You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

请求合并Windows防火墙日志PowerShell脚本适配Win32应用部署

合并Intune Remediation脚本适配Win32应用(Windows防火墙日志管理)

以下是合并后的检测与修复脚本,完全适配Win32应用部署逻辑,实现原Intune Remediations的全部功能:

检测脚本(返回1=合规,返回0=需修复)

# Windows防火墙日志合规性检测脚本
$firewallLogPath = "$env:SystemRoot\system32\LogFiles\Firewall\pfirewall.log"
$requiredLogSizeKB = 16384 # 可根据需求调整日志最大容量(单位:KB)
$isFileExist = $true
$isPermissionCorrect = $true
$isLogSizeCorrect = $true

# 1. 检查日志文件是否存在
if (-not (Test-Path $firewallLogPath)) {
    $isFileExist = $false
}

# 2. 检查MpsSvc服务的写入权限
$acl = Get-Acl $firewallLogPath
$validPermission = $acl.Access | Where-Object {
    $_.IdentityReference -eq "NT SERVICE\MpsSvc" -and
    $_.FileSystemRights -band [System.Security.AccessControl.FileSystemRights]::Write -and
    $_.AccessControlType -eq "Allow" -and
    $_.IsInherited -eq $false
}
if (-not $validPermission) {
    $isPermissionCorrect = $false
}

# 3. 检查日志大小配置
$currentLogSize = (netsh advfirewall show allprofiles logging | Select-String "Maximum log size").Line.Split(":")[1].Trim()
$currentLogSizeKB = [int]$currentLogSize.Replace(" KB", "")
if ($currentLogSizeKB -ne $requiredLogSizeKB) {
    $isLogSizeCorrect = $false
}

# 综合返回结果
if ($isFileExist -and $isPermissionCorrect -and $isLogSizeCorrect) {
    exit 1
} else {
    exit 0
}

修复脚本(执行全量配置修复)

# Windows防火墙日志配置修复脚本
$firewallLogPath = "$env:SystemRoot\system32\LogFiles\Firewall\pfirewall.log"
$requiredLogSizeKB = 16384 # 与检测脚本保持一致

# 1. 创建缺失的日志文件
if (-not (Test-Path $firewallLogPath)) {
    New-Item -Path $firewallLogPath -ItemType File -Force | Out-Null
}

# 2. 配置MpsSvc服务写入权限
$acl = Get-Acl $firewallLogPath
$mpsSvcAccessRule = New-Object System.Security.AccessControl.FileSystemAccessRule(
    "NT SERVICE\MpsSvc",
    [System.Security.AccessControl.FileSystemRights]::Write,
    [System.Security.AccessControl.InheritanceFlags]::None,
    [System.Security.AccessControl.PropagationFlags]::None,
    [System.Security.AccessControl.AccessControlType]::Allow
)
$acl.SetAccessRule($mpsSvcAccessRule)
Set-Acl -Path $firewallLogPath -AclObject $acl

# 3. 设置日志最大容量
netsh advfirewall set allprofiles logging maxfilesize=$requiredLogSizeKB | Out-Null

部署说明

  • 检测脚本需配置为Win32应用的检测规则,Win32应用会根据返回值判断是否触发修复:返回1则跳过修复,返回0则执行修复脚本。
  • 修复脚本无需额外配置返回值,执行完成即完成所有修复动作。
  • 可根据实际需求修改$requiredLogSizeKB参数调整日志最大容量。

内容的提问来源于stack exchange,提问作者Admaine

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 14:41:11