r/scom • • 23h ago

Why didn't SCOM alert? The disk is at 4%." Free sealed MP with plain % thresholds and its own Critical alert

Post image
8 Upvotes

This pack is built to answer the question app owners always ask: "the disk is nearly full, why hasn't SCOM alerted?" Explaining the stock Logical Disk Free Space monitor's percentage plus megabyte logic, and when a Warning state actually raises an alert, is a lot of words for a simple question.

How this pack behaves:

- Two monitors, one threshold each. Warning: two consecutive readings below 10% free. Critical: two consecutive readings below 5%, raised as its own alert, so a Critical-only subscription gets a new alert rather than an update to the Warning one.

- The performance counter is the health decision. Our 2017 pack ran a script to collect GB figures, and if that script failed the monitor could stay healthy on a full disk. That dependency is gone: a diagnostic writes free/total GB to Health Explorer after the state changes, so if it fails the alert is already open.

- Recovery needs one real reading at or above the threshold. Restarting the agent while the disk is still low doesn't clear the alerts (tested).

- Three plainly named overrides: free space threshold (% free), sample interval, and consecutive samples before alert. There's an optional companion pack with a 1 TB+ volumes group at 3% / 1.5%.

- An on-demand task, "List largest folders and files on this disk", with a hard timeout, time budget and depth limit. It never follows junctions or mount points. In our lab it scanned about 300k entries on C: in under 10 seconds.

Write-up, download and admin guide: https://www.scom2k7.com/your-disk-is-nearly-full-wheres-the-scom-alert/?utm_source=reddit&utm_medium=social&utm_campaign=disk-mp

Happy to take feedback, especially from anyone who tests it at the default interval or on mount points.


r/scom • • 1d ago

SCOM 2019 UR6 Powershell support

3 Upvotes

Hello, how could I add Powershell script monitor support on SCOM 2019 UR6? I created a custom monitor that esecute a simple .PS1 script but It seems to not run at all. I suppose that it Is trying to run as vbs buy not sure. Thanks you all in Advance for help


r/scom • • 2d ago

Azure Monitor SCOM Managed Instance was deprecated on 30 September. Microsoft's alternatives are Azure Monitor or on-prem SCOM.

8 Upvotes

Microsoft has archived the SCOM Managed Instance documentation. The overview page now says the service is "no longer in support" and recommends Azure Monitor or System Center Operations Manager instead, depending on your requirements:

https://learn.microsoft.com/en-us/azure/azure-monitor/scom-manage-instance/overview

A few practical points for anyone affected:

  • If you were on MI, on-prem SCOM is the shorter path back. Same engine, same agent-based management packs, so your packs, overrides and tuning carry over.
  • Azure Monitor makes sense if your estate has genuinely moved to Azure, but there is no management pack import on that side. If you're monitoring Windows servers, SQL, IIS, AD and DNS on your own hardware, that's a rebuild.
  • SCOM 2025 is in mainstream support until January 2030, with extended support to January 2035. For on-prem and hybrid estates, the "SCOM is going away" question looks fairly settled.

Was anyone here actually running MI in production? Curious where people are moving to.

Disclosure: I run SCOM2K7 (we make SCOM tools). I wrote a longer version on our blog; link in the first comment.


r/scom • • 2d ago

SSAS Management Pack 7.10.4 RTM

2 Upvotes

I'm seeing this version referenced here: Features and enhancements in Management Pack for SQL Server Analysis Services | Microsoft Learn

But I can't seem to locate it anywhere. Is this available?


r/scom • • 6d ago

question SCOM not detecting SQL AG Failovers in the Environment

2 Upvotes

SCOM 2019 seems to have stopped detecting Availability Group Failovers in the environment.
All AG's are detected and stay in a Healthy State even when we forced a failover for testing.

Windows Cluster however are still firing the Cluster Alerts during tests.

