You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Get-MgAuditLogDirectoryAudit筛选Microsoft Entra审计日志特定IP?

如何通过Microsoft Entra审计日志筛选特定IP地址

问题分析

你尝试使用以下PowerShell命令筛选特定IP地址的审计日志,但无法成功:

Get-MgAuditLogDirectoryAudit -All -Property * -Filter "initiatedBy/user/ipAddress eq '$IpAddress'"
Get-MgBetaAuditLogDirectoryAudit -All -Property * -Filter "initiatedBy/user/ipAddress eq '$IpAddress'"

但筛选用户主体名称(UPN)的命令可以正常运行:

Get-MgAuditLogDirectoryAudit -All -Property * -Filter "initiatedBy/user/userPrincipalName eq '$UPN'"

原因

Microsoft Graph API的directoryAudits端点中,initiatedBy/user/ipAddress字段不支持$filter查询参数,而userPrincipalName属于可筛选字段,因此直接用Filter筛选IP会失效。

解决方案

方案1:PowerShell本地筛选

先拉取所有审计日志,再通过PowerShell的Where-Object在本地过滤IP地址:

# 替换为目标IP地址
$targetIp = "192.168.1.100"

# 获取所有审计日志
$allAuditLogs = Get-MgAuditLogDirectoryAudit -All -Property *

# 筛选匹配目标IP的日志
$filteredLogs = $allAuditLogs | Where-Object { 
    $_.InitiatedBy.User.IpAddress -eq $targetIp 
}

# 输出结果
$filteredLogs

方案2:Entra管理中心直接筛选

在Microsoft Entra管理中心操作更直观:

  • 进入审计日志页面
  • 在顶部搜索框输入 ipAddress:你的目标IP,按回车即可筛选出对应日志

内容的提问来源于stack exchange,提问作者user3022917

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 02:49:51