You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Get-WinEvent+Select-String提取4625事件源IP的问题

提取Windows安全日志4625事件中的来源IP地址

你执行的命令无输出,是因为Get-WinEvent返回的是事件对象而非纯文本,Select-String无法直接解析对象的Message内容。以下是几种可行的解决方法:

方法1:提取Message文本后匹配IP

先将事件的Message属性转为纯文本,再用正则匹配提取IP:

Get-WinEvent -FilterHashtable @{LogName='Security';ID=4625} -MaxEvents 100 | 
    ForEach-Object { $_.Message } | 
    Select-String -Pattern "Source Network Address:\s*(.*)" | 
    ForEach-Object { $_.Matches.Groups[1].Value }

方法2:直接解析事件属性(更高效)

4625事件的Source Network Address对应事件Properties数组的第19项(索引从0开始为18),可直接提取:

Get-WinEvent -FilterHashtable @{LogName='Security';ID=4625} -MaxEvents 100 | 
    ForEach-Object {
        $ip = $_.Properties[18].Value
        # 排除无IP的本地登录(值为"-"的情况)
        if ($ip -ne '-') { $ip }
    }

方法3:通过正则直接从Message提取

在循环中对每个事件的Message做正则匹配:

Get-WinEvent -FilterHashtable @{LogName='Security';ID=4625} -MaxEvents 100 | 
    ForEach-Object {
        if ($_.Message -match 'Source Network Address:\s*(.*)') {
            $matches[1]
        }
    }

内容的提问来源于stack exchange,提问作者Aucesar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.31 21:25:21