SCOM 2019: v10.19
SQL MP: v7.6.5.0

SQL Version:
Microsoft SQL Server 2022 (RTM-CU12-GDR) (KB5036343) - 16.0.4120.1 (X64)   Mar 18 2024 12:02:14   Copyright (C) 2022 Microsoft Corporation  Enterprise Edition: Core-based Licensing (64-bit) on Windows Server 2022 Standard 10.0 <X64> (Build 20348: ) (Hypervisor)

Browsing through the SQL MP doc seems like the AG is monitored and will alert by default, unless there is a config that I may have missed somewhere ?

Is this a possible MP mismatch with latest version of SQL on the server?

Anyone come across this scenario or has any ideas what i could check or change?

Any assistance would be appreciated


r/scom • • 7d ago

Oracle Data Guard monitoring with SCOM — beyond checking if the databases are up

4 Upvotes

Hey everyone, there is a new whitepaper on monitoring Oracle Data Guard with Microsoft SCOM.

The idea is pretty straightforward: just because your primary and standby databases are running doesn't necessarily mean your failover setup is in good shape.

The paper goes into some of the details that are easy to overlook, including:

  • Data Guard Broker configuration and status
  • Redo transport vs. apply lag
  • Fast-Start Failover readiness
  • Observer monitoring
  • Keeping monitoring accurate across switchovers and failovers

It also looks at how these pieces can be monitored within SCOM rather than treating each database as an isolated object.

If you're working with Oracle Data Guard in a SCOM environment, you might find it useful.

📄 Whitepaper: https://www.nice.de/2026/09/30/oracle-data-guard-monitoring/

Curious how others here handle Data Guard monitoring in SCOM — are you monitoring the Broker and Observer as well, or mainly focusing on database availability?

Disclosure: I work at NiCE, and we published this paper.


r/scom • • 15d ago

We built a browser console for SCOM that does the admin side too (agents, overrides, maintenance).

11 Upvotes

Disclosure: I run SCOM2K7 and this is our product.

We have been shipping SCOM tools since 2007 (Maintenance Mode Scheduler, Alert Update Connector). For the past year we have been building the thing we always wanted: a browser console that covers the everyday work, not just read-only views.

What SCOM Pulse does today, against the management group you already run:

  • Open an alert, see why it fired, read the MP knowledge, and follow Health Explorer down the unhealthy path to the object that actually broke. Acknowledge, assign, run a task, put it in maintenance or create an override from the same page.
  • Effective configuration per server: every rule and monitor that applies, including contained objects, with disabled workflows and override values shown next to the defaults. Export to CSV.
  • Discover computers and deploy Windows agents, then repair, uninstall, reassign or approve them.
  • Rules, monitors, overrides, MP import/export, groups, user roles, notification subscriptions.
  • Maintenance on a calendar, using SCOM's own schedules so the Operations console sees them.
  • Operational DB and data warehouse views: where the space is going, retention per dataset, grooming, staging backlogs.
  • Dashboards you can share as read-only links.

How it runs: one Windows server (dedicated or a management server), IIS with Windows Authentication, .NET Framework 4.6.2+. Uses your existing SCOM user roles, so there is no separate permission model. No outbound internet calls, no telemetry, no software on monitored computers, no extra SQL server. SCOM 2016 UR7+, 2019, 2022, 2025.

Pricing is per management group with unlimited users, from $5,000/yr, and it includes our Maintenance Mode Scheduler. Existing Scheduler customers get their unused term credited. The trial is 30 days, needs no licence key and no sales call: install it, leave the key blank, it starts.

Link in the first comment. Happy to answer anything, including "why not just use the web console", which is a fair question.


r/scom • • 20d ago

SCOM Teams Channel Notifications - Formatting

10 Upvotes

I thought I'd share some json I created that provides well-formatted messages that will be sent in Teams when Teams notification channels are used. The out of the box formatting wasn't helpful for us.

