of this product or a specific customer account that this Endpoint belongs to.
seen - SeenOnline! Describes when this SystemService was seen.
objectType - GraphObjectType! The type of this graph object.
objectTypeLabel - String! A localized label describing the object type.
displayName - String! A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object.
firstSeen - Time! Time this object was first seen.
lastSeen - Time! Time this object was last seen.
createdAt - Time! The time this object was created in the security graph.
updatedAt - Time! The time this object was last mutated in the security graph.
snapshotInfo - GraphObjectSnapshotInfo! Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed.
endpoint - Endpoint The Endpoint this SystemService belongs to if available.
executablePath - String! Executable path of the service.
userName - String! The user account the service runs as, on macOS and Linux. Empty on Windows and when no account is configured.
startType - ServiceStartType! When or on what trigger the service is started, such as automatically at boot, on demand, or on a schedule.
description - String The service's descriptive text as registered with the service manager. Available on Windows and Linux; null on macOS.
restartType - ServiceRestartType! The restart behavior of the service after it stops. On Linux it reflects the systemd Restart= setting; on macOS it is derived from the launchd KeepAlive setting; on Windows it is derived from the start type.
state - ServiceState! Current state of the service.
osSpecific - SystemServiceOsSpecific The platform-specific service attributes: SystemServiceWindows, SystemServiceMacOS or SystemServiceLinux.
findings - FindingsPayload! Policy findings for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issues - IssuesPayload! Policy issues for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issuesSummary - IssuesSummary! Summary of the active policy issues currently open on this object, broken down by severity.

Returned by

  • systemService query: Retrieves a SystemService by its graph object id: a background service or daemon configured on an endpoint (a Windows service, macOS launchd job, or…

Used by

  • Endpoint type: A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
  • GraphObjectType enum: An enumeration of the different types of security graph objects.
  • GraphObjectTypeCategory enum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.
  • RuleApplyToOptionKey enum: Attribute keys that further scope which objects a rule applies to, in addition to its applyTo object type.
  • SystemServiceConnection type: Collection payload for SystemService edges with total count.
  • SystemServiceEdge type: Edge payload for a SystemService with optional seen data.
  • SystemServicePayload type: Payload wrapper for a single SystemService result.

Related types

  • Endpoint A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.

Example

Example

{
  "id": 4,
  "orgId": "615f3b3b28284380e28a7342",
  "seen": SeenOnline,
  "objectType": "ACCOUNT_POLICY",
  "objectTypeLabel": "abc123",
  "displayName": "abc123",
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z",
  "createdAt": "2021-10-07T18:23:25.829Z",
  "updatedAt": "2021-10-07T18:23:25.829Z",
  "snapshotInfo": GraphObjectSnapshotInfo,
  "endpoint": Endpoint,
  "executablePath": "xyz789",
  "userName": "abc123",
  "startType": "AUTO_START",
  "description": "xyz789",
  "restartType": "NO",
  "state": "CONTINUE_PENDING",
  "osSpecific": SystemServiceMacOS,
  "findings": FindingsPayload,
  "issues": IssuesPayload,
  "issuesSummary": IssuesSummary
}