Skip to main content

SCCM 2012 user and device collections membership rule queries

There is no need for choosing objects when creating collections. Because after creating a user or device collection on microsoft system center configuration manager 2012 there would be objects that is created newly on your network infrastructure.
To prevent collections become stale, dynamic groups should be set. Following two examples are the queries select objects from sccm database. First one selects specific active directory group using "UserGroupName" parameter as the criteria. Second one selects workstations that are on specific subnet using two parameters "SMS_G_System_NETWORK_ADAPTER_CONFIGURATION.IPAddress" and "SMS_R_System.OperatingSystemNameandVersion".

How to use these queries on sccm? Open "Configuration Manager Console", Under "Assets and Compliance" right click on "User Collections", choose "Create User Collection", on the "Membership Rules" tab click "Add Rule" as the type of "Query Rule", click "Edit Query Statement" then click "Edit Query Statement", click "Show Query Language" then paste query.


This is for user collection:
--------------------------------

select SMS_R_USER.ResourceID, SMS_R_USER.ResourceType, SMS_R_USER.Name, SMS_R_USER.UniqueUserName, SMS_R_USER.WindowsNTDomain from SMS_R_User where SMS_R_User.UserGroupName = "DOMAIN_NAME\\GROUP_Name"
This is for device collection:
----------------------------------------
select SMS_R_SYSTEM.ResourceID, SMS_R_SYSTEM.ResourceType, SMS_R_SYSTEM.Name, SMS_R_SYSTEM.SMSUniqueIdentifier, SMS_R_SYSTEM.ResourceDomainORWorkgroup, SMS_R_SYSTEM.Client from SMS_R_System inner join SMS_G_System_NETWORK_ADAPTER_CONFIGURATION on SMS_G_System_NETWORK_ADAPTER_CONFIGURATION.ResourceID = SMS_R_System.ResourceId where SMS_G_System_NETWORK_ADAPTER_CONFIGURATION.IPAddress like "10.%" and LOWER(SMS_R_System.OperatingSystemNameandVersion) like "%workstation%"

Comments

  1. Very helpful, how would you create a query combining 2? For instance, all users in the ou Domain\service, need to grab all those users machines they have logged into?

    ReplyDelete
  2. It is up to your SMS db design knowledge. What you require is a query not a collection. On the SCCM console "Monitor" page has a "Queries" tab. Create new query. In this case you can use SystemConsoleUser and join that SystemResource like:
    -----------
    select SMS_G_System_SYSTEM_CONSOLE_USER.SystemConsoleUser, SMS_R_System.ResourceNames from SMS_G_System_SYSTEM_CONSOLE_USER inner join SMS_R_System on SMS_G_System_SYSTEM_CONSOLE_USER.ResourceID = SMS_R_System.ResourceId where SMS_G_System_SYSTEM_CONSOLE_USER.SystemConsoleUser in (select SMS_R_USER.UniqueUserName from SMS_R_User where SMS_R_User.UserGroupName = "DOMAIN_NAME\\GROUP_Name")
    ------------------------

    ReplyDelete

Post a Comment

Popular posts from this blog

Sending Jboss Server Logs to Logstash Using Filebeat with Multiline Support

In addition to sending system logs to logstash, it is possible to add a prospector section to the filebeat.yml for jboss server logs. Sometimes jboss server.log has single events made up from several lines of messages. In such cases Filebeat should be configured for a multiline prospector. Filebeat takes lines do not start with a date pattern (look at pattern in the multiline section "^[[:digit:]]{4}-[[:digit:]]{2}-[[:digit:]]{2}" and negate section is set to true ) and combines them with the previous line that starts with a date pattern. server.log file excerpt where DatePattern: yyyy-MM-dd-HH and ConversionPattern: %d %-5p [%c] %m%n Logstash filter:

Creating Multiple VLANs over Bonding Interfaces with Proper Routing on a Centos Linux Host

In this post, I am going to explain configuring multiple VLANs on a bond interface. First and foremost, I would like to describe the environment and give details of the infrastructure. The server has 4 Ethernet links to a layer 3 switch with names: enp3s0f0, enp3s0f1, enp4s0f0, enp4s0f1 There are two bond interfaces both configured as active-backup bond0, bond1 enp4s0f0 and enp4s0f1 interfaces are bonded as bond0. Bond0 is for making ssh connections and management only so corresponding switch ports are not configured in trunk mode. enp3s0f0 and enp3s0f1 interfaces are bonded as bond1. Bond1 is for data and corresponding switch ports are configured in trunk mode. Bond0 is the default gateway for the server and has IP address 10.1.10.11 Bond1 has three subinterfaces with VLAN 4, 36, 41. IP addresses are 10.1.3.11, 10.1.35.11, 10.1.40.11 respectively. Proper communication with other servers on the network we should use routing tables. There are three