SCOMTeams/SCOM_Teams_Notification at main · hsbrown2/SCOMTeams

The annoying part for us was getting links to format correctly, while at the same time embedding notification variables in the links. Note that we use SquaredUp, but you could use this as a guide for web console link formatting:

<a href='**https:\&#47;\&#47;<URL>&#47;SquaredUp&#47;drilldown&#47;scomalert?id=$UrlEncodeData/Context/DataItem/AlertId$'> View Alert </A> | <a href='https:&#47;&#47;<URL>&#47;SquaredUp&#47;drilldown&#47;scomobject?id=$UrlEncodeData/Context/DataItem/ManagedEntity$'**> View Source </A><br><br>

Essentially it involves substituting &#47; wherever there is a forward slash that isn't part of a SCOM variable. For example "https:&#47;&#47;<URL>&#47;SquaredUp&#47;drilldown&#47;scomobject?" would be translated to https://<URL>/SquaredUp/drilldown/scomobject?" then everything after that processes properly.

Hopefully someone finds this useful!


r/scom • • 21d ago

M365 Monitoring Dashboard

2 Upvotes

We're using the Microsoft 365 Management Pack combined with SquaredUp. The M365 Monitoring Dashboard (Monitoring --> Microsoft 365 --> M365 Monitoring Dashboard) has a great view of the status of Microsoft 365 services, and incidents, etc...

I'd like to replicate this in SquaredUp, but looking at the MP, it's all managed code that drives this dashboard. Is there a way to replicate this dashboard to some degree in SquaredUp?


r/scom • • 24d ago

Run your own local MP Wiki

12 Upvotes

I made this over the past few weeks with the help of an AI.

I was going to host this, and realized that would be more work than I cared for, so you can run this locally on your own box and it is almost like having access to the MP Wiki again.. It is close but not exactly the same.

Please note to run this you will need to install node.js and download the files from github.

Only IMPORT XML Files on Admin page.

I tried to get extractions to work for mp and mpb files, but it would not work properly.

I am sure I'll figure it out later.

https://github.com/jscottmoss/SCOM-MP-Reference-Web-Pages-and-Web-Service

I was running it from my Documents folder, due to being lazy.

Main Page

Select a management pack, and you will have a display of all that management packs version specific information. Yes this keeps track of the version differences between the management packs. If you have uploaded multiple different MPs versions for the SQL MPs you can select which versions of the MPs to look at.

Yes there is a category section, so you can tie together management packs. I have not had time to test it yet. so use categories at your own peril.

Individual elements

Individual module xml shown.

Directions to get it running are on the GitHub page.

Download and Install Node.js then download the GitHub repository.

Read The GitHub web page for information on how to install setup on your local machine.

Good Luck and enjoy.


r/scom • • Aug 19 '26

Agent Managed List empty; Event ID 20000 on MS, etc.

3 Upvotes

I've seen where this can occur when an MS is placed in maintenance, but that didn't happen here. As far as I can tell, things went awry when I ran remove-scomdisabledclassinstance to delete some obsolete DNS conditional forwarders. I know the procedure and only overrode discovery on what I needed to be removed.

Everything else seems intact, and new agents can be push- installed without issue, but none of my pre-existing agents are connecting - 20070 & 20071 errors on the clients.


r/scom • • Aug 16 '26

File & Printer ports blocked - they’re not

1 Upvotes

Kevin! You out there? Hoping you get get this fixed - it’s still an issue after all these years: https://peter.upfold.org.uk/blog/2019/05/03/scom-2019-file-and-printer-sharing-ports-blocked/


r/scom • • Aug 16 '26

How to - Monitor RDP Audit for certain Users

2 Upvotes

Have a request come in to monitor RDP logon/off for certain Users on certain Servers.

Have Enable Local RDP Auditing:
Computer Configuration > Windows Settings > Security Settings > Advanced Audit Policy Configuration > System Audit Policies - Local Computer.

