public/Get-VPASCMComponentLogs.ps1

<#
.Synopsis
   GET CONNECTOR MANAGEMENT CONNECTOR COMPONENT LOGS
   CREATED BY: Vadim Melamed, EMAIL: vpasmodule@gmail.com
.DESCRIPTION
   USE THIS FUNCTION TO RETRIEVE CONNECTOR COMPONENT LOGS FROM CONNECTOR MANAGEMENT
.LINK
   https://vpasmodule.com/commands/Get-VPASCMComponentLogs
.PARAMETER token
   HashTable of data containing various pieces of login information (PVWA, LoginToken, HeaderType, etc).
   If -token is not passed, function will use last known hashtable generated by New-VPASToken
.PARAMETER ConnectorID
   UniqueID of the target connector in ConnectorManagement
.PARAMETER ConnectorHost
   Unique host of the target connector in ConnectorManagement
   Host in this case can either be a hostname, a publicIP, or a PrivateIP
.PARAMETER ComponentID
   UniqueID of the target component for a connector in ConnectorManagement
.PARAMETER ComponentName
   Unique name of the target component for a connector in ConnectorManagement
   Possible values: psm, cpm, cpm scanner, Management Agent
.PARAMETER OutputDirectory
   Where to place the generated logs
.PARAMETER InputParameters
   HashTable of values containing the parameters required to make the API call
.EXAMPLE
   $ComponentLogs = Get-VPASCMComponentLogs -ConnectorID {CONNECTOR ID VALUE} -ComponentID {COMPONENT ID VALUE}
.EXAMPLE
   $ComponentLogs = Get-VPASCMComponentLogs -ConnectorHost {CONNECTOR NAME VALUE} -ComponentName {COMPONENT NAME VALUE}
.EXAMPLE
   $InputParameters = @{
        ConnectorID = "ManagementAgent_fslkdj34890-1234-1234-asdf-0239kdf"
        ComponentID = "lkdfhj834920-zccv-1234-sdfg-slkdjf09458"
        OutputDirectory = "C:\temp\LogExports"
   }
   $ComponentLogs = Get-VPASCMComponentLogs -InputParameters $InputParameters
.EXAMPLE
   $InputParameters = @{
        ConnectorID = "ManagementAgent_fslkdj34890-1234-1234-asdf-0239kdf"
        ComponentName = "psm"|"cpm"|"cpm scanner"|"Management Agent"
        OutputDirectory = "C:\temp\LogExports"
   }
   $ComponentLogs = Get-VPASCMComponentLogs -InputParameters $InputParameters
.EXAMPLE
   $InputParameters = @{
        ConnectorHost = "VmanCon01.vman.com"
        ComponentID = "lkdfhj834920-zccv-1234-sdfg-slkdjf09458"
        OutputDirectory = "C:\temp\LogExports"
   }
   $ComponentLogs = Get-VPASCMComponentLogs -InputParameters $InputParameters
.EXAMPLE
   $InputParameters = @{
        ConnectorHost = "VmanCon01.vman.com"
        ComponentName = "psm"|"cpm"|"cpm scanner"|"Management Agent"
        OutputDirectory = "C:\temp\LogExports"
   }
   $ComponentLogs = Get-VPASCMComponentLogs -InputParameters $InputParameters
.OUTPUTS
   $true if successful
   ---
   $false if failed
#>

function Get-VPASCMComponentLogs{
    [OutputType([bool])]
    [CmdletBinding(DefaultParameterSetName='Set1')]
    Param(

        [Parameter(Mandatory=$true,ParameterSetName='Set1',ValueFromPipelineByPropertyName=$true,HelpMessage="Unique ConnectorID of the target connector (for example: hsfkjdhf687234-kjhf-sdfj-9876-872364iedhkjwqed)")]
        [Parameter(Mandatory=$true,ParameterSetName='Set2',ValueFromPipelineByPropertyName=$true,HelpMessage="Unique ConnectorID of the target connector (for example: hsfkjdhf687234-kjhf-sdfj-9876-872364iedhkjwqed)")]
        [String]$ConnectorID,

