Microsoft SCOM (Service Center Operations Manager) integration
This integration ingests notifications from Microsoft Service Center Operations Manager (SCOM) and maps them to APEX AIOps Incident Management events automatically.
Before you begin
This integration was validated with Service Center Operations Manager 2019 on July 29, 2024.
Before you start to set up your integration, make sure
You have an active SCOM account.
You have the necessary permissions to create alerts and notifications channels in SCOM.
SCOM can make requests to external endpoints over port 443. This is the default.
You have downloaded the Send Alerts to Moogsoft script.
NOTE: Right-click the link and select "Save Link As" from the menu to download the file. Save the file as sendAlertsToMoogsoft.ps1.
You have created an API key and have access to a copy of it.
Create a new integration in Incident Management
Log in to your Incident Management instance.
Choose Integrations > Ingestion Services > Microsoft SCOM.
Click Add New Integration.
The UI displays the integration in a new page. Click Save.
The new integration includes a custom endpoint, a set of default mappings to convert Microsoft SCOM data to Incident Management events, and a deduplication key to group similar events into alerts. You can now set up Microsoft SCOM to send data to this endpoint, as described in the following section.
(Optional) Once your endpoint starts receiving data from Microsoft SCOM, you can customize how the integration maps and deduplicates this data. To learn more about mapping and deduplication, read Use mapping types in custom integrations and Deduplicate events to reduce noise.
Edit the Send Alerts to Moogsoft script
To prepare the Send Alerts to Moogsoft Script, do the following.
Using a text editor (like Notepad), open the
sendAlertsToMoogsoft.ps1
script file you downloaded (see previous section for download information).Replace $ApiURL with the Endpoint URL located under Integrations > Ingestion Services > Microsoft SCOM> <your-integration-name>.
Replace $ApiKey with your API key.
Save the script file to C:\Moogsoft.
Set up notifications in SCOM
To set up a new notification in SCOM, do the following:
Log in to SCOM.
Go to the Administration section.
Go to Notifications > Channels.
Click New > Command.
For Channel Name, enter Moogsoft Notification and then click Next.
Enter the following values:
Full path of command file: C:\Windows\System32\windowspowershell\v1.0\powershell.exe
Command line parameters::
"c:\Moogsoft\sendAlertsToMoogsoft.ps1" '$Data[Default='Not Present']/Context/DataItem/ManagedEntityPath$ \ $Data[Default='Not Present']/Context/DataItem/ManagedEntityDisplayName$' '$Data/Context/DataItem/AlertName$' '$Data[Default='Not Present']/Context/DataItem/AlertDescription$' '$Data[Default='Not Present']/Context/DataItem/Severity$' '$Data[Default='Not Present']/Context/DataItem/Category$' '$Data[Default='Not Present']/Context/DataItem/LastModifiedLocal$' '$Data[Default='Not Present']/Context/DataItem/AlertId$' '$Data[Default='Not Present']/Context/DataItem/ResolutionStateName$'
Startup folder for the command line: C:\Windows\System32\windowspowershell\v1.0\
Click Finish, then click Close.
Set up subscriber in SCOM
Go to the Administration section.
Go to Notifications > Subscribers.
Click New.
For Subscriber Name, enter "Moogsoft Subscriber" and click Next.
Set the schedule according to your requirements and click Next.
Click Add.
On the Describe the Subscriber Address page, provide the name as "Moogsoft subscriber address" and click Next.
On the Provide the Channel and Delivery Address page, do the following:
In Channel Type, select "Command" as the method of notification.
In Command Channel, select the name of the command channel ("Moogsoft Notification") that was created in the previous section.
Click Next.
On the Schedule Notifications page, do the following:
Select either "Always send notifications," or "Notify only during the specified times."
(Optional) If you selected "Notify only during the specified times," click Add and create a date range.
Click Finish.
Click Finish, then click Close.
Set up subscriptions in SCOM
To set up a new subscription in SCOM, do the following:
Go to the Administration section.
Click Subscriptions.
Click New.
For Subscription Name, enter Moogsoft Notification and then click Next.
Set Scope based on your business use case and then click Next.
Set Criteria based on your business use case and then click Next.
Under the Subscribers section, click Add and add the subscriber you created earlier ("Moogsoft Subscriber"). Then click Next.
In the Channels section, click Add.
Select Moogsoft Notification from the list of available channels.
Click Add, then click OK.
Select "Alert Aging" according to your business use case, then click Next.
On the Summary page, check "Enable this notification subscription."
Click Finish, then click Close.
You have now configured Service Center Operations Manager (SCOM) to notify Incident Management when new alerts are created.