Invoke-Command仅返回单个对象属性?Windows服务器审计政策获取异常
解决Invoke-Command远程获取Windows审计政策仅返回单个属性的问题
针对你遇到的单台服务器通过Invoke-Command远程获取审计政策时仅返回自定义添加的SecEvtLogMaxSizeKb属性、本地执行正常的问题,可尝试以下几种解决方法:
1. 显式构造输出对象指定所有属性
远程执行时PowerShell的对象序列化/反序列化过程可能丢失未明确指定的属性,直接构造包含所有需要属性的PSCustomObject可避免这个问题:
Invoke-Command -ComputerName problematicServer -ScriptBlock { $securityLog = Get-WinEvent -ListLog Security # 按需添加所有需要的属性,示例包含常用属性 [PSCustomObject]@{ SecEvtLogMaxSizeKb = $securityLog.MaximumSizeInBytes / 1024 LogName = $securityLog.LogName Enabled = $securityLog.Enabled RecordCount = $securityLog.RecordCount Isolation = $securityLog.Isolation LogFilePath = $securityLog.LogFilePath # 其他需要的属性可继续补充 } }
2. 基于正常服务器的属性列表批量选择
先从正常服务器获取完整属性集合,再传递到远程脚本块中批量选择,确保返回对象的属性一致性:
# 从正常服务器获取审计政策对象的完整属性名 $fullPropertyList = (Get-WinEvent -ListLog Security | Select-Object *).PSObject.Properties.Name Invoke-Command -ComputerName problematicServer -ArgumentList $fullPropertyList -ScriptBlock { $props = $args[0] $securityLog = Get-WinEvent -ListLog Security | Select-Object $props # 添加自定义属性并返回 $securityLog | Add-Member -MemberType NoteProperty -Name SecEvtLogMaxSizeKb -Value ($securityLog.MaximumSizeInBytes / 1024) -PassThru }
3. 手动强制序列化/反序列化对象
通过手动序列化再反序列化,绕过PowerShell默认的远程传输属性截断机制:
Invoke-Command -ComputerName problematicServer -ScriptBlock { $securityLog = Get-WinEvent -ListLog Security | Select-Object * $securityLog | Add-Member -MemberType NoteProperty -Name SecEvtLogMaxSizeKb -Value ($securityLog.MaximumSizeInBytes / 1024) -PassThru # 用最大深度序列化后再反序列化 $serializedObj = [System.Management.Automation.PSSerializer]::Serialize($securityLog, [int]::MaxValue) [System.Management.Automation.PSSerializer]::Deserialize($serializedObj) }
4. 检查远程执行的日志状态与权限
虽然本地执行正常,但远程会话可能存在权限或日志状态的细微差异,可添加日志状态检查排查:
Invoke-Command -ComputerName problematicServer -ScriptBlock { # 输出日志状态信息用于排查 Write-Verbose "Security Log Status: $(Get-WinEvent -ListLog Security | Select-Object LogName, Status, Enabled)" -Verbose $securityLog = Get-WinEvent -ListLog Security | Select-Object * $securityLog | Add-Member -MemberType NoteProperty -Name SecEvtLogMaxSizeKb -Value ($securityLog.MaximumSizeInBytes / 1024) -PassThru }
内容的提问来源于stack exchange,提问作者scrouet
相关产品推荐
相关产品推荐