        [Parameter(Mandatory=$true,ParameterSetName='Set3',ValueFromPipelineByPropertyName=$true,HelpMessage="Name of the host holding the target connector (for example: VmanCon01)")]
        [Parameter(Mandatory=$true,ParameterSetName='Set4',ValueFromPipelineByPropertyName=$true,HelpMessage="Name of the host holding the target connector (for example: VmanCon01)")]
        [String]$ConnectorHost,

        [Parameter(Mandatory=$true,ParameterSetName='Set1',ValueFromPipelineByPropertyName=$true,HelpMessage="Unique ComponentID of the target component (for example: lkdfhj834920-zccv-1234-sdfg-slkdjf09458)")]
        [Parameter(Mandatory=$true,ParameterSetName='Set3',ValueFromPipelineByPropertyName=$true,HelpMessage="Unique ComponentID of the target component (for example: lkdfhj834920-zccv-1234-sdfg-slkdjf09458)")]
        [String]$ComponentID,

        [Parameter(Mandatory=$true,ParameterSetName='Set2',ValueFromPipelineByPropertyName=$true,HelpMessage="Name of the target component (for example: psm, cpm, cpm scanner, Management Agent)")]
        [Parameter(Mandatory=$true,ParameterSetName='Set4',ValueFromPipelineByPropertyName=$true,HelpMessage="Name of the target component (for example: psm, cpm, cpm scanner, Management Agent)")]
        [ValidateSet('psm','cpm','cpm scanner','Management Agent')]
        [String]$ComponentName,

        [Parameter(Mandatory=$false,ParameterSetName='Set1',ValueFromPipelineByPropertyName=$true)]
        [Parameter(Mandatory=$false,ParameterSetName='Set2',ValueFromPipelineByPropertyName=$true)]
        [Parameter(Mandatory=$false,ParameterSetName='Set3',ValueFromPipelineByPropertyName=$true)]
        [Parameter(Mandatory=$false,ParameterSetName='Set4',ValueFromPipelineByPropertyName=$true)]
        [String]$OutputDirectory,

        [Parameter(Mandatory=$true,ParameterSetName='InputParameters',ValueFromPipelineByPropertyName=$true,HelpMessage="Hashtable of parameters required to make API call, refer to get-help -examples for valid inputs")]
        [hashtable]$InputParameters,

        [Parameter(Mandatory=$false,ValueFromPipelineByPropertyName=$true)]
        [hashtable]$token
    )

    Begin{
        $tokenval,$sessionval,$PVWA,$Header,$ISPSS,$IdentityURL,$EnableTextRecorder,$AuditTimeStamp,$NoSSL,$VaultVersion,$HideWarnings,$AuthenticatedAs,$SubDomain,$EnableTroubleshooting = Get-VPASSession -token $token
        $CommandName = $MyInvocation.MyCommand.Name
        $log = Write-VPASTextRecorder -inputval $CommandName -token $token -LogType COMMAND
    }
    Process{
        try{
            if($PSCmdlet.ParameterSetName -eq "InputParameters"){
                $KeyHash = @{
                    set1 = @{
                        AcceptableKeys = @("ConnectorID","ComponentID","OutputDirectory")
                        MandatoryKeys = @("ConnectorID","ComponentID")
                    }
                    set2 = @{
                        AcceptableKeys = @("ConnectorID","ComponentName","OutputDirectory")
                        MandatoryKeys = @("ConnectorID","ComponentName")
                    }
                    set3 = @{
                        AcceptableKeys = @("ConnectorHost","ComponentID","OutputDirectory")
                        MandatoryKeys = @("ConnectorHost","ComponentID")
                    }
                    set4 = @{
                        AcceptableKeys = @("ConnectorHost","ComponentName","OutputDirectory")
                        MandatoryKeys = @("ConnectorHost","ComponentName")
                    }
                }
                $CheckSet = Test-VPASHashtableKeysHelper -InputHash $InputParameters -KeyHash $KeyHash

