Public/event.ps1

function Get-CSEventType {
    <#
    .SYNOPSIS
        Lists CloudStack event types.

    .DESCRIPTION
        Wraps the listEventTypes API, returning the set of event type names (such as
        VM.CREATE or VOLUME.DELETE) that can be used to filter Get-CSEvent.

    .EXAMPLE
        Get-CSEventType
        Lists every event type the server can emit.

    .EXAMPLE
        Get-CSEventType | Where-Object { $_.name -like 'VM.*' }
        Finds the VM-related event types.
    #>

    [CmdletBinding()]
    param()
    $response = Invoke-CSApiRequest -Command 'listEventTypes' -Parameters @{}
    if ($response.listeventtypesresponse.eventtype) { return $response.listeventtypesresponse.eventtype }
}

function Get-CSEvent {
    <#
    .SYNOPSIS
        Lists CloudStack events with optional resource, date, and severity filters.

    .DESCRIPTION
        Wraps the listEvents API. Returns audit events, filterable by type, severity,
        owner, affected resource, and time window. DateTime values are sent in UTC.
        Use -Archived to include archived events and -ListAll/-IsRecursive for broader
        admin scope.

    .PARAMETER Account
        Filter by account name. Must be used with -DomainId.

    .PARAMETER Archived
        Include archived events

    .PARAMETER DomainId
        Filter by domain ID

    .PARAMETER Duration
        Only events from the last this-many seconds

    .PARAMETER EndDate
        Only events on or before this date/time

    .PARAMETER EntryTime
        Correlation time (in seconds) for pending/scheduled events

    .PARAMETER Id
        Filter by a single event ID

    .PARAMETER IsRecursive
        With -DomainId, also include subdomains

    .PARAMETER Keyword
        Filter by keyword

    .PARAMETER Level
        Filter by severity: INFO, WARN, or ERROR

    .PARAMETER ListAll
        List every event the caller is allowed to see

    .PARAMETER Page
        Page number of results to return

    .PARAMETER PageSize
        Number of results per page

    .PARAMETER ProjectId
        Filter by project ID

    .PARAMETER ResourceId
        Only events affecting this resource ID

    .PARAMETER ResourceType
        Only events affecting this resource type

    .PARAMETER StartDate
        Only events on or after this date/time

    .PARAMETER StartId
        Return events that follow this event ID (for a related chain)

    .PARAMETER Type
        Filter by event type, for example 'VM.CREATE' (see Get-CSEventType)

    .EXAMPLE
        Get-CSEvent -Type 'VM.CREATE' -Level INFO -StartDate (Get-Date).AddDays(-1)
        Lists VM-create events from the last day.

    .EXAMPLE
        Get-CSEvent -Level ERROR -ListAll -PageSize 50
        Lists the most recent error events across all accounts.
    #>

    [CmdletBinding()]
    param(
        [string]$Account, [switch]$Archived, [string]$DomainId, [int]$Duration,
        [datetime]$EndDate, [datetime]$EntryTime, [string]$Id, [switch]$IsRecursive,
        [string]$Keyword, [ValidateSet('INFO','WARN','ERROR')][string]$Level,
        [switch]$ListAll, [int]$Page, [int]$PageSize, [string]$ProjectId,
        [string]$ResourceId, [string]$ResourceType, [datetime]$StartDate,
        [string]$StartId, [string]$Type
    )
    $apiParams = @{}
    foreach ($key in @('Account','DomainId','Duration','EndDate','EntryTime','Id','Keyword','Level','Page','PageSize','ProjectId','ResourceId','ResourceType','StartDate','StartId','Type')) {
        if ($PSBoundParameters.ContainsKey($key)) {
            $value = Get-Variable -Name $key -ValueOnly
            if ($value -is [datetime]) { $value = $value.ToUniversalTime().ToString('yyyy-MM-ddTHH:mm:sszzz') }
            $apiParams[$key.ToLowerInvariant()] = $value
        }
    }
    if ($Archived) { $apiParams['archived'] = 'true' }
    if ($IsRecursive) { $apiParams['isrecursive'] = 'true' }
    if ($ListAll) { $apiParams['listall'] = 'true' }
    $response = Invoke-CSApiRequest -Command 'listEvents' -Parameters $apiParams
    if ($response.listeventsresponse.event) { return $response.listeventsresponse.event }
}

function Hide-CSEvent {
    <#
    .SYNOPSIS
        Archives CloudStack events matching the supplied filters.

