---
title: SystemService type | Wartiva GraphQL API
description: A background service or daemon configured on an Endpoint. Wartiva GraphQL API reference with arguments, fields, and examples.
url: https://wartiva.com/api-docs/types/system-service.html
updated: 2026-10-07
---

Endpoint configuration · GraphQL type

# `SystemService` type

A background service or daemon configured on an [Endpoint](https://wartiva.com/api-docs/types/endpoint.html). Collected on Windows (Windows services), macOS (launchd jobs) and Linux (systemd services), each records the service's executable path, start type, restart behavior and current state, with platform-specific detail in [SystemServiceWindows](https://wartiva.com/api-docs/types/system-service-windows.html), [SystemServiceMacOS](https://wartiva.com/api-docs/types/system-service-mac-os.html) or [SystemServiceLinux](https://wartiva.com/api-docs/types/system-service-linux.html). An Endpoint has many SystemService objects, one per service label; they are listed by the Endpoint's `systemServices` field, and `systemServicesSeen` returns the history of when each service was observed.

## Fields

| Field Name | Description |
|---|---|
| `id` - [`ID!`](https://wartiva.com/api-docs/types/id.html) | The SystemService's unique identifier on the security graph. |
| `orgId` - [`OrganizationId!`](https://wartiva.com/api-docs/types/organization-id.html) | Unique identifier that corresponds to your deployment of this product or a specific customer account that this Endpoint belongs to. |
| `seen` - [`SeenOnline!`](https://wartiva.com/api-docs/types/seen-online.html) | Describes when this SystemService was seen. |
| `objectType` - [`GraphObjectType!`](https://wartiva.com/api-docs/types/graph-object-type.html) | The type of this graph object. |
| `objectTypeLabel` - [`String!`](https://wartiva.com/api-docs/types/string.html) | A localized label describing the object type. |
| `displayName` - [`String!`](https://wartiva.com/api-docs/types/string.html) | A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object. |
| `firstSeen` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | Time this object was first seen. |
| `lastSeen` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | Time this object was last seen. |
| `createdAt` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | The time this object was created in the security graph. |
| `updatedAt` - [`Time!`](https://wartiva.com/api-docs/types/time.html) | The time this object was last mutated in the security graph. |
| `snapshotInfo` - [`GraphObjectSnapshotInfo!`](https://wartiva.com/api-docs/types/graph-object-snapshot-info.html) | Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed. |
| `endpoint` - [`Endpoint`](https://wartiva.com/api-docs/types/endpoint.html) | The Endpoint this SystemService belongs to if available. |
| `executablePath` - [`String!`](https://wartiva.com/api-docs/types/string.html) | Executable path of the service. |
| `userName` - [`String!`](https://wartiva.com/api-docs/types/string.html) | The user account the service runs as, on macOS and Linux. Empty on Windows and when no account is configured. |
| `startType` - [`ServiceStartType!`](https://wartiva.com/api-docs/types/service-start-type.html) | When or on what trigger the service is started, such as automatically at boot, on demand, or on a schedule. |
| `description` - [`String`](https://wartiva.com/api-docs/types/string.html) | The service's descriptive text as registered with the service manager. Available on Windows and Linux; null on macOS. |
| `restartType` - [`ServiceRestartType!`](https://wartiva.com/api-docs/types/service-restart-type.html) | The restart behavior of the service after it stops. On Linux it reflects the systemd Restart= setting; on macOS it is derived from the launchd KeepAlive setting; on Windows it is derived from the start type. |
| `state` - [`ServiceState!`](https://wartiva.com/api-docs/types/service-state.html) | Current state of the service. |
| `osSpecific` - [`SystemServiceOsSpecific`](https://wartiva.com/api-docs/types/system-service-os-specific.html) | The platform-specific service attributes: [SystemServiceWindows](https://wartiva.com/api-docs/types/system-service-windows.html), [SystemServiceMacOS](https://wartiva.com/api-docs/types/system-service-mac-os.html) or [SystemServiceLinux](https://wartiva.com/api-docs/types/system-service-linux.html). |
| `findings` - [`FindingsPayload!`](https://wartiva.com/api-docs/types/findings-payload.html) | Policy findings for this object. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. |
| `issues` - [`IssuesPayload!`](https://wartiva.com/api-docs/types/issues-payload.html) | Policy issues for this object. |
| Arguments `limit` - [`Int`](https://wartiva.com/api-docs/types/int.html) Maximum number of results to return. `skip` - [`Int`](https://wartiva.com/api-docs/types/int.html) Number of results to skip. |
| `issuesSummary` - [`IssuesSummary!`](https://wartiva.com/api-docs/types/issues-summary.html) | Summary of the active policy issues currently open on this object, broken down by severity. |

## Returned by

- [`systemService`](https://wartiva.com/api-docs/queries/system-service.html) query: Retrieves a SystemService by its graph object id: a background service or daemon configured on an endpoint (a Windows service, macOS launchd job, or…

## Used by

- [`Endpoint`](https://wartiva.com/api-docs/types/endpoint.html) type: A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
- [`GraphObjectType`](https://wartiva.com/api-docs/types/graph-object-type.html) enum: An enumeration of the different types of security graph objects.
- [`GraphObjectTypeCategory`](https://wartiva.com/api-docs/types/graph-object-type-category.html) enum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.
- [`RuleApplyToOptionKey`](https://wartiva.com/api-docs/types/rule-apply-to-option-key.html) enum: Attribute keys that further scope which objects a rule applies to, in addition to its applyTo object type.
- [`SystemServiceConnection`](https://wartiva.com/api-docs/types/system-service-connection.html) type: Collection payload for SystemService edges with total count.
- [`SystemServiceEdge`](https://wartiva.com/api-docs/types/system-service-edge.html) type: Edge payload for a SystemService with optional seen data.
- [`SystemServicePayload`](https://wartiva.com/api-docs/types/system-service-payload.html) type: Payload wrapper for a single SystemService result.

## Related types

- [`Endpoint`](https://wartiva.com/api-docs/types/endpoint.html) A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.

## Example

### Example

```json
{
  "id": 4,
  "orgId": "615f3b3b28284380e28a7342",
  "seen": SeenOnline,
  "objectType": "ACCOUNT_POLICY",
  "objectTypeLabel": "abc123",
  "displayName": "abc123",
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z",
  "createdAt": "2021-10-07T18:23:25.829Z",
  "updatedAt": "2021-10-07T18:23:25.829Z",
  "snapshotInfo": GraphObjectSnapshotInfo,
  "endpoint": Endpoint,
  "executablePath": "xyz789",
  "userName": "abc123",
  "startType": "AUTO_START",
  "description": "xyz789",
  "restartType": "NO",
  "state": "CONTINUE_PENDING",
  "osSpecific": SystemServiceMacOS,
  "findings": FindingsPayload,
  "issues": IssuesPayload,
  "issuesSummary": IssuesSummary
}

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
