Integrations
Microsoft SCOM
Overview
This document provides a detailed guide to integrating Microsoft System Center Operations Manager (SCOM) with Callgoose SQIBS for real-time Incident Management, Incident Auto Remediation, Event-Driven Automation, and other Automation purposes. The integration enables automatic creation, updating, and resolution of incidents in Callgoose SQIBS based on alerts triggered in Microsoft SCOM. The guide includes steps for setting up alerts in SCOM, configuring webhook notifications, creating API filters in Callgoose SQIBS, and troubleshooting.
Prerequisites
- Microsoft SCOM Account: Access to Microsoft System Center Operations Manager for creating alerts and managing notifications.
- Callgoose SQIBS Account: With valid privileges to set up API filters and receive notifications.
- Webhook/API Endpoint: Available in Callgoose SQIBS to receive alerts from Microsoft SCOM.
1. Obtain API Token and Endpoint Details
To integrate with Callgoose SQIBS, you first need to obtain an API token and find the API endpoint details.
i.Generate an API Token:
- Follow the guide on How to Create API Token in Callgoose SQIBS.
ii.Find the API Endpoint:
- Refer to the Callgoose SQIBS API Endpoint Documentation to get the endpoint details where the JSON payloads from Microsoft SCOM will be sent.
2. Debugging and Troubleshooting
You can enable debugging in the API tokens used with Microsoft SCOM notifications for troubleshooting purposes.
- Enable Debugging:
- You can update the debug value when adding or updating an API token.
- When API tracking is enabled, logs are stored in the API log section for your review. The debugging option will automatically disable after 48 hours.
- When API tracking is turned off, no logs are saved in the API log.
- Using API Log for Troubleshooting:
- The API log provides detailed information on all API calls made to Callgoose SQIBS.
- You can check the JSON values in each API log entry for troubleshooting purposes.
- Use the information in the API log to create or refine API filters to ensure incidents are created correctly based on the API payloads received.
- Callgoose SQIBS creates incidents according to your API filter configuration, giving you full control over how alerts from different services trigger incidents and alerts for your support team or automation processes.
3. Configuring Microsoft SCOM to Send JSON Payloads
To configure Microsoft SCOM to generate the JSON payloads similar to the examples provided, follow the steps outlined below. These steps will guide you through setting up the necessary alerts and webhook notifications within SCOM to ensure that the JSON payloads match those expected by Callgoose SQIBS.
3.1 Setting Up Alerts in Microsoft SCOM
To generate the required JSON payloads, you first need to set up alerts within Microsoft SCOM.
i.Log in to the Microsoft SCOM Console:
- Access the Microsoft System Center Operations Manager platform using your account credentials.
ii.Navigate to the Alerts Section:
- In the SCOM console, go to Authoring > Monitors > Create a New Monitor.
iii.Create a New Alert:
- Click on Create Alert to configure a new alert rule.
- Specify Alert Conditions: Define the conditions that will trigger the alert, such as specific metrics, health states, or threshold breaches.
iv.Configure the Notification Method:
- Choose Webhook as the notification method to send data to a webhook.
- Webhook URL: Enter the webhook URL provided by Callgoose SQIBS.
3.2 Configuring the Webhook Notification
To ensure that the JSON payload sent matches the examples provided, follow these steps when configuring the webhook:
i.Add Webhook URL:
- In the Webhook URL field, enter the endpoint provided by Callgoose SQIBS.
- Ensure the protocol is HTTPS for secure data transmission.
ii.Customize Payload Format:
- Ensure that the payload includes key fields like "alertName", "status", "message", "severity", "timestamp", "alertId", and others as shown in the example payloads.
- Example Payload Setup:
json { "alertName": "$alertName", "status": "$status", "message": "$message", "severity": "$severity", "timestamp": "$timestamp", "alertId": "$alertId" }
- Placeholder Explanation:
- "$alertName": Replaces with the name of the alert.
- "$status": Replaces with the current status of the alert.
- "$message": Replaces with the alert message.
- "$severity": Replaces with the severity level of the alert.
- "$timestamp": Replaces with the date and time of the alert.
- "$alertId": Replaces with a unique ID for the alert.
iii.Test the Webhook Configuration:
- Before activating the webhook, perform a test to ensure that the JSON payload is correctly formatted and is being sent to the Callgoose SQIBS API endpoint as expected.
- Review the payload in Callgoose SQIBS to confirm that it matches the expected structure.
3.3 Finalizing and Testing
i.Save and Activate the Alert:
- Once the alert and webhook are correctly configured, save the alert configuration and activate it.
ii.Validate the Integration:
- Trigger the alert condition manually if possible to verify that the correct JSON payload is sent to Callgoose SQIBS.
- Resolve the alert to ensure the resolved state payload is also correctly sent and processed.
3.4 Additional Considerations
- Permissions: Ensure that the webhook has the necessary permissions to send alerts to the Callgoose SQIBS API endpoint.
