Horizon Cloud Service Next Gen Apis – Chapter 2

Immagine che contiene testo, Neon, Segnali luminosi, Insegna al neon Il contenuto generato dall'IA potrebbe non essere corretto.

Set Syslog settings across UAG deployments

In this second article on working with APIs in Horizon Cloud Services, we will focus on a practical, security-relevant use case: configuring Syslog on Unified Access Gateways (UAGs) deployed through Horizon Cloud.

Whether you are running Horizon Cloud Service on Microsoft Azure or Horizon Cloud Service on vSphere, centralized logging is a fundamental component of any secure and well-governed environment. Proper Syslog configuration ensures that security events, authentication logs, and operational data generated by UAG appliances are forwarded to your SIEM or log management platform for monitoring, auditing, and incident response.

Instead of performing manual configuration tasks, we will explore how to leverage Horizon Cloud APIs to automate and standardise Syslog settings across UAG deployments, improving consistency, scalability, and operational efficiency.

Now when can explain the API we need to use and how to apply the syslog configuration on UAG (In this case, I used an HCS on vSphere, the new solution where we don’t deploy the Connection Server, but we use the HCS control panel to configure Pools, Entitlements and other…)

The first step is always the authentication process; I explained how to create the API token in my previous post (Horizon Cloud Service Next Gen Apis – Chapter 1), and now I won’t explain it again.

Let’s go…..

How to show UAG information

This command displays the UAG’s information

Invoke-RestMethod -Uri https://cloud-sg.horizon.omnissa.com/admin/v2/uag-deployments Method Get -Headers $Header

 We have two UAG deployments connected to HCS, and the output displays two deployment ids:

Immagine che contiene testo, schermata, Carattere Il contenuto generato dall'IA potrebbe non essere corretto.

The UAG id for HCS on vSphere is the second id.

Immagine che contiene testo, schermata, Carattere Il contenuto generato dall'IA potrebbe non essere corretto.

Now I need to recover only the UAG IDs and OrgIDs

Invoke-RestMethod -Uri https://cloud-sg.horizon.omnissa.com/admin/v2/uag-deployments -Method Get -Headers $Header | Select-Object -ExpandProperty content | Select-Object id,OrgId

Immagine che contiene testo, schermata, Carattere Il contenuto generato dall'IA potrebbe non essere corretto.

The UAG id that I need to use for identifying the deployment for HCS on vSphere is:

6994998bcb2a7086afaddf1c 

I will use this ID to associate the syslog configuration with the UAG server.

 

How to set the correct parameters for Syslog configuration

We need to create a Body value like this:

$Body = @{
  orgId  = "8a4931b3-e6ac-44bf-9d25-723f4119e46f"
  projectId = "Pollaio-Project"
  name = "Pollaio-Configuration2"
  syslogEventCategory = "ALL_EVENTS"
  syslogServerProtocolSettingsCreateTO = @{
    sourceToSyslogServerProtocol = "TCP"
  }
  syslogFormat = "TEXT"
  syslogURI = "192.168.111.223:514"
  includeSystemMessages = $true
  sources = @(
    @{
      type = "UAG"
      id   = "6994998bcb2a7086afaddf1c"
    }
  )
}

.

Where:

Value Description Accept value
OrgID It is the OrgId that we recovered with the previous command String
ProjectId ID of theCSP project that owns this data String
Name User defined name of the syslog server configuration String
SyslogEventCategory Events sent from the UAG appliance to the syslog server [ ALL_EVENTS, AUDIT_EVENTS ]
sourceToSyslogServerProtocol The protocol used to send data from the UAG appliance to the syslog server [ UDP, TCP, TLS, MQTT ]
syslogFormat [ JSON_TITAN, TEXT ]
syslogURI Syslog server URI String
includeSystemMessages If true, system messages are sent to the syslog server [ $True]
sources

List of sources associated with the syslog server:

Type = Source for the syslog server. For es: UAG

Id = Id of the source associated with the syslog server (The Id value that we recovered with the previous command

 

.

.

How to set the configuration for UAG
$Body = @{
  orgId  = "8a4931b3-e6ac-44bf-9d25-723f4119e46f"
  projectId = "Pollaio-Project"
  name = "Pollaio-Configuration2"
  syslogEventCategory = "ALL_EVENTS"
  syslogServerProtocolSettingsCreateTO = @{
    sourceToSyslogServerProtocol = "TCP"
  }
  syslogFormat = "TEXT"
  syslogURI = "192.168.111.223:514"
  includeSystemMessages = $true
  sources = @(
    @{
      type = "UAG"
      id   = "6994998bcb2a7086afaddf1c"
    }
  )
}

#Convert Body to JSON
$JsonBody = $Body | ConvertTo-Json -Depth 5
#Send POST request to create Syslog Server UAG configuration
Invoke-RestMethod -Uri https://cloud-sg.horizon.omnissa.com/admin/v1/syslog-server -Method Post -Headers $Header -Body $JsonBody
HOW to check SYSLOG Configuration on UAG deployment

 

Invoke-RestMethod -Uri https://cloud-sg.horizon.omnissa.com/admin/v1/syslog-server -Method Get -Headers $Header

The command output is like this:

.

 Now I can see in my SYSLOG server the UAG Log

Immagine che contiene testo, schermata, Carattere Il contenuto generato dall'IA potrebbe non essere corretto.

