PowerShell获取Azure Windows 10 VM用户登录登出信息问题求助
解决Azure Windows 10 VM登录/登出信息收集问题
一、修复本地脚本账户名为空的问题
你当前脚本通过($logonEvent.Properties | Where-Object {$_.Id -eq 5}).Value获取账户名失败,原因是事件属性的Id并非固定匹配用户名字段,直接通过属性索引定位更可靠。针对事件ID 4624(登录)和4634(登出),用户名对应的属性索引为5(TargetUserName),域名索引为6(TargetDomainName)。修改后的本地脚本如下:
# 定义查询时间范围(最近1天) $startTime = (Get-Date).AddDays(-1) $endTime = Get-Date # 获取登录事件(Event ID 4624) $logonEvents = Get-WinEvent -FilterHashtable @{ LogName = 'Security' Id = 4624 StartTime = $startTime EndTime = $endTime } -ErrorAction SilentlyContinue # 获取登出事件(Event ID 4634) $logoffEvents = Get-WinEvent -FilterHashtable @{ LogName = 'Security' Id = 4634 StartTime = $startTime EndTime = $endTime } -ErrorAction SilentlyContinue # 存储结果的数组 $results = @() # 处理登录事件 foreach ($logonEvent in $logonEvents) { $accountName = $logonEvent.Properties[5].Value $domainName = $logonEvent.Properties[6].Value $fullAccountName = if ($domainName) { "$domainName\$accountName" } else { $accountName } $logonTime = $logonEvent.TimeCreated # 匹配对应的登出事件(同一用户,且登出时间晚于登录时间) $logoffEvent = $logoffEvents | Where-Object { $_.Properties[5].Value -eq $accountName -and $_.Properties[6].Value -eq $domainName -and $_.TimeCreated -gt $logonTime } | Select-Object -First 1 $logoffTime = $logoffEvent.TimeCreated # 添加到结果数组 $results += [PSCustomObject]@{ 账户全名 = $fullAccountName 登录时间 = $logonTime 登出时间 = $logoffTime } } # 格式化输出结果 $results | Format-Table -AutoSize
二、远程收集Azure VM的登录/登出信息
要从本地笔记本远程执行脚本,需先确保Azure VM已开启PowerShell远程管理:
- 在Azure VM中运行
Enable-PSRemoting -Force启用WinRM - 配置防火墙允许WinRM流量:
New-NetFirewallRule -Name "WinRM-HTTP" -DisplayName "WinRM HTTP" -Enabled True -Direction Inbound -Protocol TCP -Action Allow -LocalPort 5985 - 确保本地笔记本能访问Azure VM的公网IP或私有IP(根据网络配置)
远程执行的脚本示例:
# VM的连接信息 $vmIp = "你的Azure VM IP地址" $vmCredential = Get-Credential -Message "输入VM的管理员账户信息" $sessionParams = @{ ComputerName = $vmIp Credential = $vmCredential SessionOption = New-PSSessionOption -SkipCACheck -SkipCNCheck -SkipRevocationCheck # 适配自签名证书场景 } # 创建远程会话 $remoteSession = New-PSSession @sessionParams # 在远程会话中执行收集脚本 $remoteResults = Invoke-Command -Session $remoteSession -ScriptBlock { $startTime = (Get-Date).AddDays(-1) $endTime = Get-Date $logonEvents = Get-WinEvent -FilterHashtable @{ LogName = 'Security' Id = 4624 StartTime = $startTime EndTime = $endTime } -ErrorAction SilentlyContinue $logoffEvents = Get-WinEvent -FilterHashtable @{ LogName = 'Security' Id = 4634 StartTime = $startTime EndTime = $endTime } -ErrorAction SilentlyContinue $results = @() foreach ($logonEvent in $logonEvents) { $accountName = $logonEvent.Properties[5].Value $domainName = $logonEvent.Properties[6].Value $fullAccountName = if ($domainName) { "$domainName\$accountName" } else { $accountName } $logonTime = $logonEvent.TimeCreated $logoffEvent = $logoffEvents | Where-Object { $_.Properties[5].Value -eq $accountName -and $_.Properties[6].Value -eq $domainName -and $_.TimeCreated -gt $logonTime } | Select-Object -First 1 $logoffTime = $logoffEvent.TimeCreated $results += [PSCustomObject]@{ 账户全名 = $fullAccountName 登录时间 = $logonTime 登出时间 = $logoffTime } } return $results } # 显示远程收集的结果 $remoteResults | Format-Table -AutoSize # 关闭远程会话 Remove-PSSession $remoteSession
注意事项
- 若Azure VM使用Azure AD登录,需调整账户名的获取逻辑,AAD账户的事件属性格式与本地账户不同
- 可通过
Test-NetConnection -ComputerName $vmIp -Port 5985测试本地与VM的网络连通性 - 执行远程命令需拥有VM的管理员权限
内容的提问来源于stack exchange,提问作者MONUDDIN TAMBOLI
相关产品推荐
相关产品推荐

