使用Get-WinEvent+Select-String提取4625事件源IP的问题
提取Windows安全日志4625事件中的来源IP地址
你执行的命令无输出,是因为Get-WinEvent返回的是事件对象而非纯文本,Select-String无法直接解析对象的Message内容。以下是几种可行的解决方法:
方法1:提取Message文本后匹配IP
先将事件的Message属性转为纯文本,再用正则匹配提取IP:
Get-WinEvent -FilterHashtable @{LogName='Security';ID=4625} -MaxEvents 100 | ForEach-Object { $_.Message } | Select-String -Pattern "Source Network Address:\s*(.*)" | ForEach-Object { $_.Matches.Groups[1].Value }
方法2:直接解析事件属性(更高效)
4625事件的Source Network Address对应事件Properties数组的第19项(索引从0开始为18),可直接提取:
Get-WinEvent -FilterHashtable @{LogName='Security';ID=4625} -MaxEvents 100 | ForEach-Object { $ip = $_.Properties[18].Value # 排除无IP的本地登录(值为"-"的情况) if ($ip -ne '-') { $ip } }
方法3:通过正则直接从Message提取
在循环中对每个事件的Message做正则匹配:
Get-WinEvent -FilterHashtable @{LogName='Security';ID=4625} -MaxEvents 100 | ForEach-Object { if ($_.Message -match 'Source Network Address:\s*(.*)') { $matches[1] } }
内容的提问来源于stack exchange,提问作者Aucesar
相关产品推荐
相关产品推荐