.

.

.

Horizon Cloud Service Next Gen Apis – Chapter 2

Horizon Cloud Service Next Gen Apis – Chapter 1

.

Immagine che contiene testo, Carattere, Insegna al neon, Neon Il contenuto generato dall'IA potrebbe non essere corretto.

If you are working with Omnissa Horizon Cloud Services, sooner or later you will want to automate tasks, integrate with external systems, or simply make your daily operations more efficient. (For example, configure SYSLOG server on Unified Access Gateway). This is where REST APIs come into play.

Through the HCS Omnissa REST APIs, administrators and developers can programmatically interact with the platform, retrieve information, trigger actions, and build custom integrations that go beyond the capabilities of the graphical interface. APIs enable consistency, scalability, and repeatability — all essential elements in modern IT environments.

In this post, we will explore how to get started with the HCS Omnissa REST APIs, understand the authentication process, and see practical examples of how they can simplify management and automation.

This is the first post about this topic … here Horizon Cloud Service Next Gen Apis – Chapter 2, the second Chapter where I write about configuring SYSLOG on UAG deployment

.

Configure an Account for API Token

Before interacting with the HCS Omnissa REST APIs, you need a properly configured account that is authorised to perform API operations. In this section, we will review the prerequisites, required roles and permissions, and how to create or configure a dedicated service account to ensure secure and controlled access to the platform.

Connect to https://connect.omnissa.com and go to View My Profile under the account info.

Immagine che contiene testo, schermata, software, Icona del computer Il contenuto generato dall'IA potrebbe non essere corretto.

.

Select API Tokens TAB and Generate A New API TokenImmagine che contiene testo, schermata, software, Pagina Web Il contenuto generato dall'IA potrebbe non essere corretto.

Configure the new token, add Name and Token TTL (I suggest setting an expiration date to increase security)

Immagine che contiene testo, schermata, software, numero Il contenuto generato dall'IA potrebbe non essere corretto.

.

About the scope of the token use, we need to select the appropriate permissions

Immagine che contiene testo, schermata, software, numero Il contenuto generato dall'IA potrebbe non essere corretto.

Select the OpenID format

We can select if near the token expiration date, the system will send a mail notification.

Immagine che contiene testo, schermata, Carattere, linea Il contenuto generato dall'IA potrebbe non essere corretto.

.

And now we can select Generate

Immagine che contiene Carattere, logo, Elementi grafici, testo Il contenuto generato dall'IA potrebbe non essere corretto.

It will take some seconds and will display the Token ID,

It is important to save the token.

Immagine che contiene testo, schermata, software, Sistema operativo Il contenuto generato dall'IA potrebbe non essere corretto.

.

.

.

.

.

Obtain the Authentication Token

Authentication is a fundamental step when working with REST APIs. HCS Omnissa uses token-based authentication, which means you must first request and obtain a valid access token before performing any API calls. Here, we will walk through the authentication flow, explain the required headers and payload, and demonstrate how to retrieve and securely store the token for subsequent requests.

We can use, for example, Postman or PowerShell.

In the first step, I suggest using postman for handle the command, so we start Postman (Desktop or Web).

POST https://connect.omnissa.com/csp/gateway/am/api/auth/api-tokens/authorize

Immagine che contiene testo, schermata, linea, Carattere Il contenuto generato dall'IA potrebbe non essere corretto.

In the command output, we can see the access_token to use for sending other commands.

Immagine che contiene testo, Carattere, linea, numero Il contenuto generato dall'IA potrebbe non essere corretto.

Test the APIs with Postman

Before moving to automation, it is always a good practice to validate API calls using a tool like Postman. In this section, we will configure a collection, set up authentication headers, and test sample API requests. This approach helps you understand request structure, responses, and potential error handling in a simple and interactive way.

In the next step, I use the RESTapi to list the Pools (in my environment are HCS on vSphere Pools):

GET https://cloud-sg.horizon.omnissa.com/portal/v2/pools

Immagine che contiene schermata, testo, linea, software Il contenuto generato dall'IA potrebbe non essere corretto.

Command output

Immagine che contiene testo, schermata, Carattere, numero Il contenuto generato dall'IA potrebbe non essere corretto.

.

.

Automating with PowerShell

Once the API calls have been validated, the next step is automation. In this chapter, we will build a practical PowerShell script to authenticate, retrieve the access token, and execute REST API calls against HCS Omnissa. This will allow you to integrate API operations into your administrative workflows, scheduled tasks, or larger automation frameworks.

PowerShell command for generating an access token

$Header = @{
	    "Content-Type" = "application/x-www-form-urlencoded"
    }
$Body = @{
	    "refresh_token" = "<Token API created from the Connect Omnissa Portal"
    }
$Response = Invoke-RestMethod -Uri  https://connect.omnissa.com/csp/gateway/am/api/auth/api-tokens/authorize -Method Post -Headers $Header -Body $Body
$AccessToken = $Response.access_token

 Powershell command to show the Pools

$Header =	@{
			"Content-Type" = "application/json";
			"Authorization" = "Bearer $AccessToken"
	}

Invoke-RestMethod -Uri https://cloud-sg.horizon.omnissa.com/portal/v4/pools -Method Get -Headers $Header

 

.

.

.

Horizon Cloud Service Next Gen Apis – Chapter 1