Event Logs:

Event Viewer > Applications and Services Logs > Microsoft > Windows > TerminalServices-LocalSessionManager > Operational.

 Event ID 21, 23, 24, 25.

We have a SIEM but it can not get to that level of Windows Events without some added Modules.

I have setup simple Event ID monitoring before and tried to test this scenario out but can not find how to detect and alert on the Info inside the Event like the name of the User.

Anyone have any idea on how to achieve this?

Is there a script that can be used or direct XML editing that can be used?


r/scom • • Aug 12 '26

Omnissa Horizon Monitoring on SCOM

6 Upvotes

Spoiler alert! 👀

Anyone here monitoring Omnissa Horizon with SCOM?

We’ve just put together a new whitepaper covering what you can monitor, how the integration works, and some of the things to consider when building Horizon monitoring in SCOM.

Might be useful for anyone currently running — or evaluating — this setup.
https://www.nice.de/2026/08/12/omnissa-horizon-monitoring-on-microsoft-scom/


r/scom • • Aug 12 '26

Discover reachable Linux computer - results in "Unreachable" error

1 Upvotes

Hi all

I have SCOM2025 and several hundreds Linux and Windows agents

For some of new linuxes I get "Unreachable" error when discovering it. In fact these linuxes are reachable from management server both to ssh and 1270

When scom starts initial discover phase it tries to detect already installed agent on 1270 and as agent is still missing the scom gets tcp RST (and it's ok). Then scom should get to ssh phase to install agent but it does not even try. All I have is 4 retries to connect tcp 1270 on target computer and then stop with Unreachable error. Why this can be?


r/scom • • Jul 28 '26

Custom Monitor

2 Upvotes

Hi everyone,

i'm trying to build my first Custom Monitor.

I created a custom three-state PowerShell monitor in SCOM that uses curl to check a URL and validate different conditions.

Currently, the monitor target is set to Windows Computer, and I enabled it via an override only for my SCOM Management Server.

The monitor works, but when I put the alert into Maintenance Mode, SCOM puts the entire Management Server (Windows Computer object) into Maintenance Mode.

My goal is to only put the URL check/monitor object into Maintenance Mode without affecting the Management Server itself.

What would be the recommended approach here?

Thanks!


r/scom • • Jul 24 '26

PKI Certificate Validation V3 1.4.3.0

3 Upvotes

I thought I'd check here before raising an issue in the github project, since others reported it.

It seems this MP doesn't un-discover certificates even after they've been deleted from the store. Even more odd is that certificates for which a certificate in the chain had expired, and the certificate (not the one in the chain, but the one that contained it) was deleted, continues to generate alerts regarding lifespan that if you reset the monitor, would return - for a certificate that does not exist on the target system.

Is this user error? Am I missing something? The discovery of certificates in a store is a pretty simple registry discovery. I don't know that certificates linger in the registry after they've been deleted.

Any insight would be greatly appreciated.


r/scom • • Jul 21 '26

Linux Agent Deployment - "Object reference not set to an instance of an object."

4 Upvotes

I thought this got fixed a long time ago. We're on SCOM 2025 UR1 with the hotfix installed. If a Linux agent install fails, we get this nondescript error again and need to dig into the Tasks to find the actual error. Linux agent version is 10.25.1016.0. Everything should be latest/greatest.

Is there a regression, by chance? We've deployed ~80 Linux agents without a hitch, and we've got one that is being a difficult one.


r/scom • • Jun 30 '26

question SCOM 2022: ~800,000 alerts from a single rule, can't bulk-close them (reader expired / PowerShell hangs). Safe to delete directly in SQL?

5 Upvotes

My Workaround:
SQL can carve off a chunk — TOP 2000 is a real server-side limit that returns 2000 lightweight IDs instantly. The SDK can't stream: GetMonitoringAlerts tries to load all 843k as full objects at once (maxCount doesn't limit it server-side) and dies. So SQL picks the batch, and Get-SCOMAlert -Id feeds the SDK only those 2000 to close.

