You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Automation PowerShell:如何规避$env:TEMP的1GB限制?

解决方案:直接将O365 AuditLogs导出到Azure Blob存储

方法1:通过内存流直接上传单批次数据

无需依赖本地临时磁盘,将查询到的AuditLog数据转换为CSV格式后,通过内存流直接上传至Blob存储,适配你当前每批次5000条的查询逻辑。

代码示例

# 导入Azure存储模块
Import-Module Azure.Storage.Blobs

# 配置存储账户参数
$storageAccountName = "你的存储账户名"
$containerName = "目标容器名"
$blobName = "$recordType/Data_$($currentStart.ToString("yyyyMMddHHmm"))_$($currentEnd.ToString("yyyyMMddHHmm"))_$fileloopCount.csv"

# 使用托管身份获取容器客户端(生产环境推荐)
$containerClient = [Azure.Storage.Blobs.BlobContainerClient]::new(
    "https://$storageAccountName.blob.core.windows.net/$containerName",
    [Azure.Identity.DefaultAzureCredential]::new()
)

# 查询AuditLog数据
$results = Search-UnifiedAuditLog -StartDate $currentStart -EndDate $currentEnd -SessionId $sessionID -SessionCommand ReturnLargeSet -ResultSize 5000

if (($results | Measure-Object).Count -ne 0) {
    # 将数据转换为CSV格式并转为字节流
    $csvContent = $results | ConvertTo-Csv -NoTypeInformation
    $csvBytes = [System.Text.Encoding]::UTF8.GetBytes($csvContent -join "`r`n")
    
    # 初始化内存流
    $stream = [System.IO.MemoryStream]::new($csvBytes)
    $stream.Position = 0

    # 上传至Blob存储
    $blobClient = $containerClient.GetBlobClient($blobName)
    $blobClient.Upload($stream, overwrite:$true)

    # 释放流资源
    $stream.Dispose()
}

方法2:用Append Blob实现多批次数据追加

如果需要替代本地的Export-Csv -Append逻辑,将多批次数据合并到同一个Blob文件中,可以使用Azure的Append Blob类型,全程无需本地文件。

代码示例

Import-Module Azure.Storage.Blobs

$storageAccountName = "你的存储账户名"
$containerName = "目标容器名"
# 固定Blob名称,用于归集同时间段的所有批次数据
$blobName = "$recordType/AuditLog_$($currentStart.ToString("yyyyMMdd")).csv"

$containerClient = [Azure.Storage.Blobs.BlobContainerClient]::new(
    "https://$storageAccountName.blob.core.windows.net/$containerName",
    [Azure.Identity.DefaultAzureCredential]::new()
)

$results = Search-UnifiedAuditLog -StartDate $currentStart -EndDate $currentEnd -SessionId $sessionID -SessionCommand ReturnLargeSet -ResultSize 5000

if (($results | Measure-Object).Count -ne 0) {
    $appendBlobClient = $containerClient.GetAppendBlobClient($blobName)

    # 首次创建Blob时写入CSV表头
    if (-not $appendBlobClient.Exists()) {
        $appendBlobClient.Create()
        $header = $results | Get-Member -MemberType NoteProperty | Select-Object -ExpandProperty Name
        $headerBytes = [System.Text.Encoding]::UTF8.GetBytes(($header -join ",") + "`r`n")
        $appendBlobClient.Append([System.IO.MemoryStream]::new($headerBytes))
    }

    # 转换当前批次数据为CSV行(跳过重复表头)
    $csvRows = $results | ConvertTo-Csv -NoTypeInformation | Select-Object -Skip 1
    $csvBytes = [System.Text.Encoding]::UTF8.GetBytes(($csvRows -join "`r`n") + "`r`n")
    
    # 追加数据到Blob
    $appendBlobClient.Append([System.IO.MemoryStream]::new($csvBytes))
}

关键注意事项

  • 权限配置:确保Runbook的托管身份(或服务主体)拥有存储容器的Storage Blob Data Contributor权限,否则无法执行上传/追加操作。
  • 内存优化:如果单批次数据量过大,可进一步拆分查询批次,或使用流式处理减少内存占用。
  • 性能适配:超大规模数据场景下,可启用分块上传参数优化传输效率,避免内存溢出。

内容的提问来源于stack exchange,提问作者Harry Leboeuf

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.29 23:07:55