Modify SCOM Alert Description

Woody1150 1 Reputation point
2021-02-03T22:29:08.463+00:00

Hi,

New to SCOM trying to make some modifications to an alert description from a log event monitor. I have looked at some of the blogs and posts about some of the parameter variables, but still haven't been able to achieve the results I want. I am trying to grab certain fields from within the alert XML data. Since the XML data is not very long I will paste it here:

< DataItem type =" System.XmlData " time =" 2021-02-02T18:21:22.9683726-05:00 " sourceHealthServiceId =" 486239AE-5D94-3C1F-1D1B-0990DD8C43FE " > 
< UserData > 
< CertNotificationData ProcessName =" taskhostw.exe " AccountName =" XXXXXXXXXXXX " Context =" Machine " > 
< CertificateDetails Thumbprint =" c671adc74e2a61e2597664dbee80e3400ea2038b " > 
  < Template Name =" XXXXXXXXXXX " OID =" 1.3.6.1.4.1.311.21.8.15504135.12588515.2314127.10440875.7078001.165.5330265.16365739 " /> 
< SubjectNames > 
  < SubjectName > XXXXXXXXXXXX </ SubjectName > 
  </ SubjectNames > 
< EKUs > 
  < EKU Name =" Server Authentication " OID =" 1.3.6.1.5.5.7.3.1 " /> 
  < EKU OID =" 1.3.6.1.4.1.311.54.1.2 " /> 
  </ EKUs > 
  < NotValidAfter > 2021-02-24T19:52:32Z </ NotValidAfter > 
  </ CertificateDetails > 
  </ CertNotificationData > 
  </ UserData > 
  </ DataItem > 

As I'm sure you can tell it is from certificate events. What I am trying to do is grab the <Template Name> and <NotValidAfter>

Things that I have tried thus far:

  • Adding $Data/Context/EventData/DataItem$ to the event description = This ended up adding the <SubjectName> and <NotValidAfter> in the alert description, so almost there.
  • Adding $Data/Context/EventData/DataItem/UserData/CertNotificationData/CertificateDetails/NotValidAfter$ = this resulted in nothing being added to the alert
  • Adding $Data/Context/EventData/DataItem/UserData/CertNotificationData/CertificateDetails/Template Name$ = this also resulted in nothing being added to the alert description

So I'm not sure why trying to grab all of DataItem picks up some things and leaves out others. My only thought was those 2 have immediate closing tags after them. Or possibly the = in the tags is throwing something off. Trying to point directly to an item only results in nothing being displayed. I could also just have the syntax all wrong.

Any assistance is appreciated.

Operations Manager
Operations Manager
A family of System Center products that provide infrastructure monitoring, help ensure the predictable performance and availability of vital applications, and offer comprehensive monitoring for datacenters and cloud, both private and public.
1,419 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. CyrAz 5,181 Reputation points
    2021-02-04T08:22:47.02+00:00

    At a first glance what you tried seems correct, so I'll have to test it a bit further to see what could wrong. The $/data/Context/blabla syntax is always a mess to get right anyway :D

    But in the meantime, since it looks like you're trying to monitor certificates, have you considered using Raphael Burri's PKI MP? It's great!
    https://github.com/rafabu/SCOM-PKICertificateMP/releases/tag/v1.4.3.0