Windows Service

win_service

The Windows Service object describes a Windows service.

Attributes

CaptionNameTypeDescription
Command Linecmd_lineStringEntity:COMMAND_LINE

The full command line used to launch the service.
LabelslabelsString[]The list of labels associated with the service.
Load Order Groupload_order_groupStringThe name of the load ordering group of which this service is a member.
NamenameStringThe unique name of the service.
Raw Dataraw_dataJSONGroup:context

The event data as received from the event source.
Record IDrecord_idStringGroup:primary

Unique identifier for the object
Service Categoryservice_categoryStringThe service category, normalized to the caption of the service_category_id value. In the case of 'Other', it is defined by the event source.
Service Category IDservice_category_idIntegerThe normalized identifier of the service category.
  • 0: Unknown (UNKNOWN)
  • 1: Kernel Mode (KERNEL_MODE)
  • 2: User Mode (USER_MODE)
  • 99: Other (OTHER)
Service Dependenciesservice_dependenciesString[]The names of other services upon which this service has a dependency.
Service Error Controlservice_error_controlStringThe service error control, normalized to the caption of the service_error_control_id value. In the case of 'Other', it is defined by the event source.
Service Error Control IDservice_error_control_idIntegerThe normalized identifier of the service error control.
  • 0: Unknown (UNKNOWN)
  • 1: Ignore (IGNORE)
  • 2: Normal (NORMAL)
  • 3: Severe (SEVERE)
  • 4: Critical (CRITICAL)
  • 99: Other (OTHER)
Service Start Nameservice_start_nameStringFor a user mode service, this attribute represents the name of the account under which the service is run. For a kernel mode driver, this attribute represents the object name used to load the driver.
Service Start Typeservice_start_typeStringThe service start type, normalized to the caption of the service_start_type_id value. In the case of 'Other', it is defined by the event source.
Service Start Type IDservice_start_type_idIntegerThe normalized identifier of the service start type.
  • 0: Unknown (UNKNOWN)
  • 1: Boot (BOOT)
  • 2: System (SYSTEM)
  • 3: Auto (AUTO)
  • 4: Demand (DEMAND)
  • 5: Disabled (DISABLED)
  • 99: Other (OTHER)
Service Typeservice_typeStringThe service type, normalized to the caption of the service_type_id value. In the case of 'Other', it is defined by the event source.
Service Type IDservice_type_idIntegerThe normalized identifier of the service type.
  • 0: Unknown (UNKNOWN)
  • 1: Kernel Driver (KERNEL_DRIVER)
  • 2: File System Driver (FILE_SYSTEM_DRIVER)
  • 3: Own Process (OWN_PROCESS)
  • 4: Share Process (SHARE_PROCESS)
  • 99: Other (OTHER)
TagstagsKey:Value object[]The list of tags; key:value pairs associated to the service.
Unique IDuidStringThe unique identifier of the service.
UnmappedunmappedUnmapped[]Data from the source that was not mapped into the schema.
VersionversionStringThe version of the service.

Relationships

Windows Service shown in context

Inbound Relationships

These objects and events reference Windows Service in their attributes:

Outbound Relationships

Windows Service references the following objects and events in its attributes:

This page describes qdm-1.5.1+ocsf-1.6.0


Did this page help you?