You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Invoke-Command仅返回单个对象属性?Windows服务器审计政策获取异常

解决Invoke-Command远程获取Windows审计政策仅返回单个属性的问题

针对你遇到的单台服务器通过Invoke-Command远程获取审计政策时仅返回自定义添加的SecEvtLogMaxSizeKb属性、本地执行正常的问题,可尝试以下几种解决方法:

1. 显式构造输出对象指定所有属性

远程执行时PowerShell的对象序列化/反序列化过程可能丢失未明确指定的属性,直接构造包含所有需要属性的PSCustomObject可避免这个问题:

Invoke-Command -ComputerName problematicServer -ScriptBlock {
    $securityLog = Get-WinEvent -ListLog Security
    # 按需添加所有需要的属性,示例包含常用属性
    [PSCustomObject]@{
        SecEvtLogMaxSizeKb = $securityLog.MaximumSizeInBytes / 1024
        LogName            = $securityLog.LogName
        Enabled            = $securityLog.Enabled
        RecordCount        = $securityLog.RecordCount
        Isolation          = $securityLog.Isolation
        LogFilePath        = $securityLog.LogFilePath
        # 其他需要的属性可继续补充
    }
}

2. 基于正常服务器的属性列表批量选择

先从正常服务器获取完整属性集合,再传递到远程脚本块中批量选择,确保返回对象的属性一致性:

# 从正常服务器获取审计政策对象的完整属性名
$fullPropertyList = (Get-WinEvent -ListLog Security | Select-Object *).PSObject.Properties.Name

Invoke-Command -ComputerName problematicServer -ArgumentList $fullPropertyList -ScriptBlock {
    $props = $args[0]
    $securityLog = Get-WinEvent -ListLog Security | Select-Object $props
    # 添加自定义属性并返回
    $securityLog | Add-Member -MemberType NoteProperty -Name SecEvtLogMaxSizeKb -Value ($securityLog.MaximumSizeInBytes / 1024) -PassThru
}

3. 手动强制序列化/反序列化对象

通过手动序列化再反序列化,绕过PowerShell默认的远程传输属性截断机制:

Invoke-Command -ComputerName problematicServer -ScriptBlock {
    $securityLog = Get-WinEvent -ListLog Security | Select-Object *
    $securityLog | Add-Member -MemberType NoteProperty -Name SecEvtLogMaxSizeKb -Value ($securityLog.MaximumSizeInBytes / 1024) -PassThru
    # 用最大深度序列化后再反序列化
    $serializedObj = [System.Management.Automation.PSSerializer]::Serialize($securityLog, [int]::MaxValue)
    [System.Management.Automation.PSSerializer]::Deserialize($serializedObj)
}

4. 检查远程执行的日志状态与权限

虽然本地执行正常,但远程会话可能存在权限或日志状态的细微差异,可添加日志状态检查排查:

Invoke-Command -ComputerName problematicServer -ScriptBlock {
    # 输出日志状态信息用于排查
    Write-Verbose "Security Log Status: $(Get-WinEvent -ListLog Security | Select-Object LogName, Status, Enabled)" -Verbose
    $securityLog = Get-WinEvent -ListLog Security | Select-Object *
    $securityLog | Add-Member -MemberType NoteProperty -Name SecEvtLogMaxSizeKb -Value ($securityLog.MaximumSizeInBytes / 1024) -PassThru
}

内容的提问来源于stack exchange,提问作者scrouet

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 01:15:14