- Security: Implement security measures such as HTTPS and API tokens to protect the data being transmitted between Microsoft SCOM and Callgoose SQIBS.
- Logging and Debugging: Use the debugging and logging features in Callgoose SQIBS to monitor incoming payloads and troubleshoot any issues with the integration.
4. Configuring Callgoose SQIBS
4.1 Create API Filters in Callgoose SQIBS
- To correctly map incidents from the Microsoft SCOM alerts, you need to create API filters based on the JSON payloads received.
4.1.1 Example JSON Payloads from Microsoft SCOM
Alert Triggered (status: "New")
json { "alertName": "High CPU Usage", "status": "New", "message": "CPU usage exceeded threshold on server1", "severity": "Critical", "timestamp": "2024-08-05T12:00:00.000Z", "alertId": "scom123" }
Alert Resolved (status: "Closed")
json { "alertName": "High CPU Usage", "status": "Closed", "message": "CPU usage returned to normal on server1", "severity": "Critical", "timestamp": "2024-08-05T12:30:00.000Z", "alertId": "scom123" }
4.2.2 Manually Add/Edit the Filter
There are two filters that you can manually edit: Trigger and Resolve.
- Trigger Filter (For Creating Incidents):
- Payload JSON Key: "status"
- Key Value Contains: [New]
- Map Incident With: "alertId"
- This corresponds to the unique alertId from the Microsoft SCOM payload.
- Incident Title From: "alertName"
- This will use the alert name as the incident title in Callgoose SQIBS.
- Incident Description From: Leave this empty unless you want to use a specific key-value from the JSON payload. If a key is entered, only the value for that key will be used as the Incident Description instead of the full JSON. By default, the Incident Description will include the full JSON values.
- Example: If you use the "message" key in the Incident Description From field, the incident description will be the value of the "message" key. In the example JSON payload provided earlier, this would result in a description like "CPU usage exceeded threshold on server1".
- Resolve Filter (For Resolving Incidents):
- Payload JSON Key: "status"
- Key Value Contains: [Closed]
- Incident Mapped With: "alertId"
- This ensures the incident tied to the specific alertId is resolved when the alert status returns to Closed.
Refer to the API Filter Instructions and FAQ for more details.
4.3 Finalizing Setup
i.Save the API Filters:
- Ensure that the filters are correctly configured and saved in Callgoose SQIBS.
- Double-check that all key mappings, incident titles, and descriptions are correctly aligned with the payload structure sent by Microsoft SCOM.
ii.Test the Integration:
- Manually trigger an alert in Microsoft SCOM to test if incidents are created in Callgoose SQIBS.
- Verify that the incident appears in Callgoose SQIBS with the correct title, description, and mapped values.
- Resolve the alert in Microsoft SCOM and ensure that the corresponding incident in Callgoose SQIBS is marked as resolved.
5. Testing and Validation
5.1 Triggering Alerts
- Simulate a Monitoring Alert:
- Trigger a condition in Microsoft SCOM that causes an alert (e.g., high CPU usage or a specific threshold breach).
- Verify that an incident is created in Callgoose SQIBS with the correct information.
5.2 Resolving Alerts
- Acknowledge and Resolve the Alert:
- Once the issue is resolved in Microsoft SCOM (e.g., CPU usage returns to normal), verify that the incident in Callgoose SQIBS is automatically marked as resolved.
6. Security Considerations
- API Security: Ensure that the Callgoose SQIBS API endpoint is correctly configured and that the API token is securely stored and used.
- Microsoft SCOM Permissions: Confirm that the webhook in Microsoft SCOM has appropriate permissions to send alerts and data to Callgoose SQIBS.
- Data Encryption: Ensure that the transmission of data between Microsoft SCOM and Callgoose SQIBS is encrypted, especially if sensitive information is involved.
7. Troubleshooting
- No Incident Created: If no incident is created, verify that the webhook URL in Microsoft SCOM is correct and that the JSON payload structure matches the API filters configured in Callgoose SQIBS.
- Incident Not Resolved: Ensure that the resolve filter in Callgoose SQIBS is correctly configured and that the JSON payload sent by Microsoft SCOM matches the expected structure.
8. Conclusion
This guide provides a comprehensive overview of how to integrate Microsoft System Center Operations Manager (SCOM) with Callgoose SQIBS for effective incident management. By following the steps outlined, you can ensure that alerts from Microsoft SCOM are automatically reflected as incidents in Callgoose SQIBS, with proper resolution tracking when the issues are resolved.
For further customization or advanced use cases, refer to the official documentation for both Microsoft SCOM and Callgoose SQIBS:
- Microsoft SCOM Documentation
- Callgoose SQIBS API Token Documentation
- Callgoose SQIBS API Endpoint Documentation
- API Filter Instructions and FAQ
- How to Send API
This documentation will guide you through the integration process, ensuring that your incidents are managed effectively within Callgoose SQIBS based on real-time alerts from Microsoft SCOM.