You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PowerShell获取Azure Windows 10 VM用户登录登出信息问题求助

解决Azure Windows 10 VM登录/登出信息收集问题

一、修复本地脚本账户名为空的问题

你当前脚本通过($logonEvent.Properties | Where-Object {$_.Id -eq 5}).Value获取账户名失败,原因是事件属性的Id并非固定匹配用户名字段,直接通过属性索引定位更可靠。针对事件ID 4624(登录)和4634(登出),用户名对应的属性索引为5(TargetUserName),域名索引为6(TargetDomainName)。修改后的本地脚本如下:

# 定义查询时间范围(最近1天)
$startTime = (Get-Date).AddDays(-1)
$endTime = Get-Date

# 获取登录事件(Event ID 4624)
$logonEvents = Get-WinEvent -FilterHashtable @{
    LogName = 'Security'
    Id = 4624
    StartTime = $startTime
    EndTime = $endTime
} -ErrorAction SilentlyContinue

# 获取登出事件(Event ID 4634)
$logoffEvents = Get-WinEvent -FilterHashtable @{
    LogName = 'Security'
    Id = 4634
    StartTime = $startTime
    EndTime = $endTime
} -ErrorAction SilentlyContinue

# 存储结果的数组
$results = @()

# 处理登录事件
foreach ($logonEvent in $logonEvents) {
    $accountName = $logonEvent.Properties[5].Value
    $domainName = $logonEvent.Properties[6].Value
    $fullAccountName = if ($domainName) { "$domainName\$accountName" } else { $accountName }
    $logonTime = $logonEvent.TimeCreated

    # 匹配对应的登出事件(同一用户,且登出时间晚于登录时间)
    $logoffEvent = $logoffEvents | Where-Object {
        $_.Properties[5].Value -eq $accountName -and
        $_.Properties[6].Value -eq $domainName -and
        $_.TimeCreated -gt $logonTime
    } | Select-Object -First 1

    $logoffTime = $logoffEvent.TimeCreated

    # 添加到结果数组
    $results += [PSCustomObject]@{
        账户全名 = $fullAccountName
        登录时间 = $logonTime
        登出时间 = $logoffTime
    }
}

# 格式化输出结果
$results | Format-Table -AutoSize

二、远程收集Azure VM的登录/登出信息

要从本地笔记本远程执行脚本,需先确保Azure VM已开启PowerShell远程管理:

  • 在Azure VM中运行Enable-PSRemoting -Force启用WinRM
  • 配置防火墙允许WinRM流量:New-NetFirewallRule -Name "WinRM-HTTP" -DisplayName "WinRM HTTP" -Enabled True -Direction Inbound -Protocol TCP -Action Allow -LocalPort 5985
  • 确保本地笔记本能访问Azure VM的公网IP或私有IP(根据网络配置)

远程执行的脚本示例:

# VM的连接信息
$vmIp = "你的Azure VM IP地址"
$vmCredential = Get-Credential -Message "输入VM的管理员账户信息"
$sessionParams = @{
    ComputerName = $vmIp
    Credential = $vmCredential
    SessionOption = New-PSSessionOption -SkipCACheck -SkipCNCheck -SkipRevocationCheck  # 适配自签名证书场景
}

# 创建远程会话
$remoteSession = New-PSSession @sessionParams

# 在远程会话中执行收集脚本
$remoteResults = Invoke-Command -Session $remoteSession -ScriptBlock {
    $startTime = (Get-Date).AddDays(-1)
    $endTime = Get-Date

    $logonEvents = Get-WinEvent -FilterHashtable @{
        LogName = 'Security'
        Id = 4624
        StartTime = $startTime
        EndTime = $endTime
    } -ErrorAction SilentlyContinue

    $logoffEvents = Get-WinEvent -FilterHashtable @{
        LogName = 'Security'
        Id = 4634
        StartTime = $startTime
        EndTime = $endTime
    } -ErrorAction SilentlyContinue

    $results = @()
    foreach ($logonEvent in $logonEvents) {
        $accountName = $logonEvent.Properties[5].Value
        $domainName = $logonEvent.Properties[6].Value
        $fullAccountName = if ($domainName) { "$domainName\$accountName" } else { $accountName }
        $logonTime = $logonEvent.TimeCreated

        $logoffEvent = $logoffEvents | Where-Object {
            $_.Properties[5].Value -eq $accountName -and
            $_.Properties[6].Value -eq $domainName -and
            $_.TimeCreated -gt $logonTime
        } | Select-Object -First 1

        $logoffTime = $logoffEvent.TimeCreated

        $results += [PSCustomObject]@{
            账户全名 = $fullAccountName
            登录时间 = $logonTime
            登出时间 = $logoffTime
        }
    }
    return $results
}

# 显示远程收集的结果
$remoteResults | Format-Table -AutoSize

# 关闭远程会话
Remove-PSSession $remoteSession

注意事项

  • 若Azure VM使用Azure AD登录,需调整账户名的获取逻辑,AAD账户的事件属性格式与本地账户不同
  • 可通过Test-NetConnection -ComputerName $vmIp -Port 5985测试本地与VM的网络连通性
  • 执行远程命令需拥有VM的管理员权限

内容的提问来源于stack exchange,提问作者MONUDDIN TAMBOLI

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.18 11:33:15