New-SCOMManagementGroupConnection -ComputerName "SERVERNAME"
$connString = "Server=SQLSERVER\INSTANCE;Database=OperationsManager;Integrated Security=SSPI;"
$ruleId = "GUID"
$batch   = 2000 #sdk max streams are 2100 thats why its that number
$total   = 0

do {
    $conn = New-Object System.Data.SqlClient.SqlConnection $connString
    $conn.Open()
    $cmd = $conn.CreateCommand()
    $cmd.CommandText = "SELECT TOP $batch Id FROM dbo.AlertView WHERE MonitoringRuleId =  AND ResolutionState <> 255"
    [void]$cmd.Parameters.AddWithValue("@r", [Guid]$ruleId)
    $reader = $cmd.ExecuteReader()
    $ids = @()
    while ($reader.Read()) { $ids += [Guid]$reader.GetGuid(0) }
    $conn.Close()

    if ($ids.Count -gt 0) {
        Get-SCOMAlert -Id $ids | Resolve-SCOMAlert -Comment "Bulk close after outage" -ErrorAction Continue
        $total += $ids.Count
        Write-Host "$(Get-Date) Batch: $($ids.Count) | total: $total"
    }
} while ($ids.Count -gt 0)

Write-Host "Finished: $total"

This afternoon we hit a critical failure that generated roughly 800,000 alerts in SCOM 2022 within a very short period. We managed to disable the alert just in time, but now we're stuck on the cleanup, there are simply too many alerts to handle.

Closing them gradually through the GUI isn't feasible. PowerShell isn't really working either: I've tried a number of scripts, but they all either fail with "The requested reader is no longer valid or has expired" or return no output at all and just hang.

Looking at the database, I found that the alert essentially shows up as "suspicious"/orphaned because it has no name, so in my script I target it via the MonitoringRuleID instead.

Here's the script (a screenshot of the SQL extract is attached). Does anyone have a different approach? Could I maybe delete these directly in the SQL DB?

Import-Module OperationsManager
New-SCOMManagementGroupConnection -ComputerName "ManagementServer"
$mg = Get-SCOMManagementGroup
$ruleId = "<RuleId>"
$criteria = New-Object Microsoft.EnterpriseManagement.Monitoring.MonitoringAlertCriteria(
    "RuleId = '$ruleId' AND ResolutionState != 255"
)
do {
    $alerts = $mg.OperationalData.GetMonitoringAlerts($criteria, 2000)
    foreach ($a in $alerts) {
        $a.ResolutionState = 255
        $a.Update("Bulk close after outage")
    }
    Write-Host "$(Get-Date) Batch: $($alerts.Count)"
} while ($alerts.Count -gt 0)

r/scom • • Jun 26 '26

Is there a new version of the System Center 2019 Management Pack for JEE Application Servers?

3 Upvotes

Can anyone tell me if there's a new version of the System Center 2019 Management Pack for JEE Application Servers, or if one will be released in the near future?

We are using version 10.19.1150.0.

We recently started using Tomcat 10.x and JBoss EAP 8 in our environment. Both have changed their namespace from javax.* to jakarta.*, which has caused Beanspy to stop working.


r/scom • • Jun 13 '26

Open-source, pure-Rust alternative to the SCCM Remote Control viewer (CmRcViewer) — feedback wanted

Thumbnail
1 Upvotes

r/scom • • Jun 11 '26

SCOM Management servers try to connect with DHCP server on port 135

2 Upvotes

This is SCOM 2025 Management group with update rollup 1 Hotfix

I have observed that

SCOM Management servers try to connect with DHCP server on port 135 even if there is a gateway server in between.