    .DESCRIPTION
        Wraps the archiveEvents API. Archived events are hidden from the default event
        list but retained; show them again with Get-CSEvent -Archived. Supply at least
        one filter. Also available under the alias Archive-CSEvent. DateTime values are
        sent in UTC.

    .PARAMETER Ids
        The specific event IDs to archive

    .PARAMETER StartDate
        Archive events on or after this date/time

    .PARAMETER EndDate
        Archive events on or before this date/time

    .PARAMETER Type
        Archive events of this event type

    .EXAMPLE
        Hide-CSEvent -Ids @('event-uuid-1','event-uuid-2')
        Archives two specific events.

    .EXAMPLE
        Hide-CSEvent -Type 'VM.CREATE' -EndDate (Get-Date).AddMonths(-6)
        Archives VM-create events older than six months.
    #>

    [CmdletBinding(SupportsShouldProcess=$true, ConfirmImpact='High')]
    param([string[]]$Ids, [datetime]$StartDate, [datetime]$EndDate, [string]$Type)
    $apiParams = @{}
    if ($PSBoundParameters.ContainsKey('Ids')) { $apiParams['ids'] = $Ids -join ',' }
    foreach ($key in @('StartDate','EndDate','Type')) { if ($PSBoundParameters.ContainsKey($key)) { $value = Get-Variable -Name $key -ValueOnly; if ($value -is [datetime]) { $value = $value.ToUniversalTime().ToString('yyyy-MM-ddTHH:mm:sszzz') }; $apiParams[$key.ToLowerInvariant()] = $value } }
    if ($apiParams.Count -eq 0) { throw 'Specify at least one event filter (Ids, StartDate, EndDate, or Type).' }
    if ($PSCmdlet.ShouldProcess('matching CloudStack events','Archive')) { Invoke-CSApiRequest -Command 'archiveEvents' -Parameters $apiParams }
}
Set-Alias -Name Archive-CSEvent -Value Hide-CSEvent

function Remove-CSEvent {
    <#
    .SYNOPSIS
        Permanently deletes CloudStack events matching the supplied filters.

    .DESCRIPTION
        Wraps the deleteEvents API. Unlike Hide-CSEvent (archive), this permanently
        removes the matched events. Supply at least one filter. DateTime values are
        sent in UTC.

    .PARAMETER Ids
        The specific event IDs to delete

    .PARAMETER StartDate
        Delete events on or after this date/time

    .PARAMETER EndDate
        Delete events on or before this date/time

    .PARAMETER Type
        Delete events of this event type

    .EXAMPLE
        Remove-CSEvent -Ids @('event-uuid')
        Permanently deletes one event.

    .EXAMPLE
        Remove-CSEvent -EndDate (Get-Date).AddYears(-1) -Confirm:$false
        Permanently deletes every event older than a year.
    #>

    [CmdletBinding(SupportsShouldProcess=$true, ConfirmImpact='High')]
    param([string[]]$Ids, [datetime]$StartDate, [datetime]$EndDate, [string]$Type)
    $apiParams = @{}
    if ($PSBoundParameters.ContainsKey('Ids')) { $apiParams['ids'] = $Ids -join ',' }
    foreach ($key in @('StartDate','EndDate','Type')) { if ($PSBoundParameters.ContainsKey($key)) { $value = Get-Variable -Name $key -ValueOnly; if ($value -is [datetime]) { $value = $value.ToUniversalTime().ToString('yyyy-MM-ddTHH:mm:sszzz') }; $apiParams[$key.ToLowerInvariant()] = $value } }
    if ($apiParams.Count -eq 0) { throw 'Specify at least one event filter (Ids, StartDate, EndDate, or Type).' }
    if ($PSCmdlet.ShouldProcess('matching CloudStack events','Delete permanently')) { Invoke-CSApiRequest -Command 'deleteEvents' -Parameters $apiParams }
}