You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用PowerShell解析Windows安全事件4740的账户名与调用者计算机名

解析Windows安全事件ID4740获取账户名与调用者计算机名

方法一:通过事件对象的结构化属性提取(推荐)

直接从Get-WinEvent返回的事件对象中提取结构化属性,这种方式不受系统语言影响,稳定性更强:

# 获取最新的账户锁定事件
$lockoutEvent = Get-WinEvent -FilterHashTable @{LogName="Security"; ID=4740} -MaxEvents 1

# 提取账户名和调用者计算机名
$Account = $lockoutEvent.Properties[0].Value
$Caller = $lockoutEvent.Properties[1].Value

事件ID4740的属性索引是固定的:

  • 索引0:被锁定的目标账户名
  • 索引1:发起锁定操作的调用者计算机名

方法二:解析事件消息文本(适用于已存储消息的场景)

如果已经将事件消息存入变量$eventMessage,可以用正则表达式匹配提取:

# 假设$eventMessage是已保存的事件消息内容
$accountPattern = '账户名:\s+(\S+)'
$callerPattern = '调用者计算机名:\s+(\S+)'

$Account = if ([regex]::Match($eventMessage, $accountPattern).Success) {
    [regex]::Match($eventMessage, $accountPattern).Groups[1].Value
}

$Caller = if ([regex]::Match($eventMessage, $callerPattern).Success) {
    [regex]::Match($eventMessage, $callerPattern).Groups[1].Value
}

注意:这种方式依赖消息文本的格式,若系统语言切换,需要调整正则中的匹配关键词。

内容的提问来源于stack exchange,提问作者user1011061

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.19 10:38:09