Public/event.ps1
|
function Get-CSEventType { <# .SYNOPSIS Lists CloudStack event types. .DESCRIPTION Wraps the listEventTypes API, returning the set of event type names (such as VM.CREATE or VOLUME.DELETE) that can be used to filter Get-CSEvent. .EXAMPLE Get-CSEventType Lists every event type the server can emit. .EXAMPLE Get-CSEventType | Where-Object { $_.name -like 'VM.*' } Finds the VM-related event types. #> [CmdletBinding()] param() $response = Invoke-CSApiRequest -Command 'listEventTypes' -Parameters @{} if ($response.listeventtypesresponse.eventtype) { return $response.listeventtypesresponse.eventtype } } function Get-CSEvent { <# .SYNOPSIS Lists CloudStack events with optional resource, date, and severity filters. .DESCRIPTION Wraps the listEvents API. Returns audit events, filterable by type, severity, owner, affected resource, and time window. DateTime values are sent in UTC. Use -Archived to include archived events and -ListAll/-IsRecursive for broader admin scope. .PARAMETER Account Filter by account name. Must be used with -DomainId. .PARAMETER Archived Include archived events .PARAMETER DomainId Filter by domain ID .PARAMETER Duration Only events from the last this-many seconds .PARAMETER EndDate Only events on or before this date/time .PARAMETER EntryTime Correlation time (in seconds) for pending/scheduled events .PARAMETER Id Filter by a single event ID .PARAMETER IsRecursive With -DomainId, also include subdomains .PARAMETER Keyword Filter by keyword .PARAMETER Level Filter by severity: INFO, WARN, or ERROR .PARAMETER ListAll List every event the caller is allowed to see .PARAMETER Page Page number of results to return .PARAMETER PageSize Number of results per page .PARAMETER ProjectId Filter by project ID .PARAMETER ResourceId Only events affecting this resource ID .PARAMETER ResourceType Only events affecting this resource type .PARAMETER StartDate Only events on or after this date/time .PARAMETER StartId Return events that follow this event ID (for a related chain) .PARAMETER Type Filter by event type, for example 'VM.CREATE' (see Get-CSEventType) .EXAMPLE Get-CSEvent -Type 'VM.CREATE' -Level INFO -StartDate (Get-Date).AddDays(-1) Lists VM-create events from the last day. .EXAMPLE Get-CSEvent -Level ERROR -ListAll -PageSize 50 Lists the most recent error events across all accounts. #> [CmdletBinding()] param( [string]$Account, [switch]$Archived, [string]$DomainId, [int]$Duration, [datetime]$EndDate, [datetime]$EntryTime, [string]$Id, [switch]$IsRecursive, [string]$Keyword, [ValidateSet('INFO','WARN','ERROR')][string]$Level, [switch]$ListAll, [int]$Page, [int]$PageSize, [string]$ProjectId, [string]$ResourceId, [string]$ResourceType, [datetime]$StartDate, [string]$StartId, [string]$Type ) $apiParams = @{} foreach ($key in @('Account','DomainId','Duration','EndDate','EntryTime','Id','Keyword','Level','Page','PageSize','ProjectId','ResourceId','ResourceType','StartDate','StartId','Type')) { if ($PSBoundParameters.ContainsKey($key)) { $value = Get-Variable -Name $key -ValueOnly if ($value -is [datetime]) { $value = $value.ToUniversalTime().ToString('yyyy-MM-ddTHH:mm:sszzz') } $apiParams[$key.ToLowerInvariant()] = $value } } if ($Archived) { $apiParams['archived'] = 'true' } if ($IsRecursive) { $apiParams['isrecursive'] = 'true' } if ($ListAll) { $apiParams['listall'] = 'true' } $response = Invoke-CSApiRequest -Command 'listEvents' -Parameters $apiParams if ($response.listeventsresponse.event) { return $response.listeventsresponse.event } } function Hide-CSEvent { <# .SYNOPSIS Archives CloudStack events matching the supplied filters. .DESCRIPTION Wraps the archiveEvents API. Archived events are hidden from the default event list but retained; show them again with Get-CSEvent -Archived. Supply at least one filter. Also available under the alias Archive-CSEvent. DateTime values are sent in UTC. .PARAMETER Ids The specific event IDs to archive .PARAMETER StartDate Archive events on or after this date/time .PARAMETER EndDate Archive events on or before this date/time .PARAMETER Type Archive events of this event type .EXAMPLE Hide-CSEvent -Ids @('event-uuid-1','event-uuid-2') Archives two specific events. .EXAMPLE Hide-CSEvent -Type 'VM.CREATE' -EndDate (Get-Date).AddMonths(-6) Archives VM-create events older than six months. #> [CmdletBinding(SupportsShouldProcess=$true, ConfirmImpact='High')] param([string[]]$Ids, [datetime]$StartDate, [datetime]$EndDate, [string]$Type) $apiParams = @{} if ($PSBoundParameters.ContainsKey('Ids')) { $apiParams['ids'] = $Ids -join ',' } foreach ($key in @('StartDate','EndDate','Type')) { if ($PSBoundParameters.ContainsKey($key)) { $value = Get-Variable -Name $key -ValueOnly; if ($value -is [datetime]) { $value = $value.ToUniversalTime().ToString('yyyy-MM-ddTHH:mm:sszzz') }; $apiParams[$key.ToLowerInvariant()] = $value } } if ($apiParams.Count -eq 0) { throw 'Specify at least one event filter (Ids, StartDate, EndDate, or Type).' } if ($PSCmdlet.ShouldProcess('matching CloudStack events','Archive')) { Invoke-CSApiRequest -Command 'archiveEvents' -Parameters $apiParams } } Set-Alias -Name Archive-CSEvent -Value Hide-CSEvent function Remove-CSEvent { <# .SYNOPSIS Permanently deletes CloudStack events matching the supplied filters. .DESCRIPTION Wraps the deleteEvents API. Unlike Hide-CSEvent (archive), this permanently removes the matched events. Supply at least one filter. DateTime values are sent in UTC. .PARAMETER Ids The specific event IDs to delete .PARAMETER StartDate Delete events on or after this date/time .PARAMETER EndDate Delete events on or before this date/time .PARAMETER Type Delete events of this event type .EXAMPLE Remove-CSEvent -Ids @('event-uuid') Permanently deletes one event. .EXAMPLE Remove-CSEvent -EndDate (Get-Date).AddYears(-1) -Confirm:$false Permanently deletes every event older than a year. #> [CmdletBinding(SupportsShouldProcess=$true, ConfirmImpact='High')] param([string[]]$Ids, [datetime]$StartDate, [datetime]$EndDate, [string]$Type) $apiParams = @{} if ($PSBoundParameters.ContainsKey('Ids')) { $apiParams['ids'] = $Ids -join ',' } foreach ($key in @('StartDate','EndDate','Type')) { if ($PSBoundParameters.ContainsKey($key)) { $value = Get-Variable -Name $key -ValueOnly; if ($value -is [datetime]) { $value = $value.ToUniversalTime().ToString('yyyy-MM-ddTHH:mm:sszzz') }; $apiParams[$key.ToLowerInvariant()] = $value } } if ($apiParams.Count -eq 0) { throw 'Specify at least one event filter (Ids, StartDate, EndDate, or Type).' } if ($PSCmdlet.ShouldProcess('matching CloudStack events','Delete permanently')) { Invoke-CSApiRequest -Command 'deleteEvents' -Parameters $apiParams } } |