                if(!$CheckSet){
                    $log = Write-VPASTextRecorder -inputval "FAILED TO FIND TARGET PARAMETER SET" -token $token -LogType MISC
                    Write-Verbose "FAILED TO FIND TARGET PARAMETER SET"
                    Write-VPASOutput -str "FAILED TO FIND TARGET PARAMETER SET...VIEW EXAMPLES BELOW:" -type E
                    $examples = Write-VPASExampleHelper -CommandName $CommandName
                    return $false
                }
                else{
                    foreach($key in $InputParameters.Keys){
                        Set-Variable -Name $key -Value $InputParameters.$key
                    }
                }
            }
        }catch{
            $log = Write-VPASTextRecorder -inputval $_ -token $token -LogType ERROR
            $log = Write-VPASTextRecorder -inputval "REST API COMMAND RETURNED: FALSE" -token $token -LogType MISC
            Write-Verbose "FAILED TO RETRIEVE COMPONENT LOGS"
            Write-VPASOutput -str $_ -type E
            return $false
        }

        try{
            if($SubDomain -eq "N/A"){
                Write-VPASOutput -str "SelfHosted + PriviledgeCloud Standard solutions do not support this API Call, returning false" -type E
                $log = Write-VPASTextRecorder -inputval "SelfHosted + PrivilegeCloud Standard solutions do not support this API Call, returning false" -token $token -LogType MISC
                $log = Write-VPASTextRecorder -inputval $false -token $token -LogType RETURN
                return $false
            }

            if([String]::IsNullOrEmpty($ConnectorID)){
                Write-Verbose "NO CONNECTOR ID PROVIDED...INVOKING HELPER FUNCTION TO RETRIEVE UNIQUE CONNECTOR ID BASED ON SPECIFIED PARAMETERS"
                $ConnectorID = Get-VPASCMConnectorIDHelper -token $token -SearchQuery $ConnectorHost
                Write-Verbose "RETURNING CONNECTOR ID"
            }
            else{
                Write-Verbose "CONNECTOR ID SUPPLIED, SKIPPING HELPER FUNCTION"
            }

            if($ConnectorID -eq -1){
                $log = Write-VPASTextRecorder -inputval "COULD NOT FIND TARGET CONNECTOR ID: $ConnectorID" -token $token -LogType MISC
                $log = Write-VPASTextRecorder -inputval "REST API COMMAND RETURNED: FALSE" -token $token -LogType MISC
                Write-Verbose "COULD NOT FIND TARGET CONNECTOR ID: $ConnectorID"
                Write-VPASOutput -str "COULD NOT FIND TARGET CONNECTOR ID: $ConnectorID" -type E
                return $false
            }
            else{
                if([String]::IsNullOrEmpty($ComponentID)){
                    Write-Verbose "NO COMPONENT ID PROVIDED...INVOKING HELPER FUNCTION TO RETRIEVE UNIQUE COMPONENT ID BASED ON SPECIFIED PARAMETERS"
                    $ComponentID = Get-VPASCMConnectorComponentIDHelper -token $token -SearchQuery $ComponentName -ConnectorID $ConnectorID
                    Write-Verbose "RETURNING COMPONENT ID"
                }
                else{
                    Write-Verbose "COMPONENT ID SUPPLIED, SKIPPING HELPER FUNCTION"
                }

                if($ComponentID -eq -1){
                    $log = Write-VPASTextRecorder -inputval "COULD NOT FIND TARGET COMPONENT ID: $ComponentID" -token $token -LogType MISC
                    $log = Write-VPASTextRecorder -inputval "REST API COMMAND RETURNED: FALSE" -token $token -LogType MISC
                    Write-Verbose "COULD NOT FIND TARGET CONNECTOR ID: $ComponentID"
                    Write-VPASOutput -str "COULD NOT FIND TARGET COMPONENT ID: $ComponentID" -type E
                    return $false
                }
                else{
                    write-verbose "MAKING API CALL TO CYBERARK"
                    $uri = "https://$SubDomain.connectormanagement.cyberark.cloud/api/connectors/$ConnectorID/components/$ComponentID/logs"
                    Write-Verbose "CONSTRUCTING URI: $uri"

                    $log = Write-VPASTextRecorder -inputval $uri -token $token -LogType URI
                    $log = Write-VPASTextRecorder -inputval "GET" -token $token -LogType METHOD

                    if($sessionval){
                        $response = Invoke-RestMethod -Headers @{"Authorization"=$Header} -Uri $uri -Method GET -ContentType "application/json" -WebSession $sessionval
                    }
                    else{
                        $response = Invoke-RestMethod -Headers @{"Authorization"=$Header} -Uri $uri -Method GET -ContentType "application/json"
                    }
                    $log = Write-VPASTextRecorder -inputval $response -token $token -LogType RETURNARRAY
                    Write-Verbose "PARSING COMPONENT LOG LIST"
                    $logID = $response.logs.logId

                    if($logID){
                        write-verbose "MAKING API CALL TO CYBERARK"
                        $uri = "https://$SubDomain.connectormanagement.cyberark.cloud/api/connectors/$ConnectorID/components/$ComponentID/logs/$logID"
                        Write-Verbose "CONSTRUCTING URI: $uri"

                        $log = Write-VPASTextRecorder -inputval $uri -token $token -LogType URI
                        $log = Write-VPASTextRecorder -inputval "GET" -token $token -LogType METHOD

                        if($sessionval){
                            $response = Invoke-RestMethod -Headers @{"Authorization"=$Header} -Uri $uri -Method GET -ContentType "application/json" -WebSession $sessionval
                        }
                        else{
                            $response = Invoke-RestMethod -Headers @{"Authorization"=$Header} -Uri $uri -Method GET -ContentType "application/json"
                        }
                        $log = Write-VPASTextRecorder -inputval $response -token $token -LogType RETURNARRAY

                        if([String]::IsNullOrEmpty($OutputDirectory)){
                            $curUser = $env:UserName
                            $OutputDirectory = "C:\Users\$curUser\AppData\Local\VPASModuleOutputs\Logs"
                            Write-Verbose "NO OUTPUT DIRECTORY SUPPLIED, USING DEFAULT LOCATION: $OutputDirectory"

                            if(Test-Path -Path $OutputDirectory){
                                #DO NOTHING
                            }
                            else{
                                write-verbose "$OutputDirectory DOES NOT EXIST, CREATING DIRECTORY"
                                $MakeDirectory = New-Item -Path $OutputDirectory -Type Directory
                            }
                        }
                        else{
                            if(Test-Path -Path $OutputDirectory){
                                #DO NOTHING
                            }
                            else{
                                $curUser = $env:UserName
                                $OutputDirectory = "C:\Users\$curUser\AppData\Local\VPASModuleOutputs\Reports"
                                write-verbose "$OutputDirectory DOES NOT EXIST, USING DEFAULT LOCATION: $OutputDirectory"
                                if(Test-Path -Path $OutputDirectory){
                                    #DO NOTHING
                                }
                                else{
                                    $MakeDirectory = New-Item -Path $OutputDirectory -Type Directory
                                }
                            }
                        }

                        $targetFile = "$OutputDirectory\CMLogs.zip"
                        $createZip = [IO.File]::WriteAllBytes($targetFile, [System.Convert]::FromBase64String($response))
                        Write-Verbose "ZIP FILE OUTPUT: $targetFile"
                        Write-Verbose "RETURNING TRUE"
                        Write-VPASOutput -str "ZIP FILE OUTPUT: $targetFile" -type M
                        return $true
                    }
                    else{
                        $log = Write-VPASTextRecorder -inputval "COULD NOT FIND COMPONENT LOGS" -token $token -LogType MISC
                        $log = Write-VPASTextRecorder -inputval "REST API COMMAND RETURNED: FALSE" -token $token -LogType MISC
                        Write-Verbose "COULD NOT FIND COMPONENT LOGS"
                        Write-VPASOutput -str "COULD NOT FIND COMPONENT LOGS" -type E
                        return $false
                    }
                }
            }
        }catch{
            $log = Write-VPASTextRecorder -inputval $_ -token $token -LogType ERROR
            $log = Write-VPASTextRecorder -inputval "REST API COMMAND RETURNED: FALSE" -token $token -LogType MISC
            Write-Verbose "FAILED TO RETRIEVE CONNECTOR MANAGEMENT CONNECTOR COMPONENT LOGS"
            Write-VPASOutput -str $_ -type E
            return $false
        }
    }
    End{
        $log = Write-VPASTextRecorder -inputval $CommandName -token $token -LogType DIVIDER
    }
}