You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用Purview API结合PowerShell通过FQDN获取资产GUID

用PowerShell调用Purview API通过FQDN获取资产GUID

你找到的微软文档是正确的,这个Get By Unique Attributes接口就是用来通过唯一属性(比如FQDN对应的qualifiedName)查询实体GUID的。下面是具体的PowerShell实现步骤和脚本:

前提准备

  • 确保你已经通过Connect-AzAccount登录了有权访问Purview账户的Azure账号。
  • 你的账号需要有Purview数据平面的数据读取者或更高权限。
  • 明确目标资产的实体类型(比如Azure SQL Server是azure_sql_server,虚拟机是azure_vm,不同资产类型的typeName不一样,可在Purview目录的资产详情页查看)。

PowerShell脚本示例

# 1. 定义参数
$purviewAccountName = "你的Purview账户名"
$assetTypeName = "azure_sql_server" # 根据你的资产类型替换
$assetFQDN = "sqlserver01.contoso.com" # 目标资产的FQDN

# 2. 获取Purview的Azure AD访问令牌
$accessToken = (Get-AzAccessToken -ResourceUrl "https://purview.azure.net").Token

# 3. 构造API请求URL和头部
$apiUrl = "https://$purviewAccountName.purview.azure.com/catalog/api/atlas/v2/entity/uniqueAttribute/type/$assetTypeName"
$headers = @{
    "Authorization" = "Bearer $accessToken"
    "Content-Type"  = "application/json"
}

# 4. 构造请求体(指定唯一属性为qualifiedName,即FQDN)
$body = @{
    uniqueAttributes = @{
        qualifiedName = $assetFQDN
    }
} | ConvertTo-Json

# 5. 发送API请求并处理响应
try {
    $response = Invoke-RestMethod -Uri $apiUrl -Headers $headers -Method Post -Body $body
    # 提取资产GUID
    $assetGuid = $response.guid
    Write-Host "资产GUID: $assetGuid"
}
catch {
    Write-Error "请求失败: $_"
    # 打印详细错误信息
    if ($_.Exception.Response) {
        $errorContent = Get-Content $_.Exception.Response.GetResponseStream() | ConvertFrom-Json
        Write-Error "错误详情: $($errorContent.error.message)"
    }
}

关键说明

  • 实体类型(typeName):必须和资产在Purview中的类型完全匹配,比如Azure Blob容器是azure_blob_container,你可以在Purview的资产详情页的"类型"字段找到准确值。
  • qualifiedName:绝大多数云资产的FQDN都会映射到qualifiedName这个唯一属性,这是Purview中实体的全局唯一标识字段。
  • 权限问题:如果返回403错误,检查你的账号是否被授予了Purview数据平面的读取权限,或者是否需要通过服务主体认证(如果是自动化脚本,推荐用服务主体)。

服务主体认证(可选,适合自动化脚本)

如果是无人值守的自动化脚本,建议用服务主体认证,替换令牌获取部分的代码:

# 服务主体参数
$tenantId = "你的租户ID"
$clientId = "服务主体ID"
$clientSecret = "服务主体密钥"

# 获取服务主体令牌
$tokenEndpoint = "https://login.microsoftonline.com/$tenantId/oauth2/v2.0/token"
$tokenParams = @{
    client_id     = $clientId
    client_secret = $clientSecret
    scope         = "https://purview.azure.net/.default"
    grant_type    = "client_credentials"
}
$tokenResponse = Invoke-RestMethod -Uri $tokenEndpoint -Method Post -Body $tokenParams
$accessToken = $tokenResponse.access_token

内容的提问来源于stack exchange,提问作者Subhransu Sekhar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.26 01:20:15