<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="https://www.xlayer.co.za/forum/extern.php?action=feed&amp;tid=132&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[SXI Forum / Get SCOM Alerts using PowerShell and the REST API]]></title>
		<link>https://www.xlayer.co.za/forum/viewtopic.php?id=132</link>
		<description><![CDATA[The most recent posts in Get SCOM Alerts using PowerShell and the REST API.]]></description>
		<lastBuildDate>Thu, 22 Apr 2021 15:11:37 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[Get SCOM Alerts using PowerShell and the REST API]]></title>
			<link>https://www.xlayer.co.za/forum/viewtopic.php?pid=210#p210</link>
			<description><![CDATA[<p>To <strong>COLLECT</strong> Alerts from SCOM create a PowerShell script (e.g. GetAlerts.ps1) with the following code:</p><div class="codebox"><pre><code>$scomHeaders = New-Object &quot;System.Collections.Generic.Dictionary[[String],[String]]&quot;
$scomHeaders.Add(&#039;Content-Type&#039;,&#039;application/json; charset=utf-8&#039;)
$bodyraw = &quot;AuthenticationMode:&lt;DOMAIN&gt;\&lt;USERNAME&gt;:&lt;PASSWORD&gt;&quot;
$Bytes = [System.Text.Encoding]::UTF8.GetBytes($bodyraw)
$EncodedText =[Convert]::ToBase64String($Bytes)
$jsonbody = $EncodedText | ConvertTo-Json

$uriBase = &#039;http://&lt;SCOM_SERVER&gt;/OperationsManager/authenticate&#039;
$auth = Invoke-RestMethod -Method POST -Uri $uriBase -Headers $scomheaders -body $jsonbody -UseDefaultCredentials -SessionVariable websession

$query = @{
&quot;classId&quot; = $null;
&quot;objectIds&quot; = $null;
&quot;criteria&quot;= &quot;(((Severity = &#039;1&#039;) or (Severity = &#039;2&#039;)) AND (ResolutionState = &#039;0&#039;))&quot; ;
&quot;displayColumns&quot; = &quot;severity&quot;,&quot;monitoringobjectdisplayname&quot;,&quot;name&quot;,&quot;age&quot;,&quot;repeatcount&quot;,&quot;lastmodified&quot;,&quot;resolutionstate&quot;,&quot;ticketid&quot;
} 

$jsonquery = $query | ConvertTo-Json
$Response = Invoke-WebRequest -Uri &quot;http://&lt;SCOM_SERVER&gt;/OperationsManager/data/alert&quot; -Method Post -Body $jsonquery -ContentType &quot;application/json&quot; -UseDefaultCredentials -WebSession $websession
$alerts = ConvertFrom-Json -InputObject $Response.Content
$alerts.rows | select id,monitoringobjectdisplayname,name,severity,resolutionstate,lastmodified,age,ticketid</code></pre></div><p>You will receive a <em>Response</em> that will look something like this</p><div class="quotebox"><blockquote><div><p>id&#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160;: b506ce29-9bb8-4c93-8be0-6a53dfc68757<br />monitoringobjectdisplayname : demohost01.sxi.local<br />name&#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160;: OleDB: Results Error<br />severity&#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160;: Error<br />resolutionstate&#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160;: New<br />lastmodified&#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160;: 2021-04-22T08:20:41.2000000Z<br />age&#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160;: 6 hours, 46 minutes<br />ticketid&#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; : </p><p>id&#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160;: f1400c42-1699-4e00-95fb-9482418be391<br />monitoringobjectdisplayname : demohost01.sxi.local<br />name&#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160;: System Center Management Health Service Unloaded System Rule(s)<br />severity&#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; : Error<br />resolutionstate&#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; : New<br />lastmodified&#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; : 2021-04-22T07:57:31.3270000Z<br />age&#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; : 7 hours, 9 minutes<br />ticketid&#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160;: </p><p>id&#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160;: f1f3fd94-0a4d-4adc-bab6-960013d52f30<br />monitoringobjectdisplayname : demohost02.sxi.local<br />name&#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160;: OleDB: Results Error<br />severity&#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; : Error<br />resolutionstate&#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; : New<br />lastmodified&#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; : 2021-04-22T08:20:41.2000000Z<br />age&#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; : 6 hours, 46 minutes<br />ticketid&#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160;:</p></div></blockquote></div><p>The <em>$query</em> can be changed to fine-tune what you are collecting.&#160; Here are some starting parameters</p><h5>Severity</h5><div class="codebox"><pre><code>0 - Information
1 - Warning
2 - Error</code></pre></div><h5>Priority</h5><div class="codebox"><pre><code>0 - Low
1 - Medium
2 - High</code></pre></div><h5>ResolutionState</h5><div class="codebox"><pre><code>Acknowledged            = 249
Assigned to Engineering = 248
Awaiting Evidence       = 247
Closed                  = 255
New                     = 0
Resolved                = 254
Scheduled               = 250</code></pre></div>]]></description>
			<author><![CDATA[dummy@example.com (SeanR)]]></author>
			<pubDate>Thu, 22 Apr 2021 15:11:37 +0000</pubDate>
			<guid>https://www.xlayer.co.za/forum/viewtopic.php?pid=210#p210</guid>
		</item>
	</channel>
</rss>
