You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何解决PowerShell脚本第6行的“无法索引空值”错误

修复PowerShell登录用户列表脚本的空索引错误

问题原因

你遇到的“无法索引空值”错误,实际出现在ForEach-Object循环的$_.ReplacementStrings[5]行——部分Security日志的4624事件没有ReplacementStrings属性,或该属性值为空,导致索引访问失败。另外,Get-EventLog已被微软标记为过时,在新Windows版本中兼容性较差。

修复后的脚本

# 设置回溯天数
$DaysBack = 7

# 获取当前时间
$EndDate = Get-Date

# 计算起始时间
$StartDate = $EndDate.AddDays(-$DaysBack)

# 获取近7天内的4624登录事件(用Get-WinEvent替代旧的Get-EventLog)
$UserLogins = Get-WinEvent -FilterHashtable @{
    LogName   = 'Security'
    Id        = 4624
    StartTime = $StartDate
    EndTime   = $EndDate
} -ErrorAction SilentlyContinue

# 提取并去重显示登录用户名
$UserLogins | ForEach-Object {
    # 从事件属性中提取用户名(4624事件的TargetUserName对应属性索引5)
    $_.Properties[5].Value
} | Where-Object { $_ -ne $null } | Sort-Object -Unique

关键改进点

  • 替换Get-EventLog为Get-WinEvent:后者是微软推荐的日志查询工具,事件数据结构更稳定,支持更灵活的过滤规则。
  • 增加空值过滤:通过Where-Object { $_ -ne $null }剔除无效的空用户名结果。
  • 使用Properties替代ReplacementStrings:Properties是Get-WinEvent返回事件的标准属性结构,比旧的ReplacementStrings兼容性更强。
  • 添加错误抑制:-ErrorAction SilentlyContinue忽略日志访问权限不足、日志不存在等意外错误,避免脚本中断。

兼容旧环境的替代方案

如果必须使用Get-EventLog,可以修改原脚本的循环逻辑,先判断属性是否有效:

$UserLogins | ForEach-Object {
    if ($_.ReplacementStrings -ne $null -and $_.ReplacementStrings.Count -ge 6) {
        $_.ReplacementStrings[5]
    }
} | Sort-Object -Unique

内容的提问来源于stack exchange,提问作者Intellect Liberty Study Group

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.19 06:59:55