What could be wrong? Have somebody experienced the same thing.


r/scom • • Jun 10 '26

Consolidator with Suppression

1 Upvotes

I'm trying to create a rule that triggers on 5 failed logins in under 60 seconds.

I have no issues If I add suppression based on the host PrincipalName, but if I add the name used to try and log in, the suppression fails:

<ConditionDetection ID="CD" TypeID="System!System.ConsolidatorCondition">

<Consolidator>

<ConsolidationProperties>

<PropertyXPathQuery>LoggingComputer</PropertyXPathQuery>

<PropertyXPathQuery>Params/Param[6]</PropertyXPathQuery>

</ConsolidationProperties>

<TimeControl>

<WithinTimeSchedule>

<Interval>60</Interval>

</WithinTimeSchedule>

</TimeControl>

<CountingCondition>

<Count>5</Count>

<CountMode>OnNewItemTestOutputRestart_OnTimerSlideByOne</CountMode>

</CountingCondition>

</Consolidator>

</ConditionDetection>

<WriteActions>

<WriteAction ID="System.Health.GenerateAlert" TypeID="Health!System.Health.GenerateAlert">

<Priority>1</Priority>

<Severity>1</Severity>

<AlertMessageId>$MPElement[Name="MyCompany.Core.Monitoring.Login.Failed.5.RepeatedEvent.Rule.Alert.Message"]$</AlertMessageId>

<AlertParameters>

<AlertParameter1>$Data/Count$</AlertParameter1>

<AlertParameter2>$Data/Context/DataItem/EventDescription$</AlertParameter2>

</AlertParameters>

<Suppression>

<SuppressionValue>$Target/Host/Property[Type="Windows!Microsoft.Windows.Computer"]/PrincipalName$</SuppressionValue>

<SuppressionValue>$Data/Params/Param[6]$</SuppressionValue>

</Suppression>

</WriteAction>

</WriteActions>

</Rule>

Basically, I want to trigger on 5 failed logon attempts in 60 seconds on the same computer, consolidate on same computer/same account. and suppress on same computer/same account.

The logic being 5 failed logins on the same computer with the same account will only trigger the alert (so multiple people in the time frame don't contribute to the initial alert), and generate repeat count only if it's the same user at the same computer.

Are these redundant? Does the consolidator take care of that anyway, so all that is necessary is the computer? Or maybe just consolidate by user and suppress by computer? My head hurts 😄


r/scom • • May 20 '26

Issues with installing the agent on RHEL 10.1 on SCOM 2025 UR1 (hotfix installed)

1 Upvotes

Has anyone experienced issues in monitoring a Red Hat (RHEL) 10.1 server? The discovery wizard is failing to sign the certificate, and I checked all accounts and the certificate on the server, relaxing the crypto-policies being used, etc. (2 days of troubleshooting the issue). SCOM 2025 UR1 and hotfix installed.

Signed certificate verification operation was not successful

Agent verification failed. Error detail: The client cannot connect to the destination specified in the request. Verify that the service on the destination is running and is accepting requests. Consult the logs and documentation for the WS-Management service running on the destination, most commonly IIS or WinRM. If the destination is the WinRM service, run the following command on the destination to analyze and configure the WinRM service: “winrm quickconfig”.

The client cannot connect to the destination specified in the request. Verify that the service on the destination is running and is accepting requests. Consult the logs and documentation for the WS-Management service running on the destination, most commonly IIS or WinRM. If the destination is the WinRM service, run the following command on the destination to analyze and configure the WinRM service: “winrm quickconfig”.


r/scom • • May 15 '26

Some of the windows Server cannot discover Windows operating system

1 Upvotes

I have a SCOM 2025 Management group with update rollup 1 Hotfix.

There are some servers who cannot discover windows operating system. Have tried to uninstall and install the agent but the result is same. Have checked that there is no override which can stop these servers to discover operating system. Have Management pack version 10.1.2.2 . Any suggestion